NIS2 · CRA
Digital infrastructure and IT providers
Cloud, data centres, DNS, TLD registries and managed service providers are named directly in NIS2 — and if you ship software, the CRA is coming for the product as well.
WHAT MAKES THIS SECTOR DIFFERENT
Where the pressure actually comes from
Being in scope twice is the normal case here: once as an operator of your own estate, and once as the supplier whose customers now have to evidence their supply chain. Expect the second to arrive as questionnaires from clients long before a regulator writes to you.
WHICH RULES CATCH YOU
Start here, in this order
NIS2 / ZInfV-1
Slovenia's Information Security Act, in force since 19 June 2025, took the number of obliged organisations from roughly 100 to roughly 1,000. Risk measures, incident reporting, supply-chain security and training, supervised by URSIV.
Read more 453 days leftCyber Resilience Act
Anyone placing hardware or software with digital elements on the EU market: secure by design, secure defaults, signed updates, and reporting of actively exploited vulnerabilities. Reporting duties start first; full compliance follows on 11 December 2027.
Read more Contract requirementISO/IEC 27001
Not a law but a contract requirement: increasingly the price of bidding at all. SIST EN ISO/IEC 27001:2023 is the Slovenian adoption. We take organisations from gap analysis to a certifiable management system.
Read moreWHAT WE DO ABOUT IT
The three that matter most here
Penetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more TPRMaaSThird-party risk management
Your suppliers are your attack surface, and under NIS2 they are also your legal responsibility. We inventory them, rate them and keep watching.
Read more VMVulnerability management
Continuous discovery, prioritised by what is actually reachable and actually exploited — not by a scanner dumping ten thousand findings on your team.
Read more