Skip to main content
NIS2 · SLOVENIA

NIS2 in Slovenia — ZInfV-1, a sixfold scope expansion, and universities in scope.

Slovenia transposed NIS2 through ZInfV-1, the new Information Security Act adopted on 23 May 2025 and in force since 19 June 2025 — late against the EU deadline, and after a Commission reasoned opinion, but now fully in force. The Government Office for Information Security (URSIV) is the competent authority and single point of contact; SI-CERT, operating inside the ARNES public institute, is the national incident-response team; inspections sit with the Information Society Inspectorate.

The headline is scope. ZInfV-1 grows the regulated population from roughly 1,000 entities under the old act to an estimated 6,000–8,000 — and Slovenia goes beyond the directive by pulling research and higher-education institutions into scope. Entities subject from day one had to self-register with URSIV by 19 December 2025; entities entering scope later register within 30 days. The measures clocks run to 19 June 2026 for entities carried over from the old regime and to 19 December 2026 for everyone else.

Who it applies to

Essential and important entities across the NIS2 sectors, plus research and higher-education institutions — a Slovenian addition. Self-registration with URSIV: six months for day-one entities (the deadline was 19 December 2025), 30 days for entities entering scope later. Incident reporting to SI-CERT: 24-hour early warning, 72-hour notification, one-month final report.

The clock

Competent authority: URSIV (Government Office for Information Security). Transposition: Zakon o informacijski varnosti (ZInfV-1), Uradni list RS 40/2025.

NIS2 in Slovenia · timeline
WhenWhat happens
23 May 2025National Assembly adopts ZInfV-1
19 Jun 2025ZInfV-1 enters into force
19 Dec 2025Self-registration deadline for day-one entities
19 Dec 2026Measures deadline for entities new to the regime (carried-over entities: 19 Jun 2026)

A sixfold scope expansion, with universities inside it

Slovenia's transposition is notable less for its structure than for its reach. ZInfV-1 replaces the 2018 act, multiplies the regulated population roughly sixfold, and adds research and higher-education institutions — a category the directive does not require member states to include. For Slovenian universities and research institutes, NIS2-grade obligations are new territory: a documented information-security management system, business continuity, an effectiveness assessment at least annually, and 24-hour incident reporting to SI-CERT. The two-track measures deadlines — June 2026 for entities carried over from the old act, December 2026 for the newly regulated — mean the compliance conversation differs sharply depending on which side of that line an entity sits. TruSecure records which track applies as a dated fact and phases the measures plan accordingly.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Slovenia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Slovenia requirements · how TruSecure answers them
What the law asksWhere it is answered
Self-register with URSIV (30 days for newly in-scope entities)Entity profile · registration facts held as dated records
Run a documented ISMS and business continuity systemControl library · ISMS scope and continuity plans as living records
Report incidents to SI-CERT: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Assess effectiveness at least annuallyAssessment records · dated, versioned, audit-ready
Meet the measures deadline for your track (Jun or Dec 2026)Compliance plan · track recorded, milestones phased

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Slovenia NIS2 readiness file · excerptSample data
URSIV registration
filed 02 Dec 2025 · ahead of the deadline
Measures track
new to the regime · December 2026 deadline applies
Controls evidenced
68/96 · ISMS documentation complete
Incident reports
0 filed · SI-CERT workflow tested
Export
sealed · sha256:5e1a...c3b8

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your registration position with URSIV confirmed, your measures track established, and the ISMS mapped against what you already document. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Slovenia by URSIV (Government Office for Information Security). TruSecure determines applicability against Slovenia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Which body enforces NIS2 in Slovenia?
URSIV — the Government Office for Information Security — is the competent authority and single point of contact; SI-CERT, inside the ARNES public institute, is the national incident-response team. ZInfV-1 has been in force since 19 June 2025, so the structure is settled, not still emerging.