NIS2 in Slovenia — ZInfV-1, a sixfold scope expansion, and universities in scope.
Slovenia transposed NIS2 through ZInfV-1, the new Information Security Act adopted on 23 May 2025 and in force since 19 June 2025 — late against the EU deadline, and after a Commission reasoned opinion, but now fully in force. The Government Office for Information Security (URSIV) is the competent authority and single point of contact; SI-CERT, operating inside the ARNES public institute, is the national incident-response team; inspections sit with the Information Society Inspectorate.
The headline is scope. ZInfV-1 grows the regulated population from roughly 1,000 entities under the old act to an estimated 6,000–8,000 — and Slovenia goes beyond the directive by pulling research and higher-education institutions into scope. Entities subject from day one had to self-register with URSIV by 19 December 2025; entities entering scope later register within 30 days. The measures clocks run to 19 June 2026 for entities carried over from the old regime and to 19 December 2026 for everyone else.
Who it applies to
Essential and important entities across the NIS2 sectors, plus research and higher-education institutions — a Slovenian addition. Self-registration with URSIV: six months for day-one entities (the deadline was 19 December 2025), 30 days for entities entering scope later. Incident reporting to SI-CERT: 24-hour early warning, 72-hour notification, one-month final report.
The clock
Competent authority: URSIV (Government Office for Information Security). Transposition: Zakon o informacijski varnosti (ZInfV-1), Uradni list RS 40/2025.
| When | What happens |
|---|---|
| 23 May 2025 | National Assembly adopts ZInfV-1 |
| 19 Jun 2025 | ZInfV-1 enters into force |
| 19 Dec 2025 | Self-registration deadline for day-one entities |
| 19 Dec 2026 | Measures deadline for entities new to the regime (carried-over entities: 19 Jun 2026) |
A sixfold scope expansion, with universities inside it
Slovenia's transposition is notable less for its structure than for its reach. ZInfV-1 replaces the 2018 act, multiplies the regulated population roughly sixfold, and adds research and higher-education institutions — a category the directive does not require member states to include. For Slovenian universities and research institutes, NIS2-grade obligations are new territory: a documented information-security management system, business continuity, an effectiveness assessment at least annually, and 24-hour incident reporting to SI-CERT. The two-track measures deadlines — June 2026 for entities carried over from the old act, December 2026 for the newly regulated — mean the compliance conversation differs sharply depending on which side of that line an entity sits. TruSecure records which track applies as a dated fact and phases the measures plan accordingly.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Slovenia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Self-register with URSIV (30 days for newly in-scope entities) | Entity profile · registration facts held as dated records |
| Run a documented ISMS and business continuity system | Control library · ISMS scope and continuity plans as living records |
| Report incidents to SI-CERT: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Assess effectiveness at least annually | Assessment records · dated, versioned, audit-ready |
| Meet the measures deadline for your track (Jun or Dec 2026) | Compliance plan · track recorded, milestones phased |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- URSIV registration
- filed 02 Dec 2025 · ahead of the deadline
- Measures track
- new to the regime · December 2026 deadline applies
- Controls evidenced
- 68/96 · ISMS documentation complete
- Incident reports
- 0 filed · SI-CERT workflow tested
- Export
- sealed · sha256:5e1a...c3b8
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your registration position with URSIV confirmed, your measures track established, and the ISMS mapped against what you already document. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Slovenia by URSIV (Government Office for Information Security). TruSecure determines applicability against Slovenia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.