Slovenia transposed the NIS2 Directive through the Zakon o informacijski varnosti (ZInfV-1, Information Security Act), Uradni list RS (Official Gazette of the Republic of Slovenia) št. 40/25, adopted by the National Assembly on 22 May 2025, published 3 June 2025 and in force since 18 June 2025.
Article 69(1) repeals the predecessor Zakon o informacijski varnosti (Uradni list RS, št. 30/18, 95/21, 130/22, 18/23 and 49/23), Slovenia's NIS1-era transposition, along with four implementing regulations and two general acts on essential-service security documentation, security measures and incident notification that governed under it; none of the predecessor regime survives.
Article 10(1) designates the Urad Vlade Republike Slovenije za informacijsko varnost (URSIV, the Government Office for Information Security) as the competent national authority, supervising through its own information-security inspectors under Article 45.
Article 13 provides for one or more CSIRT groups; pending their formal designation, Article 59 assigns SIGOV-CERT (the internal unit of the competent authority) to handle incidents of state and local public-administration bodies and trust-service providers used by state administration, and SI-CERT, the unit hosted by the public research-network institute ARNES, to handle incidents for every other obligated entity and to act as the single point of contact.
Two instruments carry the coded duties: Article 22's cybersecurity risk-management measures, together with Article 20's governance duty and Article 21's security-documentation duty, and Article 29 and 30's significant-incident notification duty with its 24-hour, 72-hour and one-month clock.
Article 6 binds an entity within Annex 1 (Priloga 1, highly critical sectors) or Annex 2 (Priloga 2, other critical sectors) that has at least 50 employees and an annual turnover or balance-sheet total of at least EUR 10 million, the medium-enterprise floor, unless one of Article 6(2)'s no-threshold triggers applies (sole national provider of the service, public electronic-communications or trust-service provider, top-level domain (TLD) registry or DNS provider, or a public-administration body).
Article 29(3) separately names a provider of an online marketplace, an online search engine or a social-networking-services platform, alongside a DNS service, TLD registry, cloud, data-centre, content-delivery-network, managed-service or managed-security-service provider, for special notification treatment, confirming these digital providers sit within the Act's scope on the same NIS2 Annex II model as the rest of the corpus.
Article 52 and 53 set a two-tier misdemeanor (prekršek) fine, not a criminal offence: an essential entity faces 0.5 to 2 percent of worldwide annual turnover or EUR 10,000 to 10,000,000, whichever is higher, and an important entity faces 0.3 to 1.4 percent or EUR 7,000 to 7,000,000, whichever is higher, both triggered by a failure under Articles 21, 22, 24, 29 or 30; a responsible person of the entity, or a sole trader, faces a separate personal fine under the same articles.
The Cyber Resilience Act (Regulation (EU) 2024/2847) is directly applicable EU law and is documented at the European Union level rather than restated here; Slovenia's government adopted an implementing regulation assigning Cyber Resilience Act (CRA) market-surveillance tasks jointly to URSIV and the Market Inspectorate (Tržni inšpektorat), reported in Slovenian legal press, but this filing does not rest a coded claim on that secondary reporting.
Slovenia has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and ZVOP-2's personal-data-breach notification to the Informacijski pooblaščenec (Information Commissioner), both of which sit in the privacy topic rather than here.
Article 50(1) of this Act requires a security inspector who finds that a matter under investigation involves a personal-data breach, or a suspected one, to notify the Informacijski pooblaščenec, the one point where the two regimes cross-refer without either duplicating the other's corpus.