NIS2 and compliance
The NIS2 directive and the Slovenian Information Security Act (ZInfV-1) require essential and important entities to manage cyber risks, report incidents within set deadlines and make management personally accountable. They cover energy, transport, health, water, digital infrastructure, manufacturing, food, waste management and everyone in the supply chain of such organisations. We help you find out whether you are in scope, where the gaps are and how to close them without unnecessary projects. We operate under ISO 27001 and ISO 22301 ourselves, so we know which evidence an auditor or the supervisory authority really expects.
What NIS2 requires of you
Risk management
Risk management
Risk analysis, security policies and measures for networks, access, encryption and multi-factor authentication.
Incident reporting
Incident reporting
An early warning within 24 hours, a notification within 72 hours and a final report within a month; that needs detection and a procedure.
Management accountability
Management accountability
Management must approve and oversee the measures and undergo training; it is personally liable for breaches.
Supply chain security
Supply chain security
Supplier assessment and contractual requirements; this is why NIS2 indirectly affects companies that are not in scope themselves.
Business continuity
Business continuity
Backups, disaster recovery and crisis management; here we draw on our ISO 22301 experience.
Training and testing
Training and testing
Regular employee training, penetration testing and audits of how effective the measures are.
The road to compliance in four steps
- 01
Are you in scope
We check your sector, size and role in the supply chain and determine whether you are an essential, important or indirectly affected entity.
- 02
Gap assessment
We compare your current state with the NIS2 and ZInfV-1 requirements and prepare a prioritised list of gaps with a risk rating.
- 03
Plan and implementation
Policies and procedures, technical measures (MFA, segmentation, backups, SOC) and management training; we can implement them ourselves or with your team.
- 04
Evidence and upkeep
A register of assets, incidents and measures, regular reports and a yearly review, so you are ready for supervision at any time.
Frequently asked questions
Does NIS2 also apply to smaller companies?
Directly, as a rule, medium and large companies in the covered sectors, with exceptions for critical services regardless of size. Indirectly it affects every supplier of an in-scope entity, because that entity must assess and contractually bind its supply chain.
What are the deadlines for reporting an incident?
An early warning within 24 hours of becoming aware of a significant incident, a notification with a first assessment within 72 hours and a final report within one month. You can only meet the deadlines if you detect the incident at all; that is why 24/7 monitoring is a prerequisite, not an extra.
Does ISO 27001 mean we are NIS2 compliant?
Not automatically, but it covers a large part. ISO 27001 gives you the management system and most technical measures; NIS2 adds incident reporting deadlines, management obligations, the supply chain and registration with the supervisory authority. A gap assessment shows what is missing.
Who is the supervisory authority in Slovenia?
The Government Information Security Office (URSIV); incidents are reported to the national response centre SI-CERT. We build the reporting procedure into your response plan so nobody has to look for it during an incident.
How long does it take to become compliant?
A gap assessment takes two to four weeks. Closing the gaps depends on the starting point: a company with well-run IT and maintenance needs three to six months, a company without policies and monitoring usually a year.
Which of your services cover the requirements?
24/7 SOC and NOC for detecting and reporting incidents, penetration testing for verifying measures, IT maintenance for backups and patches, and training for employees and management. Policies and evidence are prepared in the consulting part.
Official sources
The content of this page is based on the directive text, the Slovenian act and the publications of the competent authorities; the same sources underpin our ComplyIT platform.
- NIS2 Directive
- Directive (EU) 2022/2555, official text on EUR-Lex
- Slovenian act
- Information Security Act (ZInfV-1) on PisRS
- Competent authority in Slovenia
- Government Information Security Office (URSIV)
- Information security in Slovenia
- Topic "Information and cyber security" on GOV.SI
- Incident reporting
- SI-CERT, the national cyber security incident response centre
Let's check whether NIS2 applies to you
Tell us your sector, size and main customers; within a week you receive an assessment of whether you are in scope and a proposal for the next steps.