NIS2 and compliance
The NIS2 directive and the Slovenian Information Security Act (ZInfV-1) require essential and important entities to manage cyber risks, report incidents within set deadlines and make management personally accountable. They cover energy, transport, health, water, digital infrastructure, manufacturing, food, waste management and everyone in the supply chain of such organisations. We help you find out whether you are in scope, where the gaps are and how to close them without unnecessary projects. We operate under ISO 27001 and ISO 22301 ourselves, so we know which evidence an auditor or the supervisory authority really expects.
What NIS2 requires of you
The road to compliance in four steps
- 01
Are you in scope
We check your sector, size and role in the supply chain and determine whether you are an essential, important or indirectly affected entity.
- 02
Gap assessment
We compare your current state with the NIS2 and ZInfV-1 requirements and prepare a prioritised list of gaps with a risk rating.
- 03
Plan and implementation
Policies and procedures, technical measures (MFA, segmentation, backups, SOC) and management training; we can implement them ourselves or with your team.
- 04
Evidence and upkeep
A register of assets, incidents and measures, regular reports and a yearly review, so you are ready for supervision at any time.
Frequently asked questions
Does NIS2 also apply to smaller companies?
Directly, as a rule, medium and large companies in the covered sectors, with exceptions for critical services regardless of size. Indirectly it affects every supplier of an in-scope entity, because that entity must assess and contractually bind its supply chain.
What are the deadlines for reporting an incident?
An early warning within 24 hours of becoming aware of a significant incident, a notification with a first assessment within 72 hours and a final report within one month. You can only meet the deadlines if you detect the incident at all; that is why 24/7 monitoring is a prerequisite, not an extra.
Does ISO 27001 mean we are NIS2 compliant?
Not automatically, but it covers a large part. ISO 27001 gives you the management system and most technical measures; NIS2 adds incident reporting deadlines, management obligations, the supply chain and registration with the supervisory authority. A gap assessment shows what is missing.
Who is the supervisory authority in Slovenia?
The Government Information Security Office (URSIV); incidents are reported to the national response centre SI-CERT. We build the reporting procedure into your response plan so nobody has to look for it during an incident.
How long does it take to become compliant?
A gap assessment takes two to four weeks. Closing the gaps depends on the starting point: a company with well-run IT and maintenance needs three to six months, a company without policies and monitoring usually a year.
Which of your services cover the requirements?
24/7 SOC and NOC for detecting and reporting incidents, penetration testing for verifying measures, IT maintenance for backups and patches, and training for employees and management. Policies and evidence are prepared in the consulting part.