Resources › Legislation › ZInfV-1
LEGISLATION

ZInfV-1

The Information Security Act

The Information Security Act (ZInfV-1) is Slovenia’s central legislation in the field of information and cybersecurity. It regulates the national information security system, the responsibilities of the national authority and CSIRT teams, and sets out the obligations of entities regarding risk management, security documentation, security measures, incident reporting and supervision.

ZInfV-1

ZInfV-1 was published in the Official Gazette of the Republic of Slovenia No. 40/2025 on 4 June 2025 and has applied since 19 June 2025. Through the Act, Slovenia transposed Directive (EU) 2022/2555, known as NIS2, into national law.

Publication date 5 October 2026
Official Gazette No. 40/2025
In force since 19 June 2025
01

What is ZInfV-1 and why is it important?

ZInfV-1 regulates information and cybersecurity and establishes the national information security system in the Republic of Slovenia. 

Among other things, the Act regulates the responsibilities of the national authority, the operation of CSIRT teams, risk management measures, reporting obligations and supervision of compliance with statutory requirements. The competent national authority is the Government Information Security Office of the Republic of Slovenia (URSIV).

KEY POINT

ZInfV-1 is a governance requirement, not just a technical one.

Compliance is not limited to the IT department. It requires clearly defined responsibilities, risk management, documentation, as well as management support and oversight.

The Act does not limit information security management to the technical responsibilities of the IT department. Responsible persons of essential and important entities must approve risk management measures and supervise their implementation. The Act also requires management support and the inclusion of information and cybersecurity in the annual business plan or work programme. This means that compliance is not limited to individual security technologies. ZInfV-1 requires a documented information security management and business continuity system, risk analysis, an asset inventory, incident response and recovery plans, as well as technical, operational and organisational security measures.

For most essential and important entities, an important transitional deadline is set out in Article 62 of ZInfV-1. Measures required under Articles 21 and 22 must be adopted within 18 months of the Act entering into force, which means by 19 December 2026. For certain entities that were already subject to the previous ZInfV framework, and for certain operators under ZEKom 2, the Act established a one year deadline that expired on 19 June 2026.

Incident reporting deadlines are also important. In the event of a significant incident, an entity must submit an early warning no later than 24 hours after detection, followed by an incident notification within 72 hours. A final report must generally be submitted no later than one month after the incident notification. If the incident is still ongoing at that time, a progress report must be submitted, followed by a final report no later than one month after the incident has been resolved.

ZInfV-1 also provides for penalties. For certain core infringements, the Act provides for turnover based fines. For essential entities, fines may range from 0.5% to 2% of the legal entity’s total annual turnover from the previous financial year. For important entities, the range is from 0.3% to 1.4%. Articles 52 and 53 also set specific monetary limits and separate fines for responsible persons.

The practical significance of ZInfV-1 is not limited to avoiding penalties. Requirements relating to asset inventories, clearly defined responsibilities, risk analysis, business continuity, supplier management and incident response provide organisations with a structured framework for managing information and cyber resilience. URSIV also structures its current guidance for regulated entities around clear responsibilities, risk management and timely incident response.

02

Does ZInfV-1 apply to your organisation?

This is usually the first question an organisation should ask.

The basic assessment involves several steps:

1
Check your activity
Do you perform one of the activities or services listed in Annex 1 or Annex 2 of ZInfV-1? The Act covers, among others, energy, transport, healthcare, drinking water and wastewater, digital infrastructure, ICT service management, public administration, postal and courier services, waste management, manufacturing, research, food and chemicals. The complete list should be checked directly in the annexes to the Act.
2
Check your size
Under the general rule, an entity listed in Annex 1 or Annex 2 must have at least 50 employees and, at the same time, annual turnover or an annual balance sheet total of at least EUR 10 million. This is an important distinction: the general rule should not be simplified to “50 employees or EUR 10 million in turnover”.
3
Check the exceptions to the size criterion
For certain categories, size is not decisive. These include, for example, certain providers of electronic communications, trust service providers, TLD registries and DNS service providers, critical entities, certain entities of particular importance and certain public administration bodies. The Act therefore requires a substantive assessment, not merely a review of employee numbers and revenue.
4
Determine whether you are an essential or important entity
The classification primarily affects the supervisory regime and certain compliance assessment obligations.
5
Complete self registration
When circumstances arise that make an organisation subject to the Act, the general deadline for self registration is 30 days. Information that changes after registration must generally be updated within ten working days. Organisations that already met the relevant criteria when the Act entered into force were required to complete their initial self registration by 19 December 2025.
03

Key requirements of ZInfV-1

Management responsibility and training

Heads of public administration entities and the responsible persons of legal entities are responsible for implementing the measures required under Articles 21 and 22. Responsible persons approve the measures and supervise their implementation. 

At least once every four years, they must complete education or training in information and cybersecurity risk management. They must also ensure regular employee training, while administrators of information and communication systems must complete regular annual training.

4 years
training for responsible persons
annually
training for ICT system administrators
21
Article

Security documentation

Article 21 requires essential and important entities to establish and maintain a documented information security management system and a business continuity management system. At a minimum, these must include security policies, an up to date inventory of information and other assets, a risk management analysis including the methodology used and the acceptable level of risk, a business continuity policy and plan including a business impact assessment, a recovery plan, an incident response plan, a security measures plan and procedures for assessing the effectiveness of those measures.

URSIV has published model security documentation, including an asset inventory methodology, risk analysis, a risk register, a business continuity policy and plan, BIA, a recovery plan, an incident response plan and a security measures plan. URSIV explicitly notes that these templates are not a universal solution and must be adapted to the organisation’s infrastructure, sector, scale of operations, external providers and the results of its risk analysis.

22
Article

Technical, operational and organisational measures

Article 22 requires technical, operational and organisational measures based on an all hazards approach. The Act covers, among other things, management support, cyber hygiene, human resources security, identity and access rights, backups, logging, cryptography, communications management, supply chain security, physical security, secure development and maintenance of systems, vulnerability management, protection against malicious software, multifactor authentication and policies regarding the use of cloud services.
The measures must be proportionate to the risks. When assessing proportionality, organisations must consider their exposure to risks, the size of the entity, the likelihood of incidents and their potential severity, including societal and economic impact. A similar proportionality approach is also used by Commission Implementing Regulation (EU) 2024/2690 for the categories of digital providers to which it directly applies.

Supply chain

Supply chain security is one of the requirements expressly listed in Article 22. Essential and important entities must define appropriate minimum information and cybersecurity requirements for key direct suppliers or service providers and take into account their specific vulnerabilities and the overall quality of their cybersecurity practices.

On 31 August 2026, URSIV published specific recommendations for supply chain risk management. The materials include a supplier questionnaire, a risk assessment tool, a supplier register and a checklist of contractual provisions. URSIV expressly emphasises that these are practical supporting tools and that using them does not in itself demonstrate compliance with ZInfV-1.

24
Article

Logging

Article 24 requires procedures and tools for monitoring and recording events in network and information systems so that incidents or near incidents can be detected, analysed and reconstructed. The Act also specifies minimum categories of records and requires their authenticity, integrity, availability and confidentiality. The general minimum retention period is six months, although a longer period may be required where indicated by the risk analysis.

Reporting significant incidents

Essential and important entities must report incidents that have a significant impact on the provision of their services to the competent CSIRT. The Act defines a significant incident as an incident that has caused or could cause serious operational disruption or financial loss, or could cause significant material or non material damage to other natural or legal persons.

SI-CERT explains that entities within its remit must submit an early warning without undue delay and no later than 24 hours after detection. If it is not immediately clear whether an incident meets the criteria for mandatory reporting, SI-CERT expressly advises entities to report the incident anyway.

04

Path to compliance

A practical approach begins by confirming whether the organisation is subject to the Act and whether it is classified as an essential or important entity. The assessment should be based on the organisation’s actual activities, the annexes to the Act, size data and any specific criteria set out in Articles 6 and 7.

RESPONSIBILITIES

Define responsible persons

The next step is to define responsibilities. The Act requires responsible persons to approve measures and supervise their implementation. During self-registration, the organisation must also provide details of a contact person for information security and their deputy.

ASSETS

Establish an asset inventory

The next step is to create an inventory of the information and other assets necessary for the organisation’s operations or provision of services, together with their respective managers. The asset inventory is a direct requirement of Article 21 and provides one of the foundations for defining the scope of the management system.

RISKS

Conduct a risk analysis

Based on this, the organisation should conduct a risk management analysis. The Act also requires the organisation to define its acceptable level of risk and describe the methodology used. For business continuity planning, ZInfV-1 also requires a business impact assessment, or BIA.

MEASURES

Assess existing measures

The organisation should then compare its existing technical, operational and organisational measures against the requirements of the Act and identify the necessary improvements based on the risks identified. ZInfV-1 requires measures to be effective, adapted, consistent, proportionate, specific and verifiable.

DOCUMENTATION

Connect documentation with implementation

Security documentation must be connected to actual implementation. When describing inspection procedures, URSIV specifically emphasises that supervision considers not only the documentation itself but also whether security measures are actually being implemented. URSIV also notes that being classified as a regulated entity does not in itself mean that the organisation is compliant.

INCIDENTS

Prepare incident response and recovery procedures

The organisation must also have procedures in place for incident response and business continuity. The Act requires an incident response plan that includes a protocol for notifying the competent CSIRT, as well as a recovery plan for restoring the operation of information systems.

REVIEW

Regularly assess effectiveness

Finally, the organisation must regularly assess the effectiveness of its measures and maintain appropriate evidence. Essential entities must carry out a compliance assessment at least once every two years or following a significant incident. Important entities must conduct a self-assessment of compliance. URSIV also provides supporting materials and a self-assessment tool for this purpose.

SPECIFIC REQUIREMENTS

Check additional requirements for digital providers

For certain providers of digital infrastructure and services, Commission Implementing Regulation (EU) 2024/2690 also applies and provides more detailed technical and methodological requirements. In June 2025, ENISA published technical guidance containing explanations, examples of evidence and mappings of requirements to support implementation of the Regulation.

05

How can Blue Octopus help?

Blue Octopus does not replace legal assessment, CSIRT teams, independent audits or technical security solutions such as MFA, backups, firewalls or event monitoring systems. However, it can support the management side of the process, where ZInfV-1 requires structured management of risks, responsibilities, analyses and documentation.

Area
How Blue Octopus can support it
Risk analysis and risk register
Structuring, assessing and prioritising risks
Responsibilities
Assigning risks and activities to responsible owners
Overview of current status
A centralised overview of findings, priorities and responsibilities
Documentation
Connecting and managing relevant documents
Analyses
Structured management of analyses and linking findings to risks
Improvements
Recording findings and linking activities to responsible persons

This use is consistent with the logic of ZInfV-1, which requires documented risk analysis, defined responsibilities, planning of measures and verifiable implementation. However, the use of software itself does not constitute evidence that an organisation complies with ZInfV-1.

06
FAQ

Frequently asked questions

Short answers to the most common questions about the scope and requirements of ZInfV-1.

No. Size is an important general criterion, but the Act defines several situations in which an entity may be subject to ZInfV-1 regardless of the number of employees or financial thresholds. It is therefore necessary to first check the type of activity and the specific categories defined in Article 6.

Yes. This is possible particularly for categories to which the statutory size threshold does not apply, or where an entity is designated under other criteria because of the importance of the service it provides.

Operational responsibilities may be distributed across different functions. However, the Act expressly requires responsible persons to approve risk management measures and supervise their implementation. Information security is therefore also a matter of organisational governance.

No. ISO/IEC 27001 is an international standard that specifies requirements for an information security management system and provides a highly useful framework for structured risk management. ZInfV-1 encourages the use of European and international standards, but compliance must always be assessed against the specific statutory requirements.

The general minimum requirement under ZInfV-1 is six months. If the risk analysis identifies a need for a longer retention period, the organisation must adjust the retention period accordingly.

SI-CERT advises organisations to report the incident if they are in doubt. This does not change the statutory criteria, but it reduces the risk of missing the 24 hour deadline while waiting for further information.

Entities subject to ZInfV-1 must manage supply chain risks and define appropriate minimum security requirements for key suppliers or service providers. As a result, ZInfV-1 requirements may also be passed on in practice to companies outside the direct scope of the Act through contracts and procurement procedures.

No. The Act requires the implementation of technical, operational and organisational measures and the assessment of their effectiveness. Documentation is an important part of the system, but it must reflect actual implementation.

07

Official sources

08

Next step

ZInfV-1 requires organisations to connect risk management, responsibilities, documentation, security measures, incident response and effectiveness reviews into a systematic process. Blue Octopus can help structure analyses, risks, responsibilities and related documentation in one place.

Download

↓
ZInfV-1 checklist A practical overview of the key compliance steps.
↓