Law / Slovenia

Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance

Zakon o informacijski varnosti (ZInfV-1), Uradni list RS, št. 40/25, čl. 20-22

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force in 93 days, effective 18 December 2026.

A sector security regimes rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This duty is not yet binding for the general population of essential and important entities: Article 62(1) phases the Article 21-22 risk-management measures in over eighteen months from the Act's 18 June 2025 commencement, to 18 December 2026, though Article 62(2) held that date to one year (18 June 2026, already past) for an entity already designated as an essential-service operator or a state-administration body under the predecessor Zakon o informacijski varnosti.
  • This binds you once it applies where you fall within Annex 1 or Annex 2's sector lists and, unless one of Article 6(2)'s no-threshold triggers applies, you have at least 50 employees and an annual turnover or balance-sheet total of at least EUR 10 million; Article 29(3) separately names a provider of an online marketplace, an online search engine or a social-networking-services platform, alongside a DNS service, top-level domain (TLD) registry, cloud, data-centre, content-delivery-network, managed-service or managed-security-service provider, confirming these digital providers sit within the Act's scope.
  • Once it binds, take technical, operational and organisational measures to secure the integrity, authenticity, confidentiality and availability of the network and information systems you use for your work or to provide your services, and to prevent or reduce the impact of an incident on the recipients of your services and on other services.
  • Cover at minimum: management support for information and cybersecurity, personnel integrity checks before, during and after employment, basic cyber-hygiene practices and training, human-resources security and access-rights management, backup management, logging of events on your network and information systems, and, where relevant, supply-chain security, cryptography and encryption policy, and multi-factor or continuous authentication.
  • Have your responsible person, the individual who leads, supervises or manages the entity or a public-administration body's head, approve these measures and oversee their implementation, and complete cybersecurity risk-management training at least every four years.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Articles 52 and 53 create a prekršek (misdemeanor, an administrative offence under Slovenia's minor-offences framework), not a kaznivo dejanje (criminal offence under the Kazenski zakonik). No provision reviewed here makes a failure to adopt these measures a criminal offence.

Penalty structure

Article 52(1): an essential entity's failure to meet obligations under, among others, Articles 21, 22 and 24 carries a fine of 0.5 to 2 percent of the legal person's total annual turnover in the preceding business year, but not less than EUR 10,000 and not more than EUR 10,000,000, whichever amount is higher. Article 53(1), the mirror provision for an important entity, sets 0.3 to 1.4 percent of turnover, not less than EUR 7,000 and not more than EUR 7,000,000, whichever is higher. Article 52(2)-(3) and 53(2)-(3) separately fine a sole trader (EUR 5,000-25,000 essential tier, EUR 3,000-20,000 important tier) and the entity's responsible person individually (EUR 1,000-10,000 essential tier) for the same failure.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Urad Vlade Republike Slovenije za informacijsko varnost (URSIV, the Government Office for Information Security), acting through its information-security inspectors.

Settledness

As of
15 September 2026
Guidance link
https://www.gov.si/assets/vladne-sluzbe/URSIV/PR/ZInfV-1_Odgovori-na-vprasanja.pdf
Guidance body
Urad Vlade Republike Slovenije za informacijsko varnost (URSIV)
Open questions
Does Article 62(2)'s one-year transition for an entity already designated as an essential-service operator or a state-administration body under the predecessor Zakon o informacijski varnosti also reach a digital-infrastructure or digital-provider entity the predecessor Act separately regulated, or does every digital provider newly reached by Priloga 2 fall under Article 62(1)'s general eighteen-month clock instead?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 22(1) requires an essential or important entity to adopt technical, operational and organisational measures to secure the integrity, authenticity, confidentiality and availability of the network and information systems it uses for its work or to provide its services, and to prevent or reduce the impact of an incident on the recipients of its services and other services.

Article 22(2) requires those measures to follow an all-hazards approach covering at minimum management support for information and cybersecurity, personnel integrity checks before, during and after employment (cross-referencing Article 23), basic cyber-hygiene practices and training, human-resources security and access-rights management, backup management, the logging duty of Article 24, supply-chain security with minimum requirements for key suppliers, cryptography and encryption policy, and further items through paragraph 13.

Article 20 assigns responsibility for these measures to the entity's odgovorna oseba (responsible person, the individual who leads, supervises or manages a legal person's business, or is otherwise legally charged with ensuring its lawful operation, or the head of a public-administration body), who must approve the Article 22 measures, oversee their implementation, complete cybersecurity risk-management training at least every four years, and ensure regular staff training.

Article 6(1) binds an entity within Priloga 1 (Annex 1, highly critical sectors) or Priloga 2 (Annex 2, other critical sectors) that has at least 50 employees and an annual turnover or balance-sheet total of at least EUR 10 million; Article 6(2) drops that threshold for, among others, a public electronic-communications or trust-service provider, a top-level domain (TLD) registry or DNS provider, a sole national provider of the service, and a public-administration body.

Article 62(1) phases this duty in over eighteen months from the Act's 18 June 2025 commencement, to 18 December 2026, for the general population of essential and important entities; Article 62(2) held that date to one year (18 June 2026, already past) for an entity already designated as an essential-service operator under Article 6 of the predecessor Zakon o informacijski varnosti or a state-administration body designated under that Act's Article 9, which remained bound by the predecessor Act's own security requirements and penalties until its own one-year deadline passed.

This Act, the ZInfV-1, by its own Article 69(1) repeals the predecessor Zakon o informacijski varnosti (Uradni list RS, št. 30/18, 95/21, 130/22, 18/23 and 49/23), Slovenia's NIS1-era transposition, together with four implementing regulations and two general acts that carried the risk-management and security-documentation duties under it.

Article 29(3) of this Act, in the companion notification row, confirms that a provider of an online marketplace, an online search engine or a social-networking-services platform is among the essential or important entities this Article 6 scope reaches, naming them for variant notification treatment; that same population is bound by this row's Article 22 risk-management duty once it applies to them.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text
pisrs.si (Pravno-informacijski sistem Republike Slovenije), Zakon o informacijski varnosti (ZInfV-1), ID ZAKO8934, Uradni list RS, št. 40/25

Back to the example  ·  Lint your app