NIS2 in Slovenia — evolving authority structures and current verification requirements.
Slovenia transposed NIS2 through national legislation, with SI-CERT operating alongside Slovenia's information security administration as the designated bodies. What makes Slovenia distinctive is the evolving nature of the authority structure — this is one of the transpositions where the precise division of enforcement authority is still settling. The current arrangement involves SI-CERT providing operational CSIRT functions alongside a separate information security administration for regulatory oversight, but this structure may continue to develop as the regime matures.
The transposition follows the standard EU structure, but the evolving authority division creates uncertainty for organizations trying to understand which body enforces which aspects of NIS2. TruSecure verifies the current designated authority directly rather than assuming a settled structure, ensuring that obligations are mapped to the regime that actually exists today. This is particularly important for Slovenia, where the authority landscape has been in flux.
Who it applies to
Essential and important entities across NIS2 sectors, with SI-CERT and the information security administration providing oversight under the evolving structure. Entities that meet the size thresholds must register and submit risk-management documentation. The evolving authority structure means verification is part of compliance.
The clock
Competent authority: SI-CERT + information security administration. Transposition: National Cybersecurity Law (NIS2 transposition).
| When | What happens |
|---|---|
| National transposition | NIS2 law enters into force · SI-CERT and information security administration designated |
| On registration | Registration · risk-management filing under current structure |
| Ongoing | Incident reporting to SI-CERT · annual compliance updates |
Evolving authority structure, ongoing verification
Slovenia's NIS2 authority structure is one of the less settled transpositions — the precise division of enforcement authority between SI-CERT and the information security administration has been evolving. This creates practical uncertainty: organizations subject to NIS2 in Slovenia must verify which body handles which aspects of compliance, not just once but as the structure develops. TruSecure tracks the current designation directly rather than assuming a settled structure, ensuring that obligations are mapped to the regime that exists today. The evolution reflects Slovenia's effort to build appropriate governance structures, but it means verification is an ongoing requirement.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Slovenia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Verify current authority division | Applicability engine · SI-CERT and information security administration roles confirmed |
| Register under current structure | Entity profile · registration under evolving governance |
| File risk-management documentation | Risk register · aligned with Slovenian NIS2 requirements |
| Report incidents to SI-CERT | Incident workflow · clocked reporting, verified channels |
| Track authority evolution | Compliance workspace · authority structure monitored for changes |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Authority verification
- current · SI-CERT operational, regulatory under information security administration
- Registration
- complete · under evolving structure
- Controls evidenced
- 39/62 · 23 open, prioritized by risk
- Authority tracking
- active · structure monitored for changes
- Export
- sealed · sha256:1c6e...9b4f
Where teams usually start
With a demo walked through by TruSecure — the current Slovenian authority structure verified, your obligations mapped to the regime that exists today with ongoing tracking as the structure evolves.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Slovenia by SI-CERT + information security administration. TruSecure determines applicability against Slovenia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.