National Coordinated Vulnerability Disclosure Framework (Usklajeno razkrivanje ranljivosti): Article 17 of the Information Security Act (ZInfV-1) established a national coordinator for coordinated vulnerability disclosure in Slovenia. The coordinator acts as a trusted intermediary between the person reporting a vulnerability and the affected ICT product manufacturer, service provider or system operator. Vulnerabilities may be reported anonymously and the coordinator facilitates responsible handling and disclosure of the vulnerability.
Sources: https://pisrs.si/pregledPredpisa?id=ZAKO8934 (Article 17)
https://www.gov.si/novice/2025-07-01-usklajeno-razkrivanje-ranljivosti-in-evropska-podatkovna-zbirka-ranljivosti/
SI-CERT Vulnerability Reporting and Coordination Service: Researchers, organisations and individuals who discover a technical vulnerability can report it directly to SI-CERT. SI-CERT coordinates communication with the affected operator or vendor, protects the identity of the reporter where requested, and follows a coordinated disclosure model under which parties agree on a reasonable remediation period before public disclosure. The reporting process includes submission of technical information about the vulnerability and affected systems.
Sources: https://www.cert.si/koordinirano-razkrivanje-ranljivosti/
National Vulnerability Coordination Role under ZInfV-1: The Information Security Act assigns SI-CERT responsibility for coordinated vulnerability disclosure and requires it to act as a trusted intermediary. Where a reported vulnerability may affect entities in other EU Member States, the coordinator may cooperate with other CSIRTs through European networks. The framework also links Slovenia with the European Vulnerability Database established by ENISA.
Sources: https://pisrs.si/pregledPredpisa?id=ZAKO8934 (Article 17, Article 59)
https://www.gov.si/novice/2025-07-01-usklajeno-razkrivanje-ranljivosti-in-evropska-podatkovna-zbirka-ranljivosti/