NIS2 Slovakia: zákon o kybernetickej bezpečnosti, NBÚ & JISKB
Slovakia transposed NIS2 by amending its existing zákon o kybernetickej bezpečnosti (Act No. 69/2018 Coll.) through Act No. 366/2024 Coll., in force since 1 January 2025 and amended twice since. This page sets out who has to register with the Národný bezpečnostný úrad (NBÚ), what your deadlines actually run from, how incidents are reported through JISKB, and the fine ranges — which have a floor as well as a cap.
Introduction: NIS2 Directive & the Slovak context
Slovakia has had a dedicated Cybersecurity Act since 2018. Act No. 69/2018 Coll. on Cybersecurity established minimum cybersecurity requirements, incident-handling rules and the role of the National Security Authority (NBÚ) as the central player in national cyber governance.
The adoption of Directive (EU) 2022/2555 (NIS2) required Slovakia to substantially revise this framework. Rather than pass a new statute, Slovakia amended the existing one: Act No. 366/2024 Coll., adopted on 28 November 2024, promulgated on 19 December 2024 and in force from 1 January 2025, rewrote large parts of Act No. 69/2018 Coll. and carried NIS2 into Slovak law.
Two things follow from that choice, and both matter more than they sound. Slovak law keeps its own vocabulary — there is no “essential entity” or “important entity” in the Act, only the prevádzkovateľ základnej služby and a kritická základná služba subset. And because the Act predates NIS2, it has continued to move: it has been amended twice since the transposition, with effect from 1 January 2026 and 30 April 2026.
NIS2 implementation in Slovakia
NIS2 is implemented in Slovakia through an amendment to the zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti (Act No. 69/2018 Coll. on cybersecurity), enacted as Act No. 366/2024 Coll. The National Council adopted it on 28 November 2024; it was promulgated in the Collection of Laws on 19 December 2024 and entered into force on 1 January 2025. The amending act sets its own commencement in terms: „Tento zákon nadobúda účinnosť 1. januára 2025.“
The European Commission lists Slovakia as having transposed NIS2, with the amended Cybersecurity Act serving as the single horizontal framework. There is no separate NIS2 statute to look for.
The amendment substantially widened the regulated population, pulling in public bodies, whole sectors that had never been regulated, and — unusually — certain suppliers of the largest operators. NBÚ publishes no figure for how many organisations are now in scope, and the estimates in circulation do not agree with each other, so the only reliable answer is to run the test in the next section against your own activity.
- 1 January 2026 — NBÚ takes on the role of market surveillance authority for products with digital elements under the Cyber Resilience Act, Regulation (EU) 2024/2847.
- 30 April 2026 — scope changes in Section 17(1). Public administration IT administrators are narrowed to those subject to Category II or Category III minimum security measures, and the economic-mobilisation entry is reworded. If you concluded in 2025 that a public body was in scope, that conclusion is worth re-running.
Status
Transposed and operating. The amended Act has been in force since 1 January 2025, and the implementing decrees are published — they are not “awaited”, as older summaries still say.
Legal structure
The regime sits inside Act No. 69/2018 Coll., as amended by Act No. 366/2024 Coll., and is completed by three NBÚ decrees you can cite by number: vyhláška 227/2025 Z. z. (security measures), 226/2025 Z. z. (details of reports) and 493/2022 Z. z. (cybersecurity audit).
Supervisory approach
The Národný bezpečnostný úrad (NBÚ) leads supervision, keeps the register and issues the decrees; SK-CERT, which sits inside NBÚ, is the national CSIRT. Nine central bodies named in the Act share sectoral responsibility — see Competent authorities.
Are you a prevádzkovateľ základnej služby?
Slovak law does not use the Directive’s “essential” and “important” labels. Everyone in scope is a prevádzkovateľ základnej služby (PZS) — operator of an essential service — and a subset of those operate a kritická základná služba, a critical essential service, which carries the higher duties and the higher fines. Getting your category right decides your audit obligation and which fine band applies to you.
NBÚ sets out three tests that have to be satisfied together. Being active in a listed sector is not on its own enough.
1. Sector or subsector
Are you active in a sector or subsector in Annex 1 (high criticality) or Annex 2 of the Act? Annex 1 covers energy, transport, finance, health, water and atmosphere, digital infrastructure, B2B ICT service management, public administration and space. Annex 2 adds post and courier services, waste, chemicals, food, manufacturing, digital service providers and research.
2. Type of entity
You also have to match the type of entity described for that sector in the annex. Using a digital service does not make you a digital service provider; what counts is the specific service you provide, your role, and the statutory description.
3. Size or special standing
Most entities are assessed against Commission Recommendation 2003/361/EC. Medium means fewer than 250 staff and turnover up to EUR 50 million or a balance sheet total up to EUR 43 million. Medium and larger are typically in scope — but a number of categories are caught regardless of size.
A public body is treated differently again: central state administration bodies and other state bodies with nationwide competence are registered as operators, and a city or a regional authority is caught where disruption of its functions could significantly affect public order, security or public health. NBÚ publishes an indikatívna pomôcka, an indicative self-check tool, which it is explicit does not replace a legal assessment.
Registration & the register
There is no mass registration date in Slovak law. The duty is triggered by your activity, and every later deadline you have is measured from the day you are entered in the register — not from the Act, and not from a national deadline.
| Trigger | Deadline | Basis |
|---|---|---|
| You start performing the relevant activity | 60 days to notify NBÚ | Section 17(2) |
| You begin operating a critical essential service | Notify NBÚ (entered in the register by the authority) | Section 18(2), 18(3) |
| Entry in the register | Obligations start no earlier than 30 days after entry, as stated in your notice of entry | NBÚ registration guidance |
| Registered data changes (non-reference data) | 30 days to notify | NBÚ registration guidance |
| You apply to be removed from the register | NBÚ decides within 60 days, after consulting the relevant central body | NBÚ registration guidance |
Scope & obligations under the Slovak Act
The Slovak Act does not mirror the Directive’s labels — it keeps its own. Every regulated organisation is a prevádzkovateľ základnej služby; those running a kritická základná služba under Section 18 sit in the higher tier, face the EUR 10,000,000 / 2% fine band and must be audited rather than self-assess.
Who is in scope?
- Operators in sectors covered by NIS2 (energy, transport, ICT, electronic communications, banking, financial market infrastructures, health, water, digital infrastructure, public administration, etc.).
- Medium and large organisations meeting NIS2 size/turnover criteria, plus some size-independent providers (DNS, domain name registration, cloud, data centre, content delivery, managed and security services).
- Additional entities designated by NBÚ as operators of “basic” or “critical basic” services under national criteria.
Core obligations
- Implement risk-based cybersecurity measures under Section 20 and vyhláška 227/2025 Z. z., covering organisational, personnel, physical and technological security.
- Maintain policies, procedures and governance structures for cyber risk management, including board-level responsibility and oversight.
- Report through JISKB on the 24-hour / 72-hour / one-month chain — and note that Slovakia requires four categories to be reported, not just incidents (see Incident reporting).
- Manage supply-chain risk. Section 19(2) requires a written contract with any third party whose activity directly affects the availability, confidentiality or integrity of your networks and systems, preceded by a risk analysis, binding that third party to the security and notification duties for the life of the contract.
- Provide regular staff and management training and keep documentation and evidence ready for audits and inspections.
What your clock runs from
Notify NBÚ within 60 days of starting the activity. After entry in the register: obligations begin no earlier than 30 days later, security measures must be adopted and applied within 12 months (Section 19(1)), and the first audit or self-assessment completed within 24 months (Section 29(1)). Two comparable companies registered a year apart therefore have deadlines a year apart.
Incident reporting through JISKB
All mandatory reporting runs through the jednotný informačný systém kybernetickej bezpečnosti (JISKB) — the Cybersecurity Single Information System, at jiskb.nbu.gov.sk. A registered operator reports there; the public reporting route through SK-CERT is not a substitute for it.
An incident counts as significant where it caused or could cause serious disruption to the operator, or damage, other harm to property or lost profit on a large scale, or where it affected or could affect other persons by causing them damage, other harm or lost profit to a considerable extent. The Act also fixes objective markers elsewhere for large-scale effects, including an economic loss exceeding 0.1% of gross domestic product, more than 25,000 people affected, or material damage of more than EUR 250,000 to at least one user.
Manufacturers of products with digital elements have their own notification duties for actively exploited vulnerabilities and product-security incidents under the Cyber Resilience Act, and holders of EUCC certificates report vulnerabilities in certified ICT products under the EUCC scheme. Both also route through JISKB. Detailed reporting requirements are in vyhláška 226/2025 Z. z.
Audit & self-assessment
Slovakia requires you to prove your security measures work, on a recurring cycle, and to pay for it yourself. Whether you can self-assess or must commission a certified audit depends on whether you run a critical essential service.
| Operator of a critical essential service | Other operator of an essential service | |
|---|---|---|
| First check after entry in the register | Audit within 2 years | Within 2 years, and it may be satisfied by self-assessment through JISKB |
| Full audit backstop | Always an audit | A full audit within 5 years of entry in the register, and thereafter on the statutory cycle |
| Who may perform it | A certified cybersecurity auditor — a natural person certified by an accredited person-certifying body | |
| Report to NBÚ | Within 30 days of the audit ending, with remediation measures and their deadlines | |
A re-audit is required after every change with a significant effect on the security measures you have implemented, as well as at the interval set by decree, so this is a standing cycle rather than a one-off exercise. NBÚ may also conduct an audit at any time, or require one as a supervisory measure. Where Regulation (EU) 2022/2554 (DORA) applies to you, verification is performed under DORA instead, by a person meeting Section 29(3). The detail is in vyhláška 493/2022 Z. z.
NIS2 timeline & key dates (Slovakia)
The 31 December 2026 cliff
Section 34b of the Act carries the transitional regime, and if you were already regulated in Slovakia before 2025 it is the part of the law that affects you most. Three separate grandfathering windows all expire on 31 December 2026.
| Provision | What it does | Expires |
|---|---|---|
| Section 34b(1), (3) | Every operator under the pre-2025 law was automatically reclassified as an operator of a critical essential service from 1 January 2025. Former digital service providers became operators of essential services. | Applied on 1 Jan 2025 |
| Section 34b(2), (4) | NBÚ may decide, on its own initiative, that such an entity is not in fact an operator of a critical essential service, or not an operator at all, because it does not meet the new Section 17 or Section 18 conditions. | 31 December 2026 |
| Section 34b(5) | An operator reclassified under 34b(1) may continue to adopt and implement security measures under the pre-2025 rules instead of the current ones. | 31 December 2026 |
| Section 34b(7) | The same operators may continue to perform audits under the pre-2025 rules. | 31 December 2026 |
| Section 34b(8) | For category I and II networks and systems, audits falling due in 2025 and 2026 could be satisfied by self-assessment through JISKB, performed by the cybersecurity manager. | End of 2026 |
Sector-specific notes for Slovakia
- Energy: electricity, gas and other critical energy operators are treated as key essential entities with strict resilience and incident-reporting duties.
- Electronic communications & ICT: telecoms, internet and other ICT services are central to the Cybersecurity Act’s scope, reflecting Slovakia’s reliance on digital infrastructure.
- Industry & manufacturing: sectors like pharmaceuticals, metallurgy and chemicals are explicitly mentioned in the Act’s sector list and are often designated as essential or important entities.
- Healthcare: hospitals and other healthcare providers remain in scope as operators of essential services, with increased attention to cyber resilience and incident management.
- Public administration & critical infrastructure: central state administration bodies and other state bodies with nationwide competence are operators of a critical essential service by definition. Cities and regional authorities are caught where disruption could significantly affect public order, security or public health. Note the 30 April 2026 change: the public administration IT entry now reaches only administrators subject to Category II or Category III minimum security measures.
- Digital infrastructure & digital services: the sector where NBÚ is itself the central body. DNS providers, TLD administrators, domain name registration services and trust service providers are in scope regardless of size, and trust service providers report on a 24-hour rather than 72-hour second-stage deadline.
Penalties: the EUR ranges
Section 31 of the Cybersecurity Act sets out seven bands of administrative offence, and every one of them has a statutory minimum as well as a maximum. The Directive sets only ceilings; Slovakia adds a floor, and the floor is what actually applies to a smaller organisation.
| Provision | Range | Applies to |
|---|---|---|
| Section 31(3) | EUR 500 – EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher | Operator of a critical essential service, for the substantive duties in 31(2) |
| Section 31(2) | EUR 300 – EUR 7,000,000 or 1.4%, whichever is higher | Security measures, security documentation, failure to report a significant incident, failure to act on a reactive or protective measure |
| Section 31(1) | EUR 300 – EUR 500,000 | Failure to notify the start of activity or a change of data, failure to notify a critical essential service, out-of-date security documentation, failure to remediate within the audit deadline |
| Section 31(5) | EUR 500 – EUR 500,000 | A non-EU provider that has not designated a representative |
| Section 31(6) | EUR 300 – EUR 500,000 | TLD administrators and domain name registration services |
| Section 31(4), (7) | EUR 300 – EUR 500,000 | Failure to supply information or cooperation to NBÚ on request |
| Section 31(8)–(11) | EUR 300 – EUR 500,000 | Certification offences under Regulation (EU) 2019/881, including a non-compliant EU declaration of conformity |
What multiplies a fine, and what stops one
- Repeat within a year doubles it. Section 31(13): if the same duty is breached again within one year of the original decision becoming final, NBÚ may impose up to double the amounts.
- Negligible harm means no fine at all. Section 31(12) is mandatory, not discretionary: where the harmful consequence is negligible, or where hearing the case is punishment enough, NBÚ shall not impose a fine.
- There is a limitation period. Section 31(17): a fine may be imposed within two years of the breach being discovered and at the latest four years after it occurred.
- Payment. Section 31(18): due within 30 days of the decision becoming final. Fines are income of the state budget.
- Turnover is defined, and defined broadly. Section 31(15): total worldwide annual turnover is the sum of all revenue and income from sales of goods or services net of indirect taxes, plus any financial assistance received, converted at ECB or National Bank of Slovakia reference rates.
The enforcement ladder beyond fines
Sections 29i to 29k give NBÚ a graduated set of powers, and two of them are unusual enough to be worth stating precisely.
- Interim measures before proceedings even begin, requiring you to do, refrain from or tolerate something, or securing evidence. An appeal has no suspensive effect (Section 29i).
- Remediation orders: NBÚ may order an audit, order corrective measures, order that affected persons or the public be informed, or prohibit provision of the service until the unlawful state is cured. The prohibition applies only where there is immediate danger to life or health, other supervisory measures have failed and remediation missed its deadline — and never to a public authority or an operator providing the service under a statutory duty (Section 29j(1)).
- A ban on the people in charge. Section 29j(4) lets NBÚ bar the statutory body, a member of it, the responsible senior manager or an authorised representative from performing that function. It applies only to operators of a critical essential service, only after an audit or remediation order has been missed even in the additional deadline given, and it runs until the duties are fulfilled rather than for a fixed term. It does not apply to public authorities.
- A court may order access to be cut. Under Section 29k, on NBÚ’s motion a court may temporarily restrict customers’ access to the service, or access to the online interface through which the breach occurs, where the unlawful state persists, causes serious harm and bears the marks of a criminal offence against life, health or the safety of persons. Where the operator cannot implement the restriction, it may be imposed on a third party that objectively can.
How Slovakia differs
If you are running a multi-country NIS2 programme, these are the points where Slovakia will not behave like the template you built somewhere else.
- It amended, rather than replaced. There is no Slovak NIS2 act to find. The regime lives inside the 2018 zákon o kybernetickej bezpečnosti, which has been amended repeatedly and most recently with effect from 30 April 2026 — so the version of the text matters, and a summary written in early 2025 is now two amendments out of date.
- Different vocabulary, and it is load-bearing. No “essential entity” or “important entity”. The split is operator of an essential service against operator of a critical essential service, and it is self-declared under Section 18(2).
- Deadlines run from your registration, not from a national date. There is no Slovak equivalent of a country-wide registration deadline, whatever secondary sources say. Two comparable companies can be a year apart.
- Obligations start on a delay. Rights and duties begin no earlier than 30 days after entry in the register, as stated in your notice of entry — a short grace period most member states do not give.
- The auditor must be certified. Not merely competent or independent — certified by an accredited person-certifying body, with the audit firm liable for damage caused during the audit.
- Four reporting categories, not one. Incidents, significant threats, near misses and unremediable vulnerabilities in publicly accessible systems.
- Statutory minimum fines on every band, including the EUR 10,000,000 band, plus a daily penalty calculated as a percentage of the maximum.
- A supplier can be registered because of its customer. Section 17(1)(i) registers a third party with significant influence on cybersecurity that contracts with an operator of a critical essential service.
- Filing needs a Slovak electronic mailbox. Registration goes through slovensko.sk, not through the regulator’s own portal, and the electronic mailbox requirement is a real obstacle for foreign-owned entities.
Slovak terms you will meet in the Act
| Slovak | English |
|---|---|
| zákon o kybernetickej bezpečnosti | the Cybersecurity Act (No. 69/2018 Coll.) |
| novela | amending act — here Act No. 366/2024 Coll. |
| Národný bezpečnostný úrad (NBÚ) | National Security Authority; the Act calls it simply úrad after first use |
| prevádzkovateľ základnej služby (PZS) | operator of an essential service |
| kritická základná služba | critical essential service — the higher tier |
| ústredný orgán | central body — the sectoral authority |
| jednotný informačný systém kybernetickej bezpečnosti (JISKB) | Cybersecurity Single Information System — the reporting portal |
| bezpečnostné opatrenia | security measures |
| včasné varovanie | early warning — the 24-hour report |
| záverečná správa | final report — due one month after the 72-hour notification |
| udalosť odvrátená v poslednej chvíli | near miss |
| samohodnotenie | self-assessment |
| pokuta / penále | fine / daily penalty for delay |
| vyhláška | decree — here 227/2025, 226/2025 and 493/2022 |
How to prepare for NIS2 in Slovakia
- Run the three tests together: sector or subsector under Annex 1 or Annex 2, then type of entity as the annex describes it, then size or special standing. Check the size-independent categories and the Section 17(1)(i) supply-chain entry before concluding you are out.
- Find your notice of entry, and read the date on it. Every deadline you have runs from entry in the register. If you were regulated before 2025, check whether you are still presumed to run a critical essential service under Section 34b(1) — and note that NBÚ’s power to decide otherwise ends on 31 December 2026.
- Gap-assess against vyhláška 227/2025 Z. z., not against the Directive in the abstract — organisational, personnel, physical and technological security, driven by a documented risk analysis.
- Book the auditor early, and check the certificate. 12 months from entry to implement measures, 24 months to the first audit or self-assessment, and a full audit within 5 years if you are not critical. Only a certified cybersecurity auditor can discharge the duty, and the final report goes to NBÚ within 30 days of the audit ending.
- Set up JISKB access before you need it. Rehearse the 24-hour early warning, the 72-hour notification and the one-month final report — and make sure the people on call know that near misses and unremediable vulnerabilities are reportable too.
- Manage supply-chain risk: identify critical suppliers and update contracts with explicit cybersecurity, audit and incident-notification clauses consistent with Slovak and EU requirements.
- Use recognised frameworks: align your ISMS with ISO/IEC 27001, NIST CSF or similar to structure NIS2 compliance and make audits smoother.
- Engage leadership and boards: brief senior management on their responsibilities and potential personal exposure under the Slovak NIS2 regime and ensure cybersecurity is integrated into enterprise risk management.
