NIS2 Country Guide

NIS2 Slovakia: zákon o kybernetickej bezpečnosti, NBÚ & JISKB

Slovakia transposed NIS2 by amending its existing zákon o kybernetickej bezpečnosti (Act No. 69/2018 Coll.) through Act No. 366/2024 Coll., in force since 1 January 2025 and amended twice since. This page sets out who has to register with the Národný bezpečnostný úrad (NBÚ), what your deadlines actually run from, how incidents are reported through JISKB, and the fine ranges — which have a floor as well as a cap.

Slovakia In force: 1 January 2025 Notify within 60 days Authority: NBÚ / SK-CERT Last updated: 10 August 2026

Introduction: NIS2 Directive & the Slovak context

Slovakia has had a dedicated Cybersecurity Act since 2018. Act No. 69/2018 Coll. on Cybersecurity established minimum cybersecurity requirements, incident-handling rules and the role of the National Security Authority (NBÚ) as the central player in national cyber governance.

The adoption of Directive (EU) 2022/2555 (NIS2) required Slovakia to substantially revise this framework. Rather than pass a new statute, Slovakia amended the existing one: Act No. 366/2024 Coll., adopted on 28 November 2024, promulgated on 19 December 2024 and in force from 1 January 2025, rewrote large parts of Act No. 69/2018 Coll. and carried NIS2 into Slovak law.

Two things follow from that choice, and both matter more than they sound. Slovak law keeps its own vocabulary — there is no “essential entity” or “important entity” in the Act, only the prevádzkovateľ základnej služby and a kritická základná služba subset. And because the Act predates NIS2, it has continued to move: it has been amended twice since the transposition, with effect from 1 January 2026 and 30 April 2026.

Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

NIS2 implementation in Slovakia

NIS2 is implemented in Slovakia through an amendment to the zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti (Act No. 69/2018 Coll. on cybersecurity), enacted as Act No. 366/2024 Coll. The National Council adopted it on 28 November 2024; it was promulgated in the Collection of Laws on 19 December 2024 and entered into force on 1 January 2025. The amending act sets its own commencement in terms: „Tento zákon nadobúda účinnosť 1. januára 2025.“

The European Commission lists Slovakia as having transposed NIS2, with the amended Cybersecurity Act serving as the single horizontal framework. There is no separate NIS2 statute to look for.

The amendment substantially widened the regulated population, pulling in public bodies, whole sectors that had never been regulated, and — unusually — certain suppliers of the largest operators. NBÚ publishes no figure for how many organisations are now in scope, and the estimates in circulation do not agree with each other, so the only reliable answer is to run the test in the next section against your own activity.

The Act did not stop moving in January 2025. Two further amendments have taken effect since the transposition, and most published summaries of Slovak NIS2 predate both:
  • 1 January 2026 — NBÚ takes on the role of market surveillance authority for products with digital elements under the Cyber Resilience Act, Regulation (EU) 2024/2847.
  • 30 April 2026 — scope changes in Section 17(1). Public administration IT administrators are narrowed to those subject to Category II or Category III minimum security measures, and the economic-mobilisation entry is reworded. If you concluded in 2025 that a public body was in scope, that conclusion is worth re-running.

Status

Transposed and operating. The amended Act has been in force since 1 January 2025, and the implementing decrees are published — they are not “awaited”, as older summaries still say.

Legal structure

The regime sits inside Act No. 69/2018 Coll., as amended by Act No. 366/2024 Coll., and is completed by three NBÚ decrees you can cite by number: vyhláška 227/2025 Z. z. (security measures), 226/2025 Z. z. (details of reports) and 493/2022 Z. z. (cybersecurity audit).

Supervisory approach

The Národný bezpečnostný úrad (NBÚ) leads supervision, keeps the register and issues the decrees; SK-CERT, which sits inside NBÚ, is the national CSIRT. Nine central bodies named in the Act share sectoral responsibility — see Competent authorities.

Are you a prevádzkovateľ základnej služby?

Slovak law does not use the Directive’s “essential” and “important” labels. Everyone in scope is a prevádzkovateľ základnej služby (PZS) — operator of an essential service — and a subset of those operate a kritická základná služba, a critical essential service, which carries the higher duties and the higher fines. Getting your category right decides your audit obligation and which fine band applies to you.

NBÚ sets out three tests that have to be satisfied together. Being active in a listed sector is not on its own enough.

1. Sector or subsector

Are you active in a sector or subsector in Annex 1 (high criticality) or Annex 2 of the Act? Annex 1 covers energy, transport, finance, health, water and atmosphere, digital infrastructure, B2B ICT service management, public administration and space. Annex 2 adds post and courier services, waste, chemicals, food, manufacturing, digital service providers and research.

2. Type of entity

You also have to match the type of entity described for that sector in the annex. Using a digital service does not make you a digital service provider; what counts is the specific service you provide, your role, and the statutory description.

3. Size or special standing

Most entities are assessed against Commission Recommendation 2003/361/EC. Medium means fewer than 250 staff and turnover up to EUR 50 million or a balance sheet total up to EUR 43 million. Medium and larger are typically in scope — but a number of categories are caught regardless of size.

Caught regardless of size. Under Section 17(1), size is irrelevant for providers of public electronic communications networks or services, trust service providers, TLD administrators, DNS providers, domain name registration services, and anyone who is the sole provider in Slovakia of a key service or whose disruption could have a significant effect on public order, security or public health.
The supply-chain entry most summaries miss. Section 17(1)(i) registers a third party that has significant influence on cybersecurity and holds a contract with an operator of a critical essential service. You can therefore be pulled into the Slovak register through a customer relationship, without being in any Annex 1 or Annex 2 sector yourself.

A public body is treated differently again: central state administration bodies and other state bodies with nationwide competence are registered as operators, and a city or a regional authority is caught where disruption of its functions could significantly affect public order, security or public health. NBÚ publishes an indikatívna pomôcka, an indicative self-check tool, which it is explicit does not replace a legal assessment.

Registration & the register

There is no mass registration date in Slovak law. The duty is triggered by your activity, and every later deadline you have is measured from the day you are entered in the register — not from the Act, and not from a national deadline.

Trigger Deadline Basis
You start performing the relevant activity 60 days to notify NBÚ Section 17(2)
You begin operating a critical essential service Notify NBÚ (entered in the register by the authority) Section 18(2), 18(3)
Entry in the register Obligations start no earlier than 30 days after entry, as stated in your notice of entry NBÚ registration guidance
Registered data changes (non-reference data) 30 days to notify NBÚ registration guidance
You apply to be removed from the register NBÚ decides within 60 days, after consulting the relevant central body NBÚ registration guidance
How you actually file, and the practical obstacle. Registration is submitted electronically through the central public administration portal, slovensko.sk, using NBÚ’s notification form. It requires an active electronic mailbox (elektronická schránka), which is the step foreign-owned entities most often get stuck on. NBÚ then notifies your entry in the register through JISKB and delivers it to that mailbox. If you are identified in several sectors, declare them in a single submission.
Two claims about Slovak registration that are circulating and are wrong. Several English-language guides state that registration “was due by 1 March 2025”. That date does not appear in Act No. 69/2018 Coll. or in Act No. 366/2024 Coll. The same guides name nis2.nbu.gov.sk as the registration portal; that host is NBÚ’s NIS2 news microsite. Filing is through slovensko.sk, and the operational system is JISKB at jiskb.nbu.gov.sk.

Scope & obligations under the Slovak Act

The Slovak Act does not mirror the Directive’s labels — it keeps its own. Every regulated organisation is a prevádzkovateľ základnej služby; those running a kritická základná služba under Section 18 sit in the higher tier, face the EUR 10,000,000 / 2% fine band and must be audited rather than self-assess.

Who is in scope?

  • Operators in sectors covered by NIS2 (energy, transport, ICT, electronic communications, banking, financial market infrastructures, health, water, digital infrastructure, public administration, etc.).
  • Medium and large organisations meeting NIS2 size/turnover criteria, plus some size-independent providers (DNS, domain name registration, cloud, data centre, content delivery, managed and security services).
  • Additional entities designated by NBÚ as operators of “basic” or “critical basic” services under national criteria.

Core obligations

  • Implement risk-based cybersecurity measures under Section 20 and vyhláška 227/2025 Z. z., covering organisational, personnel, physical and technological security.
  • Maintain policies, procedures and governance structures for cyber risk management, including board-level responsibility and oversight.
  • Report through JISKB on the 24-hour / 72-hour / one-month chain — and note that Slovakia requires four categories to be reported, not just incidents (see Incident reporting).
  • Manage supply-chain risk. Section 19(2) requires a written contract with any third party whose activity directly affects the availability, confidentiality or integrity of your networks and systems, preceded by a risk analysis, binding that third party to the security and notification duties for the life of the contract.
  • Provide regular staff and management training and keep documentation and evidence ready for audits and inspections.

What your clock runs from

Notify NBÚ within 60 days of starting the activity. After entry in the register: obligations begin no earlier than 30 days later, security measures must be adopted and applied within 12 months (Section 19(1)), and the first audit or self-assessment completed within 24 months (Section 29(1)). Two comparable companies registered a year apart therefore have deadlines a year apart.

One organisation can hold both statuses. If you perform even one critical essential service, Section 18(2) makes you an operator of a critical essential service and you must tell NBÚ so. That single fact moves you from self-assessment to a certified audit, and from the EUR 7,000,000 / 1.4% band to the EUR 10,000,000 / 2% band.

Incident reporting through JISKB

All mandatory reporting runs through the jednotný informačný systém kybernetickej bezpečnosti (JISKB) — the Cybersecurity Single Information System, at jiskb.nbu.gov.sk. A registered operator reports there; the public reporting route through SK-CERT is not a substitute for it.

Within 24 hours of detectionvčasné varovanie, the early warning. It must state whether the incident may have been caused by unlawful conduct and whether it may have cross-border impact. Trust service providers also state the effect on their trust services.
Within 72 hours of detection — the incident notification, updating and completing the early warning with an initial assessment of the incident, its severity and its consequences. For trust service providers this deadline is 24 hours, not 72.
On request from the CSIRT unit — updated or further information about the course of the incident, within the deadline it sets.
Within one month of the 72-hour notification — the záverečná správa, a final report giving a detailed description, severity and consequences, the threat type or root cause, the mitigation applied and any cross-border effect. If the incident is still running, an updated final report follows.
Slovakia requires four things to be reported, not one. Most summaries mention only incidents. Under the Act an operator must report a significant cybersecurity incident, a significant cyber threat it becomes aware of, a near miss (udalosť odvrátená v poslednej chvíli — an event that could have caused a significant incident but was averted), and a vulnerability in publicly accessible networks and systems that could be exploited to cause a significant incident and that it could not remediate or mitigate in reasonable time.

An incident counts as significant where it caused or could cause serious disruption to the operator, or damage, other harm to property or lost profit on a large scale, or where it affected or could affect other persons by causing them damage, other harm or lost profit to a considerable extent. The Act also fixes objective markers elsewhere for large-scale effects, including an economic loss exceeding 0.1% of gross domestic product, more than 25,000 people affected, or material damage of more than EUR 250,000 to at least one user.

Two arrangements worth knowing. Where an operator’s standing, scale or activity justifies it, NBÚ may conclude a written agreement setting a different method and form of reporting. And separately from the operator regime, anyone may report voluntarily and anonymously through SK-CERT with no account and no obligation to give contact details.

Manufacturers of products with digital elements have their own notification duties for actively exploited vulnerabilities and product-security incidents under the Cyber Resilience Act, and holders of EUCC certificates report vulnerabilities in certified ICT products under the EUCC scheme. Both also route through JISKB. Detailed reporting requirements are in vyhláška 226/2025 Z. z.

Audit & self-assessment

Slovakia requires you to prove your security measures work, on a recurring cycle, and to pay for it yourself. Whether you can self-assess or must commission a certified audit depends on whether you run a critical essential service.

Operator of a critical essential service Other operator of an essential service
First check after entry in the register Audit within 2 years Within 2 years, and it may be satisfied by self-assessment through JISKB
Full audit backstop Always an audit A full audit within 5 years of entry in the register, and thereafter on the statutory cycle
Who may perform it A certified cybersecurity auditor — a natural person certified by an accredited person-certifying body
Report to NBÚ Within 30 days of the audit ending, with remediation measures and their deadlines
You cannot use just any consultant. Section 29(3) requires the audit to be performed by a certifikovaný audítor kybernetickej bezpečnosti. Where a company supplies the auditor, that company is liable for damage caused during the audit. Check certification before you sign, because an audit by an uncertified person does not discharge the duty.

A re-audit is required after every change with a significant effect on the security measures you have implemented, as well as at the interval set by decree, so this is a standing cycle rather than a one-off exercise. NBÚ may also conduct an audit at any time, or require one as a supervisory measure. Where Regulation (EU) 2022/2554 (DORA) applies to you, verification is performed under DORA instead, by a person meeting Section 29(3). The detail is in vyhláška 493/2022 Z. z.

Failing to run the cycle is itself a fineable offence. Section 31(1) covers failure to carry out the remediation within the deadline set by the audit’s final report. An organisation can be genuinely secure and still be fined for missing its audit obligations.

Competent authorities & CSIRT

Slovakia runs a centralised model around the Národný bezpečnostný úrad (NBÚ) and its national CSIRT, SK-CERT — but the Act also names its sectoral bodies, one by one, rather than leaving them to be designated later. Section 4 lists them explicitly.

Role Authority Notes
National competent authority & Single Point of Contact National Security Authority (NBÚ) Leads implementation of the Cybersecurity Act, identifies and supervises essential and important entities, issues secondary legislation and represents Slovakia in EU NIS2 cooperation.
National CSIRT National Cybersecurity Centre SK-CERT (within NBÚ) Acts as the national CSIRT, handling incident notifications, issuing alerts and supporting technical response for all sectors. Recognised by the EU as the national CSIRT and reachable 24/7.
Central bodies (ústredný orgán) Nine, named in Section 4(b) The Ministries of Transport, Finance, Economy, Defence, Interior, Health, and Environment; the Ministry of Investment, Regional Development and Informatisation; and the State Material Reserves Administration. Each is assigned to sectors by Annexes 1 and 2.
Other state administration bodies Named in Section 4(c) The General Prosecutor’s Office, the Supreme Audit Office, the Health Care Surveillance Authority, the Office for Personal Data Protection and the network industries regulator ÚRSO, each within its own competence.

Which body supervises you follows from the annex your sector sits in, not from a separate designation decision. This is the map, and it is worth checking because NBÚ is itself the central body for digital infrastructure and for digital service providers — for those sectors the regulator and the sectoral authority are the same organisation.

Sector Annex Central body
Energy1Ministry of Economy (oil reserves: State Material Reserves Administration)
Transport1Ministry of Transport
Finance1Ministry of Finance
Health1Ministry of Health
Water & atmosphere1Ministry of Environment
Digital infrastructure1Ministry of Transport, NBÚ, Ministry of Interior, Ministry of Defence
ICT service management (B2B)1Ministry of Interior
Public administration1Ministry of Investment, Regional Development and Informatisation
Space1Ministry of Interior
Post & courier services2Ministry of Transport
Waste management2Ministry of Environment
Chemicals2Ministry of Economy
Food2Ministry of Agriculture and Rural Development
Manufacturing2Ministry of Health (medical devices), Ministry of Economy (other)
Digital service providers2NBÚ
Research2Ministry of Education, Research, Development and Youth
A point of precision, if you are citing the Act. The Ministry of Agriculture and the Ministry of Education appear in the annexes as the central body for food and for research, but neither is in the list of nine that Section 4(b) defines as an ústredný orgán. They therefore act under Section 4(c) rather than under the defined term. It makes no practical difference to who supervises you; it matters if you are quoting the statute.

NIS2 timeline & key dates (Slovakia)

30 January 2018 — Cybersecurity Act (No. 69/2018 Coll.) adopted, first comprehensive Slovak cybersecurity framework.
1 April 2018 — Original Cybersecurity Act enters into force, implementing NIS1.
17 October 2024 — EU deadline for NIS2 transposition passes; the Slovak bill is before the National Council, having been submitted on 4 October 2024.
28 November 2024 — the National Council adopts Act No. 366/2024 Coll., amending the Cybersecurity Act to transpose NIS2.
19 December 2024 — Act No. 366/2024 Coll. promulgated in the Collection of Laws.
1 January 2025 — the amended Act enters into force. Existing operators are automatically reclassified as operators of critical essential services; former digital service providers become operators of essential services.
30 September 2025 — last date on which an audit that fell due in 2024 for a category I or II system could be satisfied by self-assessment.
1 January 2026 — amendment takes effect: NBÚ becomes market surveillance authority for products with digital elements under the Cyber Resilience Act.
30 April 2026 — further amendment takes effect, narrowing the public administration IT entry in Section 17(1) to Category II and III systems.
31 December 2026 — three transitional windows close together. See The 31 December 2026 cliff.
Rolling, per entity — 12 months from entry in the register to implement security measures; 24 months to the first audit or self-assessment; 5 years to a full audit for operators that are not critical.

The 31 December 2026 cliff

Section 34b of the Act carries the transitional regime, and if you were already regulated in Slovakia before 2025 it is the part of the law that affects you most. Three separate grandfathering windows all expire on 31 December 2026.

Provision What it does Expires
Section 34b(1), (3) Every operator under the pre-2025 law was automatically reclassified as an operator of a critical essential service from 1 January 2025. Former digital service providers became operators of essential services. Applied on 1 Jan 2025
Section 34b(2), (4) NBÚ may decide, on its own initiative, that such an entity is not in fact an operator of a critical essential service, or not an operator at all, because it does not meet the new Section 17 or Section 18 conditions. 31 December 2026
Section 34b(5) An operator reclassified under 34b(1) may continue to adopt and implement security measures under the pre-2025 rules instead of the current ones. 31 December 2026
Section 34b(7) The same operators may continue to perform audits under the pre-2025 rules. 31 December 2026
Section 34b(8) For category I and II networks and systems, audits falling due in 2025 and 2026 could be satisfied by self-assessment through JISKB, performed by the cybersecurity manager. End of 2026
What this means in practice. If you were regulated in Slovakia before 2025 and have not revisited your position since, you are currently presumed to run a critical essential service — the higher fine band, and a certified audit rather than self-assessment — unless NBÚ decides otherwise, and its power to decide that expires at the end of 2026. At the same time the two concessions letting you work under the old security-measures and audit rules also expire. From 1 January 2027 there is a single regime, and the fallback positions are gone.

Sector-specific notes for Slovakia

  • Energy: electricity, gas and other critical energy operators are treated as key essential entities with strict resilience and incident-reporting duties.
  • Electronic communications & ICT: telecoms, internet and other ICT services are central to the Cybersecurity Act’s scope, reflecting Slovakia’s reliance on digital infrastructure.
  • Industry & manufacturing: sectors like pharmaceuticals, metallurgy and chemicals are explicitly mentioned in the Act’s sector list and are often designated as essential or important entities.
  • Healthcare: hospitals and other healthcare providers remain in scope as operators of essential services, with increased attention to cyber resilience and incident management.
  • Public administration & critical infrastructure: central state administration bodies and other state bodies with nationwide competence are operators of a critical essential service by definition. Cities and regional authorities are caught where disruption could significantly affect public order, security or public health. Note the 30 April 2026 change: the public administration IT entry now reaches only administrators subject to Category II or Category III minimum security measures.
  • Digital infrastructure & digital services: the sector where NBÚ is itself the central body. DNS providers, TLD administrators, domain name registration services and trust service providers are in scope regardless of size, and trust service providers report on a 24-hour rather than 72-hour second-stage deadline.

Penalties: the EUR ranges

Section 31 of the Cybersecurity Act sets out seven bands of administrative offence, and every one of them has a statutory minimum as well as a maximum. The Directive sets only ceilings; Slovakia adds a floor, and the floor is what actually applies to a smaller organisation.

Provision Range Applies to
Section 31(3) EUR 500 – EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher Operator of a critical essential service, for the substantive duties in 31(2)
Section 31(2) EUR 300 – EUR 7,000,000 or 1.4%, whichever is higher Security measures, security documentation, failure to report a significant incident, failure to act on a reactive or protective measure
Section 31(1) EUR 300 – EUR 500,000 Failure to notify the start of activity or a change of data, failure to notify a critical essential service, out-of-date security documentation, failure to remediate within the audit deadline
Section 31(5) EUR 500 – EUR 500,000 A non-EU provider that has not designated a representative
Section 31(6) EUR 300 – EUR 500,000 TLD administrators and domain name registration services
Section 31(4), (7) EUR 300 – EUR 500,000 Failure to supply information or cooperation to NBÚ on request
Section 31(8)–(11) EUR 300 – EUR 500,000 Certification offences under Regulation (EU) 2019/881, including a non-compliant EU declaration of conformity
The number that usually matters more than the ceiling. Under Section 29j(2), when NBÚ orders remediation it may also impose penále of 0.5% of the maximum possible fine for that breach, for every day of delay. For an operator of a critical essential service, where the maximum is EUR 10,000,000, that is EUR 50,000 per day. A slow response to a remediation order is a larger and far more likely exposure than the headline figure.

What multiplies a fine, and what stops one

  • Repeat within a year doubles it. Section 31(13): if the same duty is breached again within one year of the original decision becoming final, NBÚ may impose up to double the amounts.
  • Negligible harm means no fine at all. Section 31(12) is mandatory, not discretionary: where the harmful consequence is negligible, or where hearing the case is punishment enough, NBÚ shall not impose a fine.
  • There is a limitation period. Section 31(17): a fine may be imposed within two years of the breach being discovered and at the latest four years after it occurred.
  • Payment. Section 31(18): due within 30 days of the decision becoming final. Fines are income of the state budget.
  • Turnover is defined, and defined broadly. Section 31(15): total worldwide annual turnover is the sum of all revenue and income from sales of goods or services net of indirect taxes, plus any financial assistance received, converted at ECB or National Bank of Slovakia reference rates.

The enforcement ladder beyond fines

Sections 29i to 29k give NBÚ a graduated set of powers, and two of them are unusual enough to be worth stating precisely.

  • Interim measures before proceedings even begin, requiring you to do, refrain from or tolerate something, or securing evidence. An appeal has no suspensive effect (Section 29i).
  • Remediation orders: NBÚ may order an audit, order corrective measures, order that affected persons or the public be informed, or prohibit provision of the service until the unlawful state is cured. The prohibition applies only where there is immediate danger to life or health, other supervisory measures have failed and remediation missed its deadline — and never to a public authority or an operator providing the service under a statutory duty (Section 29j(1)).
  • A ban on the people in charge. Section 29j(4) lets NBÚ bar the statutory body, a member of it, the responsible senior manager or an authorised representative from performing that function. It applies only to operators of a critical essential service, only after an audit or remediation order has been missed even in the additional deadline given, and it runs until the duties are fulfilled rather than for a fixed term. It does not apply to public authorities.
  • A court may order access to be cut. Under Section 29k, on NBÚ’s motion a court may temporarily restrict customers’ access to the service, or access to the online interface through which the breach occurs, where the unlawful state persists, causes serious harm and bears the marks of a criminal offence against life, health or the safety of persons. Where the operator cannot implement the restriction, it may be imposed on a third party that objectively can.

How Slovakia differs

If you are running a multi-country NIS2 programme, these are the points where Slovakia will not behave like the template you built somewhere else.

  • It amended, rather than replaced. There is no Slovak NIS2 act to find. The regime lives inside the 2018 zákon o kybernetickej bezpečnosti, which has been amended repeatedly and most recently with effect from 30 April 2026 — so the version of the text matters, and a summary written in early 2025 is now two amendments out of date.
  • Different vocabulary, and it is load-bearing. No “essential entity” or “important entity”. The split is operator of an essential service against operator of a critical essential service, and it is self-declared under Section 18(2).
  • Deadlines run from your registration, not from a national date. There is no Slovak equivalent of a country-wide registration deadline, whatever secondary sources say. Two comparable companies can be a year apart.
  • Obligations start on a delay. Rights and duties begin no earlier than 30 days after entry in the register, as stated in your notice of entry — a short grace period most member states do not give.
  • The auditor must be certified. Not merely competent or independent — certified by an accredited person-certifying body, with the audit firm liable for damage caused during the audit.
  • Four reporting categories, not one. Incidents, significant threats, near misses and unremediable vulnerabilities in publicly accessible systems.
  • Statutory minimum fines on every band, including the EUR 10,000,000 band, plus a daily penalty calculated as a percentage of the maximum.
  • A supplier can be registered because of its customer. Section 17(1)(i) registers a third party with significant influence on cybersecurity that contracts with an operator of a critical essential service.
  • Filing needs a Slovak electronic mailbox. Registration goes through slovensko.sk, not through the regulator’s own portal, and the electronic mailbox requirement is a real obstacle for foreign-owned entities.

Slovak terms you will meet in the Act

Slovak English
zákon o kybernetickej bezpečnostithe Cybersecurity Act (No. 69/2018 Coll.)
novelaamending act — here Act No. 366/2024 Coll.
Národný bezpečnostný úrad (NBÚ)National Security Authority; the Act calls it simply úrad after first use
prevádzkovateľ základnej služby (PZS)operator of an essential service
kritická základná službacritical essential service — the higher tier
ústredný orgáncentral body — the sectoral authority
jednotný informačný systém kybernetickej bezpečnosti (JISKB)Cybersecurity Single Information System — the reporting portal
bezpečnostné opatreniasecurity measures
včasné varovanieearly warning — the 24-hour report
záverečná správafinal report — due one month after the 72-hour notification
udalosť odvrátená v poslednej chvílinear miss
samohodnotenieself-assessment
pokuta / penálefine / daily penalty for delay
vyhláškadecree — here 227/2025, 226/2025 and 493/2022

How to prepare for NIS2 in Slovakia

  1. Run the three tests together: sector or subsector under Annex 1 or Annex 2, then type of entity as the annex describes it, then size or special standing. Check the size-independent categories and the Section 17(1)(i) supply-chain entry before concluding you are out.
  2. Find your notice of entry, and read the date on it. Every deadline you have runs from entry in the register. If you were regulated before 2025, check whether you are still presumed to run a critical essential service under Section 34b(1) — and note that NBÚ’s power to decide otherwise ends on 31 December 2026.
  3. Gap-assess against vyhláška 227/2025 Z. z., not against the Directive in the abstract — organisational, personnel, physical and technological security, driven by a documented risk analysis.
  4. Book the auditor early, and check the certificate. 12 months from entry to implement measures, 24 months to the first audit or self-assessment, and a full audit within 5 years if you are not critical. Only a certified cybersecurity auditor can discharge the duty, and the final report goes to NBÚ within 30 days of the audit ending.
  5. Set up JISKB access before you need it. Rehearse the 24-hour early warning, the 72-hour notification and the one-month final report — and make sure the people on call know that near misses and unremediable vulnerabilities are reportable too.
  6. Manage supply-chain risk: identify critical suppliers and update contracts with explicit cybersecurity, audit and incident-notification clauses consistent with Slovak and EU requirements.
  7. Use recognised frameworks: align your ISMS with ISO/IEC 27001, NIST CSF or similar to structure NIS2 compliance and make audits smoother.
  8. Engage leadership and boards: brief senior management on their responsibilities and potential personal exposure under the Slovak NIS2 regime and ensure cybersecurity is integrated into enterprise risk management.

Official links & resources

Slov-Lex — zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti — the binding consolidated text. Check the Časová verzia header for the version date.
NBÚ — cybersecurity guidance for operators — identification, registration, obligations, audit and reporting, each with its statutory basis.
JISKB — the Cybersecurity Single Information System — where registered operators file mandatory reports and self-assessments.
NBÚ — English translation of Act No. 69/2018 Coll.caution: this is the pre-NIS2 text. It cites Directive 2016/1148, contains none of the current fine ranges or the 24/72-hour chain, and still uses “digital service provider”. Useful for orientation only; rely on Slov-Lex.
SK-CERT — the national CSIRT — alerts, guidance, and the voluntary reporting route ([email protected]).

FAQ: NIS2 in Slovakia

Has Slovakia fully transposed NIS2?
Yes. NIS2 is implemented through the amended zákon o kybernetickej bezpečnosti (Act No. 69/2018 Coll., as amended by Act No. 366/2024 Coll.), adopted on 28 November 2024 and in force since 1 January 2025. Note that the Act has been amended twice since, with effect from 1 January 2026 and 30 April 2026.
What law should we look at for NIS2 in Slovakia?
The key instrument is Act No. 69/2018 Coll. on Cybersecurity, as amended by Act No. 366/2024 Coll., together with implementing decrees that define detailed security measures and reporting rules.
Who is the main NIS2 authority in Slovakia?
The National Security Authority (NBÚ) is the national competent authority and single point of contact. The National Cybersecurity Centre SK-CERT, operating within NBÚ, acts as the national CSIRT and incident response hub.
What are the main deadlines we should be aware of?
There is no national registration date. You must notify NBÚ within 60 days of starting the relevant activity. After you are entered in the register, obligations begin no earlier than 30 days later, security measures are due within 12 months, and the first audit or self-assessment within 24 months. An operator that is not critical must still take a full audit within five years. Separately, three transitional windows for pre-2025 operators close on 31 December 2026.
How high can fines be under the Slovak NIS2 regime?
Up to EUR 10,000,000 or 2% of total worldwide annual turnover for an operator of a critical essential service, and EUR 7,000,000 or 1.4% otherwise — but Slovak law also sets a minimum on every band, from EUR 300, which is what a smaller organisation will actually face. A repeat breach within a year can double the fine, and a remediation order can carry a daily penalty of 0.5% of the maximum — up to EUR 50,000 a day. Where the harm is negligible, Section 31(12) requires NBÚ to impose no fine at all.
Some guides say registration was due by 1 March 2025. Is that right?
No. That date appears in neither Act No. 69/2018 Coll. nor the amending Act No. 366/2024 Coll. The statutory rule is 60 days from starting the relevant activity, under Section 17(2), together with the Section 34b transitional regime for entities already regulated before 2025. The same guides often name nis2.nbu.gov.sk as the registration portal; that is NBÚ’s NIS2 news site. Registration is filed through slovensko.sk and the operational system is JISKB.
Can we do a self-assessment instead of an audit?
Only if you are not an operator of a critical essential service. Those operators must be audited. Others may satisfy the two-year deadline by self-assessment through JISKB, but NBÚ is clear that a full audit is still required within five years of entry in the register, and that self-assessment is not available during a period when an audit is due. Either way, only a certified cybersecurity auditor can perform the audit.
We are not in an Annex 1 or Annex 2 sector. Can we still be in scope?
Yes. Section 17(1)(i) registers a third party that has significant influence on cybersecurity and holds a contract with an operator of a critical essential service. Several categories are also caught regardless of size, including DNS providers, TLD administrators, domain name registration services and trust service providers.
Is ISO 27001 certification mandatory?
No. Slovakia prescribes no single mandatory standard, but the security measures in vyhláška 227/2025 Z. z. are closely aligned with ISO/IEC 27001-style controls, and many organisations use ISO 27001 or a comparable framework to structure their evidence for the audit.
Information provided for general guidance and current at 10 August 2026. Always consult the consolidated zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti on Slov-Lex, NBÚ and SK-CERT publications, and legal counsel for definitive NIS2 compliance requirements in Slovakia.