85 days to EUDR Free quick checkFree check

Pravano · Knowledge base · Cyber resilience / CRA

Knowledge base · Slovakia · Cyber resilience / CRA

The CRA in Slovakia: who supervises and what must be reported from 11 September 2026

Methodology: Marek Galetka, founder of Pravano. English translation of our Slovak article, which a person approved before publication; every number, date and legal reference of the translation is checked automatically against the original.

Cross-checked as of 10 September 2026 · based on primary sources

Updated 10 September 2026. Based on Act No. 69/2018 Coll., as amended by Act No. 318/2025 Coll., and Regulation (EU) 2024/2847. An informative readiness check, not a legal service or an official audit. Original: slovenská verzia.

The Cyber Resilience Act (Regulation (EU) 2024/2847) applies directly throughout the Union. Products with digital elements – smart devices, IoT and software – must be designed securely, have a vulnerability handling process and bear the CE marking, which also covers cybersecurity. What each state determines itself is the market surveillance authority. Slovakia has designated it well in advance.

Supervisory authority: the National Security Authority

The market surveillance authority for products with digital elements under Article 52(2) of the CRA is, in Slovakia, the National Security Authority (NBÚ). This is laid down by Section 5(1)(ag) of Act No. 69/2018 Coll. on Cybersecurity, as supplemented by Act No. 318/2025 Coll. with effect from 1 January 2026. The NBÚ is also the authority for NIS2 and operates the single cybersecurity information system.

Already applicable: reporting from 11 September 2026

The main obligations of the regulation apply from 11 December 2027. The reporting obligation, however, started earlier: since 11 September 2026 the manufacturer must report actively exploited vulnerabilities and severe incidents (Article 14 of the CRA), including for products it placed on the market long before. The early warning has a deadline of 24 hours from becoming aware. Reporting takes place through the single ENISA/CSIRT platform. Act No. 69/2018 Coll. does not lay down penalties for breaching the CRA; whether the general obligations and fines of Act No. 56/2018 Coll. on Conformity Assessment will apply to manufacturers, importers and distributors is not yet clear.

You are reading a general explanation. The free check will tell you which of your products fall under the CRA and what to report from 11 September 2026. Start the free check →

What this means for companies

Anyone who manufactures, or sells under their own brand, smart devices or software needs to know already now (the reporting obligation has applied since 11 September 2026) which products fall under the CRA, and to have a contact point and a process for detecting, assessing and reporting a vulnerability or incident within 24 hours. Importers and distributors verify that the product has a conformity assessment, technical documentation and a visible end of the support period; if, however, they sell the product under their own brand or substantially modify it, they have the obligations of a manufacturer.

Primary sources

Frequently asked questions

Who is the CRA supervisory authority in Slovakia?
The National Security Authority (NBÚ). The market surveillance authority for products with digital elements under Article 52(2) of Regulation (EU) 2024/2847 is the NBÚ, under Section 5(1)(ag) of Act No. 69/2018 Coll. on Cybersecurity, as supplemented by Act No. 318/2025 Coll. with effect from 1 January 2026.
What already applies from 11 September 2026?
Since 11 September 2026, the obligation to report actively exploited vulnerabilities and severe incidents under Article 14 of the CRA applies, including for products placed on the market earlier. The early warning is submitted within 24 hours of becoming aware, through the single ENISA/CSIRT platform.
Do we have to wait for a Slovak act because of the CRA?
No. The regulation applies directly. So far, Slovak law mainly designates the supervisory authority: the NBÚ (Section 5(1)(ag) of Act No. 69/2018 Coll. and Section 26(j) of Act No. 56/2018 Coll.). Fines on notified bodies for breaching Articles 39, 41, 47 and 49 of the regulation are imposed by the Slovak Office of Standards, Metrology and Testing (Section 28(6)(b) of Act No. 56/2018 Coll.). The main obligations of manufacturers follow directly from the regulation; whether the general obligations and fines of Act No. 56/2018 Coll. will also apply to manufacturers, importers and distributors is not yet clear.
Is the NBÚ also the authority for NIS2?
Yes. The NBÚ is also the authority for NIS2 (Act No. 69/2018 Coll.) and operates the single cybersecurity information system. A company that is an operator of an essential service and at the same time a manufacturer of products with digital elements therefore deals with the same authority for both areas.

This article is a general explanation, not individual legal advice. A specific overview for your company (Pravano Kompas) comes with the free check – in writing, within 2 working days.