Pravano · Knowledge base · Cyber resilience / CRA
Knowledge base · Slovakia · Cyber resilience / CRAThe CRA in Slovakia: who supervises and what must be reported from 11 September 2026
Methodology: Marek Galetka, founder of Pravano. English translation of our Slovak article, which a person approved before publication; every number, date and legal reference of the translation is checked automatically against the original.
Cross-checked as of 10 September 2026 · based on primary sources
Updated 10 September 2026. Based on Act No. 69/2018 Coll., as amended by Act No. 318/2025 Coll., and Regulation (EU) 2024/2847. An informative readiness check, not a legal service or an official audit. Original: slovenská verzia.
The Cyber Resilience Act (Regulation (EU) 2024/2847) applies directly throughout the Union. Products with digital elements – smart devices, IoT and software – must be designed securely, have a vulnerability handling process and bear the CE marking, which also covers cybersecurity. What each state determines itself is the market surveillance authority. Slovakia has designated it well in advance.
Supervisory authority: the National Security Authority
The market surveillance authority for products with digital elements under Article 52(2) of the CRA is, in Slovakia, the National Security Authority (NBÚ). This is laid down by Section 5(1)(ag) of Act No. 69/2018 Coll. on Cybersecurity, as supplemented by Act No. 318/2025 Coll. with effect from 1 January 2026. The NBÚ is also the authority for NIS2 and operates the single cybersecurity information system.
Already applicable: reporting from 11 September 2026
The main obligations of the regulation apply from 11 December 2027. The reporting obligation, however, started earlier: since 11 September 2026 the manufacturer must report actively exploited vulnerabilities and severe incidents (Article 14 of the CRA), including for products it placed on the market long before. The early warning has a deadline of 24 hours from becoming aware. Reporting takes place through the single ENISA/CSIRT platform. Act No. 69/2018 Coll. does not lay down penalties for breaching the CRA; whether the general obligations and fines of Act No. 56/2018 Coll. on Conformity Assessment will apply to manufacturers, importers and distributors is not yet clear.
What this means for companies
Anyone who manufactures, or sells under their own brand, smart devices or software needs to know already now (the reporting obligation has applied since 11 September 2026) which products fall under the CRA, and to have a contact point and a process for detecting, assessing and reporting a vulnerability or incident within 24 hours. Importers and distributors verify that the product has a conformity assessment, technical documentation and a visible end of the support period; if, however, they sell the product under their own brand or substantially modify it, they have the obligations of a manufacturer.
Frequently asked questions
Who is the CRA supervisory authority in Slovakia?
What already applies from 11 September 2026?
Do we have to wait for a Slovak act because of the CRA?
Is the NBÚ also the authority for NIS2?
This article is a general explanation, not individual legal advice. A specific overview for your company (Pravano Kompas) comes with the free check – in writing, within 2 working days.