85 days to EUDR Free quick checkFree check

Pravano · Knowledge base · Cybersecurity / NIS2

Knowledge base · Slovakia · Cybersecurity / NIS2

NIS2 in Slovakia: registration, incident reporting and security measures

Methodology: Marek Galetka, founder of Pravano. English translation of our Slovak article, which a person approved before publication; every number, date and legal reference of the translation is checked automatically against the original.

Cross-checked as of 10 September 2026 · based on primary sources

Updated 10 September 2026. Based on Act No. 69/2018 Coll. on Cybersecurity, as amended by Act No. 366/2024 Coll.. An informative readiness check, not a legal service or an official audit. Original: slovenská verzia.

Slovakia has transposed the NIS2 Directive, (EU) 2022/2555, through amendment No. 366/2024 Coll. to Act No. 69/2018 Coll. on Cybersecurity, in effect since 1 January 2025. The Slovak act does not have two regimes; it uses a single term, operator of an essential service (a Slovak term – despite the word “essential”, it covers both NIS2 categories, see below). This article summarises three key obligations: entry in the register, incident reporting and security measures.

1) Who is an operator of an essential service, and notification within 60 days

The register of operators of essential services includes, among others, any person that meets at least the size thresholds of a medium-sized enterprise and carries out an activity in one of the sectors listed in Annex 1 or Annex 2 to the act (Section 17(1)(e)). Regardless of size, it also includes selected providers of electronic communications, trust services, DNS or TLD, the sole provider of a key service and others (point (c)). An operator of a critical essential service (Section 18) is the counterpart of an essential entity; the other operators correspond to an important entity.

Anyone carrying out such an activity must notify the National Security Authority (NBÚ) within 60 days of the day on which it starts carrying out the activity (Section 17(2)). The authority makes the entry; rights and obligations arise on the day stated in the notice of entry, at the earliest on the 30th day after the entry (Section 17(5)). Failure to notify the start of the activity is punishable by a fine from €300 to €500,000 (Section 31(1)(a)).

2) Incident reporting: 24 hours, 72 hours, one month

An operator of an essential service reports every serious (in NIS2 terms, significant) cybersecurity incident through the single cybersecurity information system (JISKB) in three steps (Section 24(3)): an early warning without undue delay, at the latest within 24 hours of detection; an incident notification at the latest within 72 hours of detection (a trust service provider within 24 hours); a final report at the latest one month after the notification. At the request of the CSIRT, intermediate information is provided, and in the case of an ongoing incident with a cross-border impact, an updated final report within 30 days of the restoration of operation. Significant threats, near misses and exploitable vulnerabilities are also reported (Section 24(5)).

The deadlines correspond to Article 23(4) of Directive (EU) 2022/2555. Failure to report a serious incident is punishable by a fine from €300 to €7,000,000 or up to 1.4% of worldwide annual turnover, whichever is higher (Section 31(2)(c)); for an operator of a critical essential service up to €10,000,000 or 2% (Section 31(3)).

You are reading a general explanation. The free check will tell you whether you are an operator of an essential service and what follows from it. Start the free check →

3) Security measures within 12 months

An operator of an essential service must, within 12 months of the day of entry in the register, adopt, comply with and implement general security measures at least to the extent of Section 20, based on a risk analysis carried out (Section 19(1)). When outsourcing activities related to the operation of networks, it must conclude a contract with the third party on ensuring the security measures (Section 19(2)). The measures cover at least the areas under Section 20(2): organisation and management of security, management of vulnerabilities and threats, asset and risk management, management of events and incidents, continuity management, suppliers, personnel security, physical security, access management, network and communication security, cryptography and others. Failure to adopt the measures is punishable by a fine from €300 to €7,000,000 or 1.4% of worldwide turnover (Section 31(2)(a)).

Transitional period until 31 December 2026

Operators of essential services under the version of the act in force until 31 December 2024 (since 1 January 2025 considered operators of critical essential services, Section 34b(1)) may until 31 December 2026 also implement the measures under the previous rules (Section 34b(5)); this does not apply to former digital service providers. An audit that an operator would be required to carry out in 2025 and 2026 may be replaced by a self-assessment for categories I and II (Section 34b(8)).

Primary sources

Frequently asked questions

How do we find out whether we are an operator of an essential service?
The register includes, among others, any person that meets at least the size thresholds of a medium-sized enterprise and carries out an activity in one of the sectors listed in Annex 1 or Annex 2 to Act No. 69/2018 Coll. (Section 17(1)(e)). Regardless of size, it also includes selected providers, for example of electronic communications, trust services, DNS or TLD (point (c)).
By when do we have to notify the authority?
Anyone carrying out such an activity must notify the National Security Authority (NBÚ) within 60 days of the day on which it starts carrying out the activity (Section 17(2)). Failure to notify is punishable by a fine of €300 to €500,000 (Section 31(1)(a)).
What deadlines apply to an incident?
An early warning within 24 hours of detection, an incident notification within 72 hours (a trust service provider within 24 hours), a final report no later than one month after the notification (Section 24(3)). Reporting is done through the single cybersecurity information system.
Do we have a transitional period?
Operators of essential services under the version of the act in force until 31 December 2024 (since 1 January 2025 considered operators of critical essential services, Section 34b(1)) may until 31 December 2026 also implement the measures under the previous rules (Section 34b(5)); this does not apply to former digital service providers. An audit that an operator would be required to carry out in 2025 and 2026 may be replaced by a self-assessment for categories I and II (Section 34b(8)). A new entity has 12 months from entry in the register to adopt the measures (Section 19(1)).

This article is a general explanation, not individual legal advice. A specific overview for your company (Pravano Kompas) comes with the free check – in writing, within 2 working days.