Skip to main content
NIS2 · SLOVAKIA

NIS2 in Slovakia — transposed on time, in its own terminology, with repeat breaches fined double.

Slovakia transposed NIS2 by amending its 2018 Cybersecurity Act — Act No. 366/2024 Coll. entered into force on 1 January 2025, making Slovakia one of the few member states that met the EU deadline. The National Security Authority (NBÚ — Národný bezpečnostný úrad) is the competent authority, with SK-CERT as the national incident-response team. Registration runs through the JISKB information system on the slovensko.sk portal; entities that fall into scope have 60 days to register.

Slovakia keeps its own vocabulary rather than adopting the directive's "essential and important" labels — operators are classified in domestic categories, including critical-essential and essential service operators — and the regime reaches beyond the directive's floor: local public administration is explicitly covered. The amendment runs on staged clocks: twelve months to implement the measures, twenty-four to the first audit, with full compliance required by 31 December 2026. Fines reach EUR 10 million or 2% of worldwide turnover, carry statutory minimums, and double for repeat breaches.

Who it applies to

Operators of critical-essential and essential services across the NIS2 sectors, plus local public administration — a Slovak extension beyond the directive minimum. Registration is through JISKB on slovensko.sk within 60 days of falling into scope. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.

The clock

Competent authority: NBÚ (National Security Authority). Transposition: Act No. 69/2018 Coll. on Cybersecurity, as amended by Act No. 366/2024 Coll..

NIS2 in Slovakia · timeline
WhenWhat happens
1 Jan 2025Amendment 366/2024 Coll. enters into force — an on-time transposition
1 Jan 2026Twelve-month measures clock matures for day-one entities
31 Dec 2026Full compliance required
2027First-audit window (24 months) opens for day-one entities

On time, in Slovak terms, and harder on repeat offenders

Slovakia did not wait for the Commission's infringement letters: the amendment was in force on 1 January 2025. But the regime speaks its own language. Where the directive says essential and important, Slovak law classifies operators in domestic categories, and scope reaches down to local public administration — municipalities are in, not just ministries. The enforcement design is unusually pointed: minimum fines are set as a floor, not only a ceiling, and repeat breaches can be fined at double. For groups operating across Central Europe, the Slovak file cannot be a translation of the Czech or Polish one — the categories, the portal and the penalty mechanics are all national. TruSecure keeps the Slovak classification as its own record and maps it to the directive tiers, so group-level reporting stays consistent without flattening the national differences.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Slovakia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Slovakia requirements · how TruSecure answers them
What the law asksWhere it is answered
Register on JISKB within 60 days of falling into scopeEntity profile · registration facts held as dated records
Implement the measures inside the 12-month clockControl library · phased plan, dated milestones
Report incidents: 24 h, 72 h, one monthIncident workflow · clocked from awareness, stages pre-built
Pass the first audit inside 24 monthsAudit-ready evidence · sealed exports, no re-collection scramble
Avoid the repeat-breach doublingFinding closure tracked · recurrence visible before the regulator sees it

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Slovakia NIS2 readiness file · excerptSample data
JISKB registration
filed 14 Mar 2025 · slovensko.sk record accepted
Operator category
essential service operator · mapped to NIS2 tiers
Measures progress
83/96 · 12-month clock met 18 Dec 2025
Incident reports
1 filed · SK-CERT, within statutory timeframes
Export
sealed · sha256:b41d...09c2

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your Slovak operator category established, the measures and audit clocks mapped, and the evidence trail sealed ahead of the first audit. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Slovakia by NBÚ (National Security Authority). TruSecure determines applicability against Slovakia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Does Slovakia use the NIS2 "essential and important" labels?
No — Slovakia keeps its own operator categories, including critical-essential and essential service operators. TruSecure records your Slovak category and maps it to the directive's tiers so cross-border reporting stays consistent.