NIS2 in Slovakia — transposed on time, in its own terminology, with repeat breaches fined double.
Slovakia transposed NIS2 by amending its 2018 Cybersecurity Act — Act No. 366/2024 Coll. entered into force on 1 January 2025, making Slovakia one of the few member states that met the EU deadline. The National Security Authority (NBÚ — Národný bezpečnostný úrad) is the competent authority, with SK-CERT as the national incident-response team. Registration runs through the JISKB information system on the slovensko.sk portal; entities that fall into scope have 60 days to register.
Slovakia keeps its own vocabulary rather than adopting the directive's "essential and important" labels — operators are classified in domestic categories, including critical-essential and essential service operators — and the regime reaches beyond the directive's floor: local public administration is explicitly covered. The amendment runs on staged clocks: twelve months to implement the measures, twenty-four to the first audit, with full compliance required by 31 December 2026. Fines reach EUR 10 million or 2% of worldwide turnover, carry statutory minimums, and double for repeat breaches.
Who it applies to
Operators of critical-essential and essential services across the NIS2 sectors, plus local public administration — a Slovak extension beyond the directive minimum. Registration is through JISKB on slovensko.sk within 60 days of falling into scope. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.
The clock
Competent authority: NBÚ (National Security Authority). Transposition: Act No. 69/2018 Coll. on Cybersecurity, as amended by Act No. 366/2024 Coll..
| When | What happens |
|---|---|
| 1 Jan 2025 | Amendment 366/2024 Coll. enters into force — an on-time transposition |
| 1 Jan 2026 | Twelve-month measures clock matures for day-one entities |
| 31 Dec 2026 | Full compliance required |
| 2027 | First-audit window (24 months) opens for day-one entities |
On time, in Slovak terms, and harder on repeat offenders
Slovakia did not wait for the Commission's infringement letters: the amendment was in force on 1 January 2025. But the regime speaks its own language. Where the directive says essential and important, Slovak law classifies operators in domestic categories, and scope reaches down to local public administration — municipalities are in, not just ministries. The enforcement design is unusually pointed: minimum fines are set as a floor, not only a ceiling, and repeat breaches can be fined at double. For groups operating across Central Europe, the Slovak file cannot be a translation of the Czech or Polish one — the categories, the portal and the penalty mechanics are all national. TruSecure keeps the Slovak classification as its own record and maps it to the directive tiers, so group-level reporting stays consistent without flattening the national differences.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Slovakia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register on JISKB within 60 days of falling into scope | Entity profile · registration facts held as dated records |
| Implement the measures inside the 12-month clock | Control library · phased plan, dated milestones |
| Report incidents: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Pass the first audit inside 24 months | Audit-ready evidence · sealed exports, no re-collection scramble |
| Avoid the repeat-breach doubling | Finding closure tracked · recurrence visible before the regulator sees it |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- JISKB registration
- filed 14 Mar 2025 · slovensko.sk record accepted
- Operator category
- essential service operator · mapped to NIS2 tiers
- Measures progress
- 83/96 · 12-month clock met 18 Dec 2025
- Incident reports
- 1 filed · SK-CERT, within statutory timeframes
- Export
- sealed · sha256:b41d...09c2
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your Slovak operator category established, the measures and audit clocks mapped, and the evidence trail sealed ahead of the first audit. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Slovakia by NBÚ (National Security Authority). TruSecure determines applicability against Slovakia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.