How to Register with Slovakia’s NIS2 Authority: NBU, SK-CERT, and What the Cybersecurity Act Requires
On January 1, 2025, Slovakia’s Act No. 366/2024 Coll. entered into force and gave thousands of organisations 60 days to register with the Národný bezpečnostný úrad. If your organisation operates in Slovakia across any of the 15+ sectors covered by NIS2, you now answer to two cybersecurity bodies: NBU as the regulator, and SK-CERT as the operational incident responder.
Most English-language coverage treats them as interchangeable. They are not. Knowing which body does what, what Slovakia’s amended Cybersecurity Act requires beyond NIS2’s minimum, and exactly how to complete registration avoids the procedural gaps that put organisations under supervisory scrutiny before they have implemented a single security measure.
This guide covers the NBU and SK-CERT functional split, the legal basis for Slovakia’s NIS2 obligations under Act No. 69/2018 as amended, entity classification thresholds, the four-step registration process at nis2.nbu.gov.sk, compliance deadlines, and the enforcement powers NBU holds if your organisation does not comply.
NBU: Slovakia’s National Competent Authority Under NIS2
NBU (Národný bezpečnostný úrad — National Security Authority) is Slovakia’s designated competent authority for cybersecurity under Directive (EU) 2022/2555 (NIS2). This designation flows from Article 8 of the Directive, which requires each Member State to designate at least one competent authority equipped with sufficient resources to supervise implementation across its territory.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Slovakia assigned NBU a dual mandate beyond the minimum required. It serves both as the national competent authority (NCA) — the body that supervises and enforces compliance — and as the national single point of contact (SPOC), the body responsible for coordinating cross-border and cross-sectoral information exchange with counterpart authorities across the EU. Article 8 requires Member States to notify the Commission of their designated SPOC and NCA; the Commission maintains a public list of all SPOC designations across Member States. NBU fulfils both roles simultaneously.
NBU’s supervisory toolkit is broad. The authority maintains the official register of essential and important entities, conducts both proactive and reactive compliance audits, issues binding corrective instructions to non-compliant organisations, can temporarily suspend services in the most serious cases, and can prohibit specific management officers from holding cybersecurity leadership positions. Where sector-specific co-regulators have jurisdiction alongside NBU (detailed in the scope section), NBU retains its coordinating function above them.
One function NBU deliberately does not perform: determining whether a private-sector entity falls within the law’s scope. That self-assessment obligation rests with the organisation itself. NBU offers guidance, seminars, and advisory consultations — but the burden of scoping falls on the entity, not the regulator. This matters because failure to self-identify and register is itself a compliance breach, even if NBU has not directly notified you.
SK-CERT: The Operational CSIRT Within NBU
SK-CERT (Slovak Computer Emergency Response Team) is Slovakia’s national CSIRT, operating under NBU. The unit was established on January 1, 2016, when NBU was first designated as the national cybersecurity authority, and was formally reconstituted in its current structure on September 1, 2019. SK-CERT operates under Act No. 69/2018 on Cyber Security and fulfils Slovakia’s notification and reporting obligations to EU cybersecurity bodies.
The distinction between NBU and SK-CERT is practical and consequential. NBU is the regulator: it registers entities, runs audits, and imposes penalties. SK-CERT is the operational responder: it handles active incidents, issues threat alerts and security bulletins, provides technical assistance to affected organisations, and coordinates with the EU CSIRT Network. When a breach occurs, your organisation notifies SK-CERT. NBU then uses those reports to assess whether regulatory follow-up is required.
Article 11 of the NIS2 Directive defines the operational framework that Slovak law applies to SK-CERT. Under it, SK-CERT carries eight core responsibilities:
- Monitor cyber threats, vulnerabilities, and incidents at national level and provide situational awareness
- Issue early warnings, alerts, and threat notifications to regulated entities and the public
- Respond to incidents and provide on-request technical assistance to affected organisations
- Conduct dynamic risk and incident analysis, and produce regular situational reports
- Perform proactive vulnerability scanning of assets when requested by an entity
- Participate in the EU CSIRT Network for cross-border incident coordination with other Member States’ teams
- Coordinate national vulnerability disclosure under agreed responsible disclosure processes
- Support deployment of secure information-sharing systems among regulated entities
Article 11 also sets operational standards: SK-CERT must ensure high availability of its communication channels with no single points of failure, operate from secure premises, maintain 24/7 staffing, and use redundant systems and backup workspace. These requirements make SK-CERT a reliable escalation channel even during major incidents.
For regulated organisations, point 2 above creates a concrete reporting obligation: when a significant cybersecurity incident occurs, you must send SK-CERT an early warning within 24 hours of discovery, a formal incident notification within 72 hours, and a final report within one month. SK-CERT manages the technical response; NBU then determines whether the incident reveals a systemic compliance failure warranting enforcement action.
See the NIS2 incident reporting guide and Article 23 incident notification requirements for the full reporting workflow and what constitutes a significant incident.
The Legal Framework: Act No. 69/2018 and the NIS2 Amendment
Slovakia’s NIS2 obligations sit inside a single national statute: Act No. 69/2018 Coll. on Cyber Security (zákon o kybernetickej bezpečnosti), substantially amended by Act No. 366/2024 Coll.
The original Act No. 69/2018 established NBU’s cybersecurity mandate and created SK-CERT on its current legal footing. The law predated NIS2 and aligned with the original NIS1 Directive, covering a narrower set of operators across fewer sectors.
Act No. 366/2024 — passed by the National Council on November 28, 2024, published December 19, and effective January 1, 2025 — is Slovakia’s NIS2 transposition instrument. Slovakia chose an amendment-based model rather than drafting an entirely new law. This approach preserves established NBU and SK-CERT governance structures while expanding scope, thresholds, and compliance obligations to match NIS2 requirements. Slovakia missed the EU-wide October 17, 2024 transposition deadline by approximately two months; NBU has been developing secondary legislation and technical guidance throughout 2025 to specify implementation detail.
The amendment goes beyond simply copying NIS2’s minimum requirements in three specific areas:
- Mandatory ICT certification. Certain ICT products and services used by regulated entities must be certified. NIS2 Article 24 gives Member States the authority to impose certification requirements where cybersecurity gaps exist — Slovakia has exercised this authority for defined ICT service categories, making certification binding rather than voluntary for those categories.
- Sector-specific supervisory powers. Co-regulators receive explicit sector-level authority under Slovak law rather than deferring entirely to NBU. This creates a structured multi-regulator environment rather than a single-authority model.
- Enhanced supply chain security. Organisations must systematically assess and manage cybersecurity risks across their ICT supply chains, building on the supply chain security obligations in NIS2 Article 21.
The Slovakia transposition tracker at nis-2-templates.com/transposition-tracker/ summarises the EU-wide implementation status, including Slovakia’s effective date and secondary legislation timeline.
Which Organisations Must Register with NBU
NIS2 scope in Slovakia follows EU-level size thresholds and sector classifications applied through Act No. 366/2024. NBU does not proactively notify private-sector organisations that they are in scope — the self-assessment is the entity’s responsibility. You assess first, then register.
| Entity type | Employee threshold | Annual turnover | Penalty tier |
|---|---|---|---|
| Operator of essential services | 250 or more FTEs | EUR 50 million or more | Up to EUR 10M or 2% global turnover |
| Operator of critical / important services | 50 to 249 FTEs | EUR 10 million or more | Up to EUR 7M or 1.4% global turnover |
| Micro and small enterprises | Fewer than 50 FTEs | Under EUR 10 million | Generally out of scope* |
*Micro and small enterprises are out of scope unless they are sole providers of an essential service in Slovakia or are designated as critical infrastructure operators regardless of size.
Slovakia implements all NIS2 Annex I (essential) and Annex II (important) sectors. Annex I covers energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Annex II adds postal and courier services, waste management, manufacture of certain critical products, food production, digital providers, and research organisations.
For sector-specific questions, note that NBU is not the only supervisory body in every domain. Four sectoral co-regulators hold authority alongside NBU:
| Sector | Co-supervisory body |
|---|---|
| Healthcare | Ministry of Health |
| Transport | Ministry of Transport |
| Banking and financial markets | National Bank of Slovakia (NBS) |
| Public administration (security aspects) | Ministry of Interior |
NBU retains responsibility for the central entity register and cross-sector enforcement coordination even where a co-supervisor is active in a specific domain.
To determine your classification, the NIS2 scope guide covers the full sector and threshold test, and the essential vs. important entity comparison explains the practical compliance implications of each tier.
How to Register: Four Steps via nis2.nbu.gov.sk
Registration is completed entirely through NBU’s official NIS2 portal at nis2.nbu.gov.sk. There is no alternative submission route — no paper forms, no email submissions.
Step 1 — Complete the self-assessment. Before opening the portal, confirm that your organisation meets the size and sector thresholds above. NBU does not determine scope for private-sector entities: the assessment is yours to complete. NBU provides advisory seminars and will consult with organisations uncertain about their status, but the classification must be resolved before submission.
Step 2 — Gather required registration information. The portal form requires the following:
- Legal entity name and company registration number
- Registered address
- Sector and sub-sector classification under NIS2 Annex I or Annex II
- IP address ranges and network identifiers covering the in-scope services
- Designated compliance officer — name, role, and contact details
Step 3 — Submit through nis2.nbu.gov.sk. Access the registration section and complete the electronic form. Having the required information assembled before starting reduces errors and the risk of a resubmission request from NBU.
Step 4 — Await confirmation and register entry. NBU reviews submissions and adds confirmed entities to the official register of essential and important entities. Once listed, your organisation falls under NBU’s ongoing supervisory jurisdiction and the compliance clock starts running against the milestones in the next section.
Deadline note: organisations operating in scope on January 1, 2025 were required to register by March 1, 2025. New entities commencing in-scope activities after that date must register within 60 days of beginning those activities. If your organisation has not yet registered, register promptly and seek advice from a Slovak legal professional about your specific exposure.
Compliance Timeline After Registration
Registration is not the end — it triggers a structured compliance schedule with two major milestones and a continuous incident reporting obligation.
| Milestone | Deadline | What it requires |
|---|---|---|
| Self-assess and register | March 1, 2025 (existing operators); 60 days from commencing activities (new entities) | NBU portal submission at nis2.nbu.gov.sk |
| Cybersecurity policies and technical measures | January 1, 2026 | Full Article 21 risk management framework: risk analysis, incident handling, business continuity, supply chain security, access control, cryptography, HR security, and multi-factor authentication |
| First compliance audit | January 1, 2027 | Internal or third-party audit demonstrating that implemented measures meet Act 366/2024 requirements |
| Incident reporting | Ongoing — immediate obligation upon registration | 24-hour early warning to SK-CERT; 72-hour formal notification; 30-day final report for each significant incident |
The January 2026 security measures deadline is the next significant horizon for organisations that completed registration on time. The NIS2 compliance checklist maps the full Article 21 requirements against implementation steps.
Penalties and NBU’s Enforcement Powers
NBU’s enforcement toolkit under Act No. 366/2024 creates accountability at both organisational and personal level. Financial penalties apply to the entity; management liability under Article 20 of the NIS2 Directive extends to individual board members and senior executives.
| Entity type | Maximum fine | Revenue alternative |
|---|---|---|
| Operators of essential services | EUR 10,000,000 | 2% of global annual turnover (whichever is higher) |
| Operators of critical / important services | EUR 7,000,000 | 1.4% of global annual turnover (whichever is higher) |
NBU applies whichever is higher — the fixed ceiling or the revenue-based percentage. For large multinationals, the revenue figure often exceeds the fixed cap, meaning actual exposure scales with global turnover regardless of the nominal maximum.
Beyond financial penalties, NBU holds three additional enforcement instruments under Act No. 366/2024:
- Binding corrective instructions — NBU can require specific remediation steps with mandatory implementation timelines. Failure to comply with a binding instruction is an independent compliance breach.
- Service suspension — where an ongoing cybersecurity failure poses continuing public risk, NBU can temporarily suspend the entity’s services until the failure is remedied.
- Management officer prohibition — NBU can prohibit named individuals from holding cybersecurity leadership roles, creating direct personal consequences that go beyond organisational fines.
NIS2 Article 20 — which Act No. 366/2024 incorporates into Slovak law — places governance obligations on management bodies directly: management must approve and oversee the organisation’s cybersecurity risk management measures, and can be held personally liable for infringements. Article 20 also requires management body members to complete cybersecurity training, with organisations encouraged to extend comparable training to all relevant staff. This marks a significant shift from the NIS1 era, where liability was typically organisational rather than personal.
In serious non-compliance cases, NBU can also publicly name the entity — a reputational consequence that matters particularly for organisations dealing with enterprise clients, public procurement, or regulated supply chains.
Frequently Asked Questions
Is NBU the same as SK-CERT?
No. NBU is the regulatory and supervisory authority — it registers entities, conducts audits, and imposes penalties. SK-CERT is the operational incident response unit within NBU. You register with NBU via nis2.nbu.gov.sk; you report incidents to SK-CERT. The two functions are complementary but distinct, and interacting with one does not substitute for the other.
My company is headquartered in another EU Member State but operates in Slovakia. Do we register with NBU?
It depends on the jurisdiction rules under NIS2. Article 26 of the Directive determines which Member State holds primary supervisory authority, based on where the entity is established for purposes of the Directive. See the Article 26 jurisdiction guide for the applicable test.
We missed the March 2025 registration deadline. What should we do?
Register now at nis2.nbu.gov.sk. The 60-day obligation under Act No. 366/2024 applies from the point in-scope activities commenced. Continued non-registration compounds exposure with each passing month. Seek advice from a qualified Slovak legal professional for guidance specific to your situation.
Does NBU confirm our scope classification before we register?
No. NBU explicitly does not determine scope for private-sector entities — the self-assessment obligation rests with the organisation. NBU offers advisory support and training seminars, but the classification must be completed by the entity before the portal submission.
What is the role of the National Bank of Slovakia (NBS) alongside NBU?
For entities in banking and financial markets, NBS acts as a co-supervisor alongside NBU under Act No. 366/2024. NBS holds sector-specific authority for cybersecurity oversight in its domain; NBU retains the central register and cross-sector coordination function. Entities in these sectors should expect engagement from both bodies.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
[1] NIS2 — Národný bezpečnostný úrad — Official NBU NIS2 portal
[2] Amendment to the Cyber Security Act: transposition of the NIS 2 Directive into Slovak law — Lansky
[3] About SK-CERT — SK-CERT / NBU
[4] NIS 2 Compliance in Slovakia: NBU Authority, CSIRT Response, and New Legal Deadlines — ISMS.online
[5] NIS 2 Directive — Slovakia Transposition — nis-2-directive.com
[6] Slovakia NIS2 Implementation — Eversheds Sutherland
[7] NIS 2 Directive Article 8 — Competent Authorities and Single Points of Contact — nis-2-directive.com
[8] NIS 2 Directive Article 11 — CSIRTs — nis-2-directive.com
[9] NIS2 Slovakia: Implementation, Obligations and Certification — nis2certification.eu
[10] NIS 2 Directive Article 20 — Governance — nis-2-directive.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
