Slovakia NIS2 compliance — NBU cybersecurity authority and automotive sector OT obligations under the Slovak Cybersecurity Act

Slovakia’s NIS2 Cybersecurity Act: How Operators Register with NBU and Meet Compliance Obligations in 2026

Slovakia produces approximately 993,000 vehicles per year — Volkswagen in Bratislava, KIA in Žilina, Stellantis in Trnava, and Jaguar Land Rover in Nitra — from a population of 5.4 million, making it the world’s largest car manufacturer per capita. Motor vehicle manufacturing is explicitly listed under Annex II of the Slovak Cybersecurity Act (Act No. 366/2024 Coll.), which transposed the NIS2 Directive into Slovak law on 1 January 2025. That combination — a legally binding cybersecurity framework and a manufacturing economy built on complex industrial control systems — creates compliance obligations that go deeper than most NIS2 country guides address.

The competent authority is the Národný bezpečnostný úrad (NBU), Slovakia’s National Security Authority, which maintains the official register of essential and important entities and oversees enforcement. The national CSIRT is SK-CERT, operating 24/7 for incident response. If your organisation was in scope as of January 2025, registration with the NBU was due by 1 March 2025. Security measures must be implemented within 12 months of registration; external audits for essential entities are required within 24 months.

This guide covers the Slovak legal framework, who must comply, the NBU registration process, post-registration compliance obligations, incident reporting requirements, and why Slovakia’s automotive OT environment demands specific security attention beyond the standard NIS2 checklist. For background on the EU-level Directive, see our complete NIS2 Directive guide.

The Slovak Legal Framework — Zákon o kybernetickej bezpečnosti

Slovakia transposed the NIS2 Directive through Act No. 366/2024 Coll., which amended the existing Cybersecurity Act No. 69/2018 Coll. — formally the Zákon o kybernetickej bezpečnosti. The National Council approved the amendment on 28 November 2024; it was published in the Collection of Laws on 19 December 2024 and entered into force on 1 January 2025.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Slovakia missed the EU’s October 17, 2024 transposition deadline — the European Commission sent formal notices to Slovakia and 22 other Member States for late transposition — but completed the process within the same calendar year. The 2024 Act does not replace Act 69/2018 wholesale; it extends and significantly strengthens existing provisions. Organisations previously regulated under Slovakia’s NIS1 framework were not automatically in compliance and were required to re-register and adopt revised security measures under the new rules.

Two Slovakia-specific expansions are worth noting. First, the Slovak Act explicitly adds thermal energy and district heating/cooling services to the regulated sector list — categories not present in the EU Directive’s Annex I baseline. Second, the Act introduced mandatory certification requirements for certain ICT services that go beyond ISO 27001 or the standard NIS2 technical baseline, meaning ISO certification alone does not satisfy Slovak audit requirements.

Secondary implementing ordinances specifying detailed technical security measures were developed during 2025. Regulated entities should monitor nis2.nbu.gov.sk for current guidance as these instruments are updated.

Who Must Comply with the Slovak Cybersecurity Act

The Slovak Act applies to entities that meet both a sector condition and a size condition. For the full EU-level scope analysis, see our guide to who must comply with NIS2. The Slovak framework distinguishes two regulated categories:

Category Size Threshold Supervision Model Audit Requirement
Essential entities 250+ employees or €50M+ annual turnover Proactive, continuous External audit every 2 years
Important entities 50–249 employees or €10M–€50M turnover Reactive, risk-based Risk-based audit schedule
Size-exempt entities Any size Same as essential As for essential entities

Size-exempt entities — covered regardless of employee count or revenue — include DNS resolution providers, top-level domain name registries, cloud computing providers, data centre operators, content delivery networks, and social networking platforms.

Regulated sectors span two annexes under the Slovak Act:

Annex I (highly critical sectors): energy (electricity, gas, oil, hydrogen, plus thermal energy and district heating — Slovak additions), transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Annex II (other critical sectors): postal and courier, waste management, chemicals, food production, manufacturing (motor vehicles and trailers; electrical equipment; computer, electronic, and optical products), digital providers, and research.

A practical decision flow to determine your status:

  • 250+ employees or €50M+ annual turnover AND operating in an Annex I or II sector in Slovakia → Essential entity
  • 50–249 employees or €10M–€50M annual turnover AND operating in an Annex I or II sector → Important entity
  • Providing DNS, cloud, data centre, or CDN services — regardless of size → Essential entity obligations
  • Manufacturing motor vehicles, electrical equipment, or computer/electronic/optical products with 50+ employees or €10M+ turnover → Important entity at minimum

Estimates of the total regulated population range from approximately 3,500 directly regulated operators to over 10,000 organisations when supply-chain-adjacent entities newly drawn into scope are included. The NBU does not determine scope applicability for individual private entities — organisations must self-identify. Where classification is uncertain, seek legal advice from a firm experienced in Slovak cybersecurity law before the registration deadline passes.

NBU — Slovakia’s National Competent Authority

The Národný bezpečnostný úrad (NBU) is Slovakia’s national competent authority, national supervisory authority, and single point of contact under NIS2. Its mandate covers:

  • Maintaining the official register of essential and important entities
  • Issuing binding supervisory decisions and corrective orders
  • Conducting inspections and audits of regulated entities
  • Imposing administrative penalties for non-compliance
  • Coordinating with ENISA and other EU member state competent authorities
  • Operating the primary incident notification channel (incident@nbu.gov.sk)

Slovakia’s implementation follows a centralised model: the NBU oversees all regulated sectors rather than delegating to sector-specific regulators such as a financial authority or energy regulator. For organisations spanning multiple sectors, this simplifies the compliance interface — one authority to register with, one channel to report to.

The NBU is headquartered at Budatínska 30, 851 06 Bratislava (podatelna@nbu.gov.sk / +421 2 6869 2318, office hours 07:30–15:30). The NIS2 registration portal is at nis2.nbu.gov.sk.

One operational point: the NBU does not proactively notify organisations that they are in scope. Entities must self-identify their status and register independently. Missed registration is itself a sanctionable failure, and the full penalty range — including personal liability for management — applies from the point obligations were first triggered.

SK-CERT — Slovakia’s National CSIRT

SK-CERT (the Slovak Computer Security Incident Response Team) operates within the NBU as Slovakia’s national CSIRT under the NIS2 framework. SK-CERT handles the operational incident response function distinct from the NBU’s regulatory mandate:

  • Receives and processes significant incident reports from regulated entities
  • Provides technical assistance during active cyber incidents
  • Coordinates cross-border incidents within the EU CSIRT Network
  • Produces threat intelligence and cyber awareness publications

SK-CERT operates 24/7 — unlike the NBU’s business hours — reflecting its role as the real-time operational response function. Contact: sk-cert@nbu.gov.sk / +421 2 6869 2915 (office hours) / +421 903 993 706 (24/7 mobile). For incident reports specifically: incident@nbu.gov.sk or the online form at nis2.nbu.gov.sk. SK-CERT receives the notification; the NBU handles subsequent regulatory assessment and any enforcement follow-up.

Slovakia’s Automotive OT Compliance Challenge

Slovakia’s NIS2 landscape has a dimension that country-specific compliance guides consistently omit: an extraordinary concentration of automotive manufacturing OT environments relative to the economy’s size.

In 2024, Slovakia’s four major assembly plants produced approximately 993,000 vehicles:

Plant Location 2024 Output
Volkswagen Slovakia Bratislava ~341,111 units
Kia Motors Slovakia Žilina ~351,270 units (plant record)
Stellantis (Peugeot Citroën) Trnava ~220,000 units (est.)
Jaguar Land Rover Nitra ~150,000 units (est.)

The automotive sector contributes approximately 12–13% of Slovakia’s GDP and supports around 275,000 direct and indirect jobs, backed by more than 365 domestic first- and second-tier suppliers. Slovakia has held the position of world’s largest vehicle manufacturer per capita since 2007.

Under Act No. 366/2024, motor vehicle and trailer manufacturing is classified under Annex II as a critical sector. The four OEMs above are large enterprises — well above the 250-employee and €50M-turnover thresholds — and qualify as essential entities subject to the most demanding supervisory regime: proactive NBU supervision and external audits by accredited Conformity Assessment Bodies every two years.

Why OT environments are the specific challenge: Modern automotive assembly integrates interconnected IT (ERP, PLM, supply chain systems) with Operational Technology — industrial control systems, SCADA, robotic assembly lines, machine vision, and quality inspection systems. The IT/OT network boundary is a documented security weakness. Attackers who gain IT network access can move laterally into production environments where no segmentation exists. Under the Slovak Cybersecurity Act, that gap is a compliance failure, not merely a technical recommendation. Essential entities must conduct risk assessments covering both IT and OT environments, implement IT/OT network segmentation, and produce business continuity plans that specifically address OT disruption scenarios — not only IT outages.

The supply chain cascade: The Slovak Act applies higher obligations to series production manufacturers, including an explicit requirement to ensure cybersecurity throughout the supply chain. Volkswagen, KIA, Stellantis, and JLR in Slovakia are not only managing their own NIS2 obligations — they must extend security requirements contractually through their supplier networks. For the 365+ domestic Slovak suppliers: if your organisation qualifies as a medium or large enterprise in manufacturing, you have independent obligations to register with the NBU. Your OEM customer’s contractual cybersecurity requirements run in parallel to, not instead of, your direct regulatory compliance duties.

Registering with the NBU — Step by Step

Registration is mandatory and proactive. The NBU does not trigger it — organisations must self-identify and file independently. The process:

Step 1: Confirm scope classification. Verify that your organisation meets the sector (Annex I or II) and size thresholds (50+ employees or €10M+ turnover). Seek legal advice if classification is uncertain — misclassification exposes the organisation and its management to penalties from the point obligations were triggered.

Step 2: Access the registration portal. Navigate to nis2.nbu.gov.sk and follow the link to the central public administration portal at slovensko.sk. Registration requires a qualified electronic signature or Slovak electronic ID card (eID).

Step 3: Complete the notification form. Required information includes:

  • Organisation name, legal form, and company registration number
  • Sector and subsector classification (Annex I or II) under the Slovak Act
  • Address(es) of all establishments where regulated services are provided
  • Designated security contact name and contact details
  • Legal representative information
  • EU Member States where services are provided (required for cross-border operators)
  • IP address ranges (required for digital infrastructure providers)

Step 4: Submit and maintain. Any subsequent changes to registered information must be reported via the portal. Registration is an ongoing obligation, not a one-time filing.

Entity Status Registration Deadline
Entities in scope as of 1 January 2025 1 March 2025 — file immediately if not yet done
New entities / newly in-scope organisations Within 60 days of commencing regulated activities
After registration is processed 30 days until full legal obligations apply

Compliance Obligations After Registration

Registration triggers a phased compliance timeline:

Phase Deadline Obligation
Registration active 30 days post-registration Full legal obligations begin
Security measures 12 months post-registration All technical and organisational measures implemented
First audit 24 months post-registration External audit (essential entities) or self-assessment (important entities)
Ongoing Continuous Incident reporting, monitoring, policy maintenance

Core security obligations under the Slovak Cybersecurity Act, aligned with NIS2 Article 21:

  • Risk analysis and documented information security policies
  • Incident handling, response, and post-incident review procedures
  • Business continuity and disaster recovery — for manufacturing entities, this must explicitly address OT system disruptions, not only IT outages
  • Supply chain security covering direct suppliers, subcontractors, and service providers
  • Security in network and information systems acquisition, development, and maintenance
  • Policies to assess the effectiveness of cybersecurity controls (metrics and KPIs)
  • Cybersecurity hygiene practices and mandatory cybersecurity training for all staff
  • Use of cryptography and encryption where appropriate
  • Human resources security, access control, and asset management policies
  • Physical security of ICT assets and facilities
  • Multi-factor authentication and secure communications systems

Management accountability is explicit in the Slovak Act. Statutory representatives — board members and directors — must formally approve the risk management framework, oversee its implementation, and personally complete cybersecurity training. Every incident notification and risk log requires a digital signature by a statutory representative. The Act enables personal liability for serious compliance failures; this accountability cannot be delegated away contractually or structurally.

ISO 27001 certification provides a useful framework but does not satisfy Slovak audit expectations. Accredited Conformity Assessment Bodies now expect dynamic, mapped evidence linking security controls to timestamped operational logs — not static certification documents. If your organisation holds ISO 27001, a gap analysis against Slovak-specific audit evidence requirements is a necessary first step.

Incident Reporting to SK-CERT — The 24/72-Hour Cascade

When a significant incident occurs, the Slovak Cybersecurity Act requires a three-stage notification to SK-CERT:

Stage Deadline Required Content
Early warning Within 24 hours of awareness Initial notification; probable cause; cross-border implications if any
Incident report Within 72 hours of awareness Updated information; initial severity and impact assessment
Interim reports On SK-CERT request Status updates during ongoing incidents
Final report Within 1 month of incident report Root cause; full impact analysis; remediation steps; recurrence prevention

A “significant” incident meets either threshold under the Slovak Act: it has caused — or may cause — serious service disruption or significant financial losses; or it has affected — or may affect — other persons through significant material or immaterial damage.

For automotive manufacturers, a ransomware attack that halts production qualifies. A 24-hour production stoppage at KIA’s Žilina facility, which produced over 350,000 vehicles in 2024, carries immediate financial, contractual, and reputational consequences that meet this threshold. The 24-hour early warning window begins at the moment of awareness — not at the moment of containment. Incident response runbooks should be designed with this clock in mind.

Report via: incident@nbu.gov.sk or the online form at nis2.nbu.gov.sk. SK-CERT is reachable 24/7.

Penalties and Enforcement

Entity Category Maximum Administrative Fine
Essential entities €10,000,000 or 2% of global annual turnover — whichever is higher
Important entities €7,000,000 or 1.4% of global annual turnover — whichever is higher

Beyond financial fines, the NBU can issue binding corrective orders, suspend specific services or activities, publicly name non-compliant organisations, and impose personal implementation bans on individual management members.

The “whichever is higher” structure is significant for large multinational operators. For an automotive OEM with a global parent generating tens of billions in annual revenue, 2% of worldwide turnover vastly exceeds the €10M cap. The turnover-based calculation becomes the operative penalty measure — and this risk justifies board-level compliance attention independent of any legal obligation.

Slovakia NIS2 Compliance Checklist

  • Confirmed sector (Annex I or II) and size threshold (50+ employees or €10M+ turnover) — entity classified correctly as essential or important
  • Registered with NBU via nis2.nbu.gov.sk / slovensko.sk — deadline was 1 March 2025 for existing entities
  • Designated security contact registered with the NBU
  • Risk management framework documented and formally approved by statutory representative or board
  • Management has completed required cybersecurity training
  • Incident response procedure documented with 24h/72h/30-day escalation timelines built in
  • SK-CERT contact (incident@nbu.gov.sk) embedded in incident response runbook
  • Supply chain security obligations assessed; contractual cybersecurity requirements issued to direct suppliers
  • IT/OT network segmentation assessed and remediated (manufacturing and industrial entities)
  • Business continuity plan explicitly covers OT disruption scenarios — not only IT outages
  • Security measures implementation tracked against 12-month deadline from registration date
  • External audit or self-assessment scheduled by the 24-month mark from registration
  • ISO 27001 gap analysis completed against Slovak audit evidence requirements
  • Registration portal updated for any changes in entity information, services, or locations

Frequently Asked Questions

Does the NBU notify organisations that they are in scope?

No. The NBU does not proactively contact organisations to confirm scope inclusion. Entities must self-identify based on sector and size thresholds and register via nis2.nbu.gov.sk. Missed registration is itself a sanctionable failure; the full penalty range — including personal management liability — applies from the point obligations were first triggered.

We hold ISO 27001 certification. Does that satisfy the Slovak Cybersecurity Act?

Not fully. The Slovak Act introduced mandatory certification requirements for certain ICT services that exceed the ISO 27001 scope. More broadly, Slovak Conformity Assessment Bodies expect dynamic evidence — timestamped, role-attributed operational logs linked to specific controls — rather than static certification documents. ISO 27001 is a useful baseline, not the compliance finish line.

We are a tier 2 automotive supplier with 60 employees. Are we in scope?

Likely yes. Motor vehicle component manufacturing, electrical equipment, and computer/electronic/optical products are all Annex II sectors. At 60 employees, you exceed the 50-employee threshold for important entity classification — provided annual turnover exceeds €10M (the condition requires either threshold: 50+ employees or €10M+ turnover). Your independent obligations to register with the NBU run in parallel to any cybersecurity requirements your OEM customer imposes contractually.

What is the difference between NBU and SK-CERT in incident response?

The NBU is Slovakia’s regulatory authority — it supervises compliance, conducts audits, and imposes penalties. SK-CERT is the operational incident response team — it receives reports, provides technical assistance, and coordinates cross-border response within the EU CSIRT Network. In practice, incident@nbu.gov.sk routes to SK-CERT for operational handling; the NBU then assesses whether regulatory follow-up is required once the incident is contained.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Slovakia’s NIS2 Cybersecurity Act: How Operators Register with NBU and Meet Compliance Obligations in 2026 — illustrated infographic guide
Slovakia’s NIS2 Cybersecurity Act: How Operators Register with NBU and Meet Compliance Obligations in 2026 infographic: key facts visualised. Source: nis-2-templates.com

Sources

1. European Commission: NIS2 Directive Implementation in Slovakia

2. Lansky Law: Amendment to the Cyber Security Act — NIS 2 Transposition into Slovak Law

3. ISMS Online: NIS 2 Compliance in Slovakia — NBÚ Authority, CSIRT Response, and New Legal Deadlines

4. Eversheds Sutherland: Slovakia — EU NIS2 Directive Implementation

5. NIS2certification.eu: NIS2 Slovakia — Implementation, Obligations & Certification

6. Cyberday.ai: NIS2 in Slovakia — Guide to Zákon o kybernetickej bezpečnosti

7. Deloitte CZ-SK: The NIS2 Directive — Implications for the Automotive Sector

8. HAVEL & PARTNERS: Impact of the NIS 2 Directive on the Automotive Sector

9. Wikipedia: Automotive Industry in Slovakia

10. NIS-2-directive.com: Transposition in Slovakia

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: