Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2025.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds a prevádzkovateľ základnej služby (essential-service operator) registered under Section 17, whose designation follows the sector annexes and, for a digital provider, reaches you by name where you provide a DNS service, a domain-name registration service, a cloud computing service, a data-centre service, a content delivery network, a managed service, a security service, an online marketplace, an online search engine, or a social-networking-services platform (Section 2(2)); the wider sector classes the Act also reaches (energy, transport, banking, health, water, digital infrastructure, public administration and the other Annex 1 and Annex 2 sectors) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
- Within 12 months of your registration as an essential-service operator, and graded by your own risk analysis, adopt, maintain and carry out general security measures covering at minimum: information- and cyber-security governance; vulnerability and threat management; asset and risk management; incident and event handling; business continuity, backup and disaster recovery; secure acquisition, development and configuration of your networks, systems and applications; compliance assessment and control; cryptography; human-resources security; identity and access management; network-operations security; protection against malicious code and unwanted content; system, network and communications security; event monitoring, logging and reporting; physical and endpoint security; records, privacy and information-labelling protection; supply-chain security; and procurement and use of certified ICT products, services and processes.
- Build and implement an effective mechanism for promptly informing your statutory body and responsible senior employees of cyber threats, vulnerabilities, incidents, near-misses, their possible impact, and the status of your risk treatment.
- Where you also operate a service the Act designates a "critical basic service" (broadly: a large enterprise, above the medium-enterprise threshold, active in an Annex 1 sector other than public administration, or a qualified trust service, top-level domain (TLD) registry, DNS service, or an at-least-medium-sized public electronic communications network or service), report that status to the Authority and expect a higher administrative-fine ceiling for the same duties.
- Expect the Authority's own Security Measures Decree, issued under Section 20(3), to specify the concrete manner and scope in which these measures must be carried out.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Section 31's own sanction for a breach of these duties is an administrative fine (správny delikt); this Act does not make the breach itself a criminal offence. Unauthorised access to a computer system is a separate offence under the Trestný zákon (Criminal Code), Section 247, documented in the scraping topic's computer-misuse family rather than here.
Penalty structure
The Act's own administrative-offence provision, Section 31, sets the cap for a breach of the risk-management or notification duties this instrument records in two tiers keyed to whether the essential-service operator also holds the "critical basic service" (kritická základná služba) designation under Section 18, not to a formal "essential entity"/"important entity" label; the Act does not use either of those two terms. Section 31(2) sets the general tier at the greater of EUR 7,000,000 or 1.4% of total worldwide annual turnover for the preceding accounting period, for a breach of, among others, Section 19(1) (the general security-measures duty) and Section 24(1) or (3) (the significant-incident notification duty). Section 31(3) raises the cap to the greater of EUR 10,000,000 or 2% of that turnover for the same list of breaches where the operator also runs a critical basic service under Section 18.
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Národný bezpečnostný úrad (National Security Authority, NBÚ), through its national CSIRT unit for incident handling, early warnings and the coordinated-vulnerability-disclosure function; see Section 4(a) and Section 5(5).
Settledness
- As of
- 15 September 2026
- Guidance link
- https://nis2.nbu.gov.sk
- Guidance body
- Národný bezpečnostný úrad (NBÚ)
- Open questions
- Does the National Security Authority's Security Measures Decree, issued to specify Section 20(3)'s manner and scope for carrying out the statute's own security measures, impose any distinct technical requirement beyond what Section 20(2) already lists?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 17 requires a person the sector annexes reach, including a central state-administration body and a digital provider named at Section 2(2) (DNS, domain-name registration, cloud computing, data centre, content delivery network, managed service, security service, online marketplace, online search engine or social-networking-services platform), to register as an essential-service operator (prevádzkovateľ základnej služby); a person meeting at least the medium-enterprise size threshold in an Annex 1 or Annex 2 sector registers under Section 17(1)(e).
Section 19(1) then requires the operator to adopt, maintain and carry out general security measures, within 12 months of registration and graded by its own risk analysis, covering at minimum the 18 domains Section 20(2) lists (security governance, vulnerability and threat management, asset and risk management, incident handling, business continuity and backup, secure development and acquisition, compliance monitoring, cryptography, human-resources security, identity and access management, network operations security, malware and unwanted-content protection, system, network and communications security, event logging and monitoring, physical and endpoint security, records and privacy protection, supply-chain security, and the use of certified ICT products, services and processes), and Section 19(6)(h) requires the operator to build an effective mechanism for promptly informing its statutory body and responsible senior staff about cyber threats, incidents, near-misses and risk-treatment status.
Section 18 defines a "critical basic service" (kritická základná služba) to include the exercise of a central state-administration body's functions.
It also includes, broadly, a large enterprise (above the medium-enterprise threshold) active in an Annex 1 sector other than public administration, and separately a qualified trust service, a top-level domain (TLD) registry, a DNS service, or an at-least-medium-sized public electronic communications network or service; an operator with this status must itself report it to the Authority, and it draws a higher administrative-penalty tier for the same duties.
The Act transposes NIS2 Article 21 without adopting NIS2's own "essential entity"/"important entity" labels; the National Security Authority's implementing Vyhláška (Decree) on security measures, referenced at Section 20(3), specifies the manner and scope in which these measures are carried out.
When LexLint raises it
operates_social_platform