Law / Slovakia

Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification

Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 January 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds a prevádzkovateľ základnej služby (essential-service operator) registered under Section 17, whose designation follows the sector annexes and, for a digital provider, reaches you by name where you provide a DNS service, a domain-name registration service, a cloud computing service, a data-centre service, a content delivery network, a managed service, a security service, an online marketplace, an online search engine, or a social-networking-services platform (Section 2(2)); the wider sector classes the Act also reaches (energy, transport, banking, health, water, digital infrastructure, public administration and the other Annex 1 and Annex 2 sectors) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
  • Report without undue delay, and no later than 24 hours after becoming aware of it, an early warning of a significant cyber security incident, stating in particular whether it may have been caused by unlawful conduct or may have a cross-border effect.
  • No later than 72 hours after becoming aware of it, report a notification updating and completing the early warning, in particular an initial assessment of the incident's severity and impact.
  • On the CSIRT unit's request, report updated or other requested information about how the incident is progressing.
  • No later than one month after the 72-hour notification, report a final report describing the incident, its severity and impact, the threat type or probable root cause, the mitigating measures taken and under way, and any cross-border impact.
  • Where a cross-border-impact incident is still ongoing when the final report is due, report an updated final report within 30 days of restoring normal network and system operation, or, if it remains unresolved at the final-report stage, within 30 days of its eventual resolution.
  • Through the same reporting system, also report a significant cyber threat you become aware of, a near-miss event that could have caused a significant incident, and a vulnerability in your own publicly available networks or systems that you could not remediate or mitigate in reasonable time.
  • Where the EU Digital Operational Resilience Regulation (Regulation (EU) 2022/2554) applies to you as a financial entity, satisfy this duty by reporting a major ICT-related incident through that Regulation's own competent-authority channel instead.
  • Expect the Authority, through its national CSIRT unit rather than your own organisation, to hold the coordinator role for communication about a vulnerability among you, the manufacturer or supplier of the affected ICT product or service, and other affected persons.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Section 31's own sanction for a breach of the notification duty is an administrative fine (správny delikt); this Act does not make the breach itself a criminal offence.

Penalty structure

The Act's own administrative-offence provision, Section 31, sets the cap for a breach of the risk-management or notification duties this instrument records in two tiers keyed to whether the essential-service operator also holds the "critical basic service" (kritická základná služba) designation under Section 18, not to a formal "essential entity"/"important entity" label; the Act does not use either of those two terms. Section 31(2) sets the general tier at the greater of EUR 7,000,000 or 1.4% of total worldwide annual turnover for the preceding accounting period, for a breach of, among others, Section 19(1) (the general security-measures duty) and Section 24(1) or (3) (the significant-incident notification duty). Section 31(3) raises the cap to the greater of EUR 10,000,000 or 2% of that turnover for the same list of breaches where the operator also runs a critical basic service under Section 18.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Národný bezpečnostný úrad (National Security Authority, NBÚ), through its national CSIRT unit for incident handling, early warnings and the coordinated-vulnerability-disclosure function; see Section 4(a) and Section 5(5).

Settledness

As of
15 September 2026
Guidance link
https://nis2.nbu.gov.sk
Guidance body
Národný bezpečnostný úrad (NBÚ)
Open questions
Does the Authority's coordinator role for vulnerability communication under Section 5(5) impose any duty directly on the manufacturer or supplier of the affected ICT product or service, or does the Authority act only as an intermediary between the essential-service operator and that manufacturer or supplier?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 24(1) requires an essential-service operator to report every significant cyber security incident (závažný kybernetický bezpečnostný incident), defined at (2) as a large-scale incident, or one that has caused or may cause serious disruption to the operator or large-scale damage or lost profit, or that has affected or may affect others with significant harm.

Section 24(3) sets the graduated clock NIS2 Article 23 requires, beginning with an early warning reported without undue delay and no later than 24 hours from detection. No later than 72 hours from detection, the operator must report a notification updating that early warning with an initial severity and impact assessment, and must report further updates on the CSIRT unit's request.

A final report is due no later than one month after that 72-hour notification, and, where a cross-border-impact incident is still ongoing at that point, an updated final report is due within 30 days of restoring normal network operation or, if it is still unresolved then, within 30 days of its eventual resolution.

Section 24(5) extends the same reporting channel to a significant cyber threat the operator becomes aware of, a near-miss event that could have caused a significant incident, and a vulnerability in the operator's own publicly available networks or systems that it could not remediate or mitigate in reasonable time.

Section 24(8) lets an operator that is a financial entity under the EU Digital Operational Resilience Regulation (Regulation (EU) 2022/2554) satisfy this duty instead by reporting a major ICT-related incident through DORA's own competent-authority channel.

Separately, Section 5(5) gives the Authority, acting through its national CSIRT unit, a coordinator role for communication about a discovered or reported vulnerability among the essential-service operator, the manufacturer or supplier of the affected ICT product or ICT service, and other affected persons, a duty the Act places on the Authority rather than on the manufacturer directly.

When LexLint raises it

  • operates_social_platform

Read the law

Consolidated text of Zákon č. 69/2018 Z. z., Slov-Lex, version effective from 30 April 2026 (amended by Zákon č. 67/2026 Z. z.)

Back to the example  ·  Lint your app