We help you get ready for NIS2 in Slovakia
Slovakia transposed NIS2 through Act 366/2024, amending its Cybersecurity Act 69/2018, supervised by the NBU.
Audit41 Readiness assesses you against the Slovak requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.
Check your Slovakia NIS2 scope- 1
Registration
2 March 2025
- 2
Measures
31 December 2026
- 3
Audit
Section 34b(8), 24 months from registration
Every 2 years, essential entities
Which tier are you?
Key entities: operators of a critical essential service. This is the higher tier, and it carries the mandatory cybersecurity audit by a certified auditor, with no self-assessment option.
Penalties
Up to 10 million EUR or 2 percent of worldwide annual turnover, whichever is higher. The NBU can double the fine for a repeat violation within a year.
Important entities: operators of an essential service that is not critical. These entities can satisfy the audit obligation by self-assessment, though they must still undergo a certified audit within the longer statutory window.
Penalties
Up to the statutory maximum, with the same repeat-violation doubling.
Your obligations under Act 69/2018 as amended
Check whether you operate an essential service under the sector and size criteria, and whether that service is a critical essential service.
Notify the NBU that you carry out a regulated activity, within the statutory window after you meet the criteria, through the NBU portal.
Appoint a cybersecurity manager responsible for your obligations under the Act.
Carry out an expert risk analysis and implement the security measures Decree 227/2025 requires, both the minimum and the general measures.
Verify the effectiveness of your measures by a cybersecurity audit within the statutory window after registration, then on the recurring cycle the Act sets.
Operators of a critical essential service: the audit must be performed by a certified auditor. Others may self-assess, but must still pass a certified audit within the longer statutory window.
Deliver the audit report to the NBU within the statutory period after it is issued, remedy any non-compliance, and inform the NBU.
Report significant incidents to the NBU under the statutory timelines.
The Slovak Act does not mandate a specific international standard. An ISO 27001 certification and its controls map usefully onto the required measures under Decree 227/2025 and give you a recognised structure, but certification does not replace the statutory measures or the cybersecurity audit.
Sectors in scope
Critical essential service is the line that matters
Slovakia treats every operator of an essential service as regulated, then draws its key line at whether that service is a critical essential service. Operators of a critical essential service face the mandatory certified audit with no lighter route, so establishing whether your service is critical is the first thing that sets your obligations.
A self-assessment route, if you are not critical
Operators that do not run a critical essential service can meet the audit obligation by self-assessment carried out by their own cybersecurity manager, rather than a certified auditor, within the standard window. They must still pass a certified audit within the longer statutory window. This lighter route is exactly the kind of preparation Audit41 Readiness is built for.
An amendment, not a new act
Slovakia did not pass a standalone NIS2 law. Act 366/2024 amends and strengthens the existing Cybersecurity Act 69/2018. Organisations already regulated under the earlier regime were not automatically compliant and had to re-register and adopt the revised measures.
The audit report goes to the regulator
The cybersecurity audit does not stay internal. The final audit report must be delivered to the NBU within the statutory period, and you must remedy and report any non-compliance it finds. The audit is a supervised checkpoint, not a private exercise.
From gap report to audit-ready
Whether you face the certified audit or the self-assessment route, most operators reach for a consultant to get there. Audit41 Readiness assesses you against the measures Decree 227/2025 requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Know where you stand on NIS2 in Slovakia
The free self-check applies the Slovak rules, tells you your entity type, and recommends the right assessment.
Check your Slovakia NIS2 scopeThis self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.