Slovakia transposed the NIS2 Directive (Directive (EU) 2022/2555) on time through Zákon č. 366/2024 Z. z., approved by the National Council on 28 November 2024 and in force since 1 January 2025, amending the existing Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti (Cybersecurity Act) rather than restating it in a fresh instrument; two further amendments (Zákon č. 318/2025 Z. z. and Zákon č.
67/2026 Z. z., effective 1 January 2026 and 30 April 2026 respectively) have since adjusted the same consolidated text, which is the version read here.
The amended Act binds an essential-service operator (prevádzkovateľ základnej služby), a category that reaches a medium or larger enterprise in a named sector and a public-administration body alike, and it expressly names the digital-provider slice this vocabulary can flag: a DNS, domain-registration, cloud computing, data-centre, content-delivery-network, managed-service, security-service, online marketplace, online-search-engine or social-networking-platform provider.
Its Section 19 and Section 20 set a general security-measures duty across 18 named domains, backstopped by a National Security Authority (Národný bezpečnostný úrad, NBÚ) Decree that specifies their manner and scope, and its Section 24 sets NIS2's own graduated notification clock (24-hour early warning, 72-hour notification, one-month final report), extended to a significant threat, a near-miss and an unremediated vulnerability in the operator's own networks.
Rather than adopting NIS2's "essential entity"/"important entity" labels, the Act layers a "critical basic service" (kritická základná služba) designation, broadly a large-enterprise or specially critical subset of essential-service operators under Section 18, onto the same register: an operator without that designation faces an administrative fine of up to the greater of EUR 7,000,000 or 1.4% of worldwide turnover for breaching these duties, one with it up to the greater of EUR 10,000,000 or 2%, mirroring NIS2 Article 34's own two tiers in substance if not in name.
A separate provision gives the Authority's national CSIRT unit, not the manufacturer, the coordinated-vulnerability-disclosure role for a vulnerability reported about an ICT product or service.
No located Slovak instrument sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and is not restated here, and no located instrument sets a general reasonable-security or information-security-programme duty with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the GDPR Article 33-34 breach-notification duty to the Úrad na ochranu osobných údajov (Office for Personal Data Protection) that Zákon č.
18/2018 Z. z. gives effect to, both of which sit in the privacy topic rather than here. The broader sector classes the Act reaches by designation (energy, transport, banking, health, water, digital infrastructure and public administration) are not expressed by any activity in this vocabulary and are recorded here as law the lint does not yet reach, rather than flagged on a guess; only the digital-provider slice is flagged.