Skip to main content
NIS2 · SLOVAKIA

NIS2 in Slovakia — the NBU, national-security mandate, and cybersecurity within broader security oversight.

Slovakia transposed NIS2 through national legislation, with the National Security Authority (NBU — Národný bezpečnostný úrad) serving as the competent authority. What makes Slovakia distinctive is the institutional placement: cybersecurity oversight sits inside the national security authority rather than a standalone cyber-specific agency. This reflects Slovakia's approach to cybersecurity as a dimension of national security alongside intelligence, counterintelligence, and other security functions.

The transposition follows the standard EU structure, but the NBU's broader mandate shapes how oversight is delivered. For organizations subject to NIS2 in Slovakia, this means reporting to an authority that views cybersecurity through a national-security lens rather than a pure technical or regulatory domain. The NBU maintains both regulatory and operational CSIRT functions, but the institutional placement is notable and creates a distinctive authority model where cybersecurity is integrated with broader security governance.

Who it applies to

Essential and important entities across NIS2 sectors, with NBU providing oversight under its broader national-security mandate. Entities that meet the size thresholds must register and submit risk-management documentation. The national-security model does not change the compliance obligations but shapes the authority structure.

The clock

Competent authority: NBU (Národný bezpečnostný úrad). Transposition: National Cybersecurity Law (NIS2 transposition).

NIS2 in Slovakia · timeline
WhenWhat happens
National transpositionNIS2 law enters into force · NBU authority confirmed
On registrationRegistration with NBU · risk-management filing
OngoingIncident reporting to NBU · annual compliance updates

National security authority with cybersecurity mandate

Slovakia's NBU holds both national security and cybersecurity oversight functions, reflecting an approach where cybersecurity is integrated with broader security governance rather than treated as a standalone technical domain. This institutional model is distinctive: rather than creating a dedicated cyber-specific agency, Slovakia placed NIS2 enforcement inside its existing national security authority. For organizations subject to NIS2 in Slovakia, this means reporting to an authority that views cybersecurity through a national-security lens rather than a pure regulatory or technical domain.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Slovakia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Slovakia requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with NBUEntity profile · registration under national-security authority processes
File risk-management documentationRisk register · aligned with Slovak NIS2 requirements
Report incidents to NBUIncident workflow · clocked reporting, with Slovak statutory timeframes
Document controls and evidenceControl library · evidence collection under NBU oversight
Understand national-security contextCompliance workspace · NBU's broader mandate tracked

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Slovakia NIS2 readiness file · excerptSample data
NBU registration
complete · filed under national-security authority
Authority structure
understood · cybersecurity within national-security mandate
Controls evidenced
54/73 · 19 open, with clear NBU alignment
Incident reports
2 filed · both to NBU within statutory timeframes
Export
sealed · sha256:7d4c...3e8a

Where teams usually start

With a demo walked through by TruSecure — NBU's national-security model understood, with Slovak NIS2 requirements mapped against the EU baseline and national specifics.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Slovakia by NBU (Národný bezpečnostný úrad). TruSecure determines applicability against Slovakia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

What is Slovakia's national NIS2 authority?
NBU (Národný bezpečnostný úrad) — Slovakia's national security authority also holds cybersecurity oversight, so NIS2 enforcement sits inside a broader national-security mandate rather than a dedicated cyber-only agency.