NIS2 in Slovakia — the NBU, national-security mandate, and cybersecurity within broader security oversight.
Slovakia transposed NIS2 through national legislation, with the National Security Authority (NBU — Národný bezpečnostný úrad) serving as the competent authority. What makes Slovakia distinctive is the institutional placement: cybersecurity oversight sits inside the national security authority rather than a standalone cyber-specific agency. This reflects Slovakia's approach to cybersecurity as a dimension of national security alongside intelligence, counterintelligence, and other security functions.
The transposition follows the standard EU structure, but the NBU's broader mandate shapes how oversight is delivered. For organizations subject to NIS2 in Slovakia, this means reporting to an authority that views cybersecurity through a national-security lens rather than a pure technical or regulatory domain. The NBU maintains both regulatory and operational CSIRT functions, but the institutional placement is notable and creates a distinctive authority model where cybersecurity is integrated with broader security governance.
Who it applies to
Essential and important entities across NIS2 sectors, with NBU providing oversight under its broader national-security mandate. Entities that meet the size thresholds must register and submit risk-management documentation. The national-security model does not change the compliance obligations but shapes the authority structure.
The clock
Competent authority: NBU (Národný bezpečnostný úrad). Transposition: National Cybersecurity Law (NIS2 transposition).
| When | What happens |
|---|---|
| National transposition | NIS2 law enters into force · NBU authority confirmed |
| On registration | Registration with NBU · risk-management filing |
| Ongoing | Incident reporting to NBU · annual compliance updates |
National security authority with cybersecurity mandate
Slovakia's NBU holds both national security and cybersecurity oversight functions, reflecting an approach where cybersecurity is integrated with broader security governance rather than treated as a standalone technical domain. This institutional model is distinctive: rather than creating a dedicated cyber-specific agency, Slovakia placed NIS2 enforcement inside its existing national security authority. For organizations subject to NIS2 in Slovakia, this means reporting to an authority that views cybersecurity through a national-security lens rather than a pure regulatory or technical domain.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Slovakia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with NBU | Entity profile · registration under national-security authority processes |
| File risk-management documentation | Risk register · aligned with Slovak NIS2 requirements |
| Report incidents to NBU | Incident workflow · clocked reporting, with Slovak statutory timeframes |
| Document controls and evidence | Control library · evidence collection under NBU oversight |
| Understand national-security context | Compliance workspace · NBU's broader mandate tracked |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- NBU registration
- complete · filed under national-security authority
- Authority structure
- understood · cybersecurity within national-security mandate
- Controls evidenced
- 54/73 · 19 open, with clear NBU alignment
- Incident reports
- 2 filed · both to NBU within statutory timeframes
- Export
- sealed · sha256:7d4c...3e8a
Where teams usually start
With a demo walked through by TruSecure — NBU's national-security model understood, with Slovak NIS2 requirements mapped against the EU baseline and national specifics.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Slovakia by NBU (Národný bezpečnostný úrad). TruSecure determines applicability against Slovakia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.