Business obligations, registers and licences · Slovakia

NIS2 and cybersecurity

The NIS2 Directive, transposed by an amendment to Act No. 69/2018 Z. z. on Cybersecurity, extended regulated entities beyond critical infrastructure to thousands of ordinary businesses in manufacturing, logistics, food, waste and digital services. We assess whether it covers you and, if so, guide you through registration, obligations and supplier agreements. We handle the legal work. Your IT team or provider handles the technical work, and we are happy to coordinate with them.

  • Assessment before documentation
  • Legal work coordinated with IT
  • Prices agreed upfront
5.0 of 70 reviews on Google

What we'll do for you

The legal and technical aspects of NIS2 are often mixed together. We handle the legal questions: whether the Act applies and under which regime, what the documentation must contain, and how to structure contracts and responsibility. Your IT team designs the technical measures, and we provide clear legal instructions.

Select an item to see the details.

  • Assessment and classification

    Based on your sector, size and activities, we assess whether you are a regulated entity and in which category. This determines the scope of obligations and sanctions. You receive a written assessment.

  • Registration

    We prepare and submit registration with the National Security Authority within the statutory time limit and establish contact details and contact persons.

  • Legal documentation

    Internal policies on risk management, incident reporting and business continuity to the extent required by law, aligned with your existing GDPR documents and internal policies.

  • Supplier agreements

    Adding security requirements to IT supplier agreements and reviewing the supply chain. NIS2 expressly addresses supply-chain security.

  • Management responsibility

    Statutory representatives are personally responsible for cybersecurity and must undergo training. We structure the allocation of duties and documentation protecting management.

Deliverablean assessment of whether the Cybersecurity Act applies to the company and legal documentation of its obligations, including supplier agreements

How it works

Does this process fit your matter? Describe it to the attorney →

  1. Assessmentday 0

    We establish whether the Act applies and under which regime. If it does not, the work ends with a written conclusion.

  2. Registration and plan

    Registration with NBÚ and a plan of obligations with deadlines, specifying what must be completed and when.

  3. Documentation and agreements

    We prepare the legal documents and amend supplier agreements. Your IT team implements technical measures based on our instructions.

  4. Ongoing complianceongoing

    Incident reports, registration changes and new guidance — we help maintain compliance.

NIS2 moved cybersecurity from the IT department into the boardroom. The amendment to the Cybersecurity Act extended obligations to thousands of companies that had not previously been considered critical infrastructure and placed responsibility on management.

We handle the legal work: assessment, registration, documentation, contracts and allocation of responsibility. We do not claim to be security technicians. We coordinate with your IT team or provider, with each contributing their own expertise.

No-obligation enquiry

Ready to start?

Send us an enquiry. We reply within 24 hours with a price confirmation and next steps. The first 30-minute consultation is free and commits you to nothing.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

For our conflict-of-interest check.
Add details such as deadline, documents and attachments (optional)
Is a deadline running?
Anything served by a court or authority gets priority.
Documents for this matter
Tick what you have at hand. We will fill in the rest together.
PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.

What clients ask

Didn’t find your question? Ask us directly →

How do I know whether NIS2 applies to my company?

The combination of sector and size is decisive. The Act covers sectors from energy and transport through manufacturing of selected products to digital services, generally where the enterprise reaches medium-sized status. With fewer than 50 employees, both annual turnover and the balance-sheet total must exceed €10 million for the enterprise to exceed the small-enterprise threshold, taking into account the rules for partner and linked enterprises. Some entities are covered regardless of size. The statutory annex is extensive and sector classifications are not always intuitive. That is exactly what our assessment and written conclusion address.

What must a regulated entity actually do?

Register with the National Security Authority, implement appropriate security measures including supply-chain risk management, report significant cyber incidents within statutory time limits and demonstrate that company management directs security. The scope differs by category. After the assessment, you receive a specific list for your company.

Is a managing director personally responsible for NIS2?

Yes. The statutory body bears responsibility for compliance and cannot remove it by delegating the subject to IT. Management must approve and oversee the measures and undergo training. Part of our work is to establish a documented allocation of duties, precisely what the authority will examine during an inspection.

We supply a company covered by NIS2. What does that mean for us?

Your customer must manage risks in its supply chain. In practice, security requirements, audits and incident reporting obligations will be added to your contracts. We help assess those requirements, negotiate a proportionate scope and establish internal processes so you can retain the business.

What sanctions can apply?

The Act permits fines reaching hundreds of thousands of euros for serious breaches, or a percentage of turnover. The exact amount depends on the entity's category and the type of breach. We explain the ranges relevant to your situation during the assessment. The authority can also order remedial measures with a significant operational impact.

Legal Q&A

Common questions on this topic

Request a NIS2 assessment
Contact a lawyer