Business obligations, registers and licences · Slovakia
NIS2 and cybersecurity
The NIS2 Directive, transposed by an amendment to Act No. 69/2018 Z. z. on Cybersecurity, extended regulated entities beyond critical infrastructure to thousands of ordinary businesses in manufacturing, logistics, food, waste and digital services. We assess whether it covers you and, if so, guide you through registration, obligations and supplier agreements. We handle the legal work. Your IT team or provider handles the technical work, and we are happy to coordinate with them.
- Assessment before documentation
- Legal work coordinated with IT
- Prices agreed upfront
What we'll do for you
The legal and technical aspects of NIS2 are often mixed together. We handle the legal questions: whether the Act applies and under which regime, what the documentation must contain, and how to structure contracts and responsibility. Your IT team designs the technical measures, and we provide clear legal instructions.
Select an item to see the details.
-
Assessment and classification
Based on your sector, size and activities, we assess whether you are a regulated entity and in which category. This determines the scope of obligations and sanctions. You receive a written assessment.
-
Registration
We prepare and submit registration with the National Security Authority within the statutory time limit and establish contact details and contact persons.
-
Legal documentation
Internal policies on risk management, incident reporting and business continuity to the extent required by law, aligned with your existing GDPR documents and internal policies.
-
Supplier agreements
Adding security requirements to IT supplier agreements and reviewing the supply chain. NIS2 expressly addresses supply-chain security.
-
Management responsibility
Statutory representatives are personally responsible for cybersecurity and must undergo training. We structure the allocation of duties and documentation protecting management.
Deliverablean assessment of whether the Cybersecurity Act applies to the company and legal documentation of its obligations, including supplier agreements
How it works
Does this process fit your matter? Describe it to the attorney →
- Assessmentday 0
We establish whether the Act applies and under which regime. If it does not, the work ends with a written conclusion.
- Registration and plan
Registration with NBÚ and a plan of obligations with deadlines, specifying what must be completed and when.
- Documentation and agreements
We prepare the legal documents and amend supplier agreements. Your IT team implements technical measures based on our instructions.
- Ongoing complianceongoing
Incident reports, registration changes and new guidance — we help maintain compliance.
NIS2 moved cybersecurity from the IT department into the boardroom. The amendment to the Cybersecurity Act extended obligations to thousands of companies that had not previously been considered critical infrastructure and placed responsibility on management.
We handle the legal work: assessment, registration, documentation, contracts and allocation of responsibility. We do not claim to be security technicians. We coordinate with your IT team or provider, with each contributing their own expertise.
No-obligation enquiry
Ready to start?
Send us an enquiry. We reply within 24 hours with a price confirmation and next steps. The first 30-minute consultation is free and commits you to nothing.
- 1Send your enquiry via this form
- 2Within 24 h you get a price confirmation and plan
- 3We start work only after your approval
Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.
What clients ask
Didn’t find your question? Ask us directly →
How do I know whether NIS2 applies to my company?
The combination of sector and size is decisive. The Act covers sectors from energy and transport through manufacturing of selected products to digital services, generally where the enterprise reaches medium-sized status. With fewer than 50 employees, both annual turnover and the balance-sheet total must exceed €10 million for the enterprise to exceed the small-enterprise threshold, taking into account the rules for partner and linked enterprises. Some entities are covered regardless of size. The statutory annex is extensive and sector classifications are not always intuitive. That is exactly what our assessment and written conclusion address.
What must a regulated entity actually do?
Register with the National Security Authority, implement appropriate security measures including supply-chain risk management, report significant cyber incidents within statutory time limits and demonstrate that company management directs security. The scope differs by category. After the assessment, you receive a specific list for your company.
Is a managing director personally responsible for NIS2?
Yes. The statutory body bears responsibility for compliance and cannot remove it by delegating the subject to IT. Management must approve and oversee the measures and undergo training. Part of our work is to establish a documented allocation of duties, precisely what the authority will examine during an inspection.
We supply a company covered by NIS2. What does that mean for us?
Your customer must manage risks in its supply chain. In practice, security requirements, audits and incident reporting obligations will be added to your contracts. We help assess those requirements, negotiate a proportionate scope and establish internal processes so you can retain the business.
What sanctions can apply?
The Act permits fines reaching hundreds of thousands of euros for serious breaches, or a percentage of turnover. The exact amount depends on the entity's category and the type of breach. We explain the ranges relevant to your situation during the assessment. The authority can also order remedial measures with a significant operational impact.
Legal Q&A
Common questions on this topic
-
We are a medium-sized business. Does NIS2 apply, and must we register with NBÚ?
Two things matter together: whether your activity is in Annex 1 or 2 to Act No. 69/2018 Coll. on Cybersecurity, and whether you are at least medium-sized, generally having at least 50 employees or both annual turnover and balance-sheet total above EUR 10 million. If so, you must identify this yourself and notify the National Security Authority within 60 days of starting the activity. Exceptions matter: some entities register regardless of size, and group companies count towards size.
Read the answer -
Who is a beneficial owner, and how are they identified?
A beneficial owner is always an individual, never a company. In a company, this particularly includes anyone with a direct or indirect interest of at least 25% in voting rights or registered capital, the right to appoint or remove statutory or supervisory bodies, control by other means, or entitlement to at least 25% of the economic benefit. If no such individual can be identified, senior management, meaning the statutory body, is treated as the beneficial owner.
Read the answer -
What happens if we are not registered in RPVS or miss annual verification?
The consequence is more than a fine. If beneficial owner verification is missing, the public-sector counterparty is not in default when it withholds performance for that reason, so it may lawfully withhold payment of your invoice. False or incomplete data can bring a company fine equal to the economic benefit obtained, or otherwise EUR 10,000–1,000,000, and EUR 10,000–100,000 for the statutory representative. The two-year re-registration ban arises in the sanction cases governed by Section 13a, not after every voluntary deletion.
Read the answer
Further reading
NIS2 does not end at registration: cybersecurity belongs in supplier contracts
The Cybersecurity Act requires essential service operators to conclude specific agreements with suppliers affecting their networks and systems, covering security policies, audits and incident reporting. What the agreement needs, what to ask IT suppliers for and what to watch when you are the supplier.
Read more →
AML amendment: goAML registration by 30 November 2026 and stricter beneficial owner verification
AML amendment Act No. 73/2026 Z. z. has applied since 1 June 2026. Obliged entities must register in the Financial Intelligence Unit’s goAML system by 30 November 2026 and must not rely solely on the register of legal entities when verifying beneficial owners.
Read more →
Conflicts of interest in public procurement: when bidders risk exclusion
A former employee on the contracting authority’s side, a designer included in the bid or personal links to the committee: Public Procurement Office guidance No. 3/2026 explains which connections create conflicts and when exclusion follows. Potential influence, disclosure and mitigation are decisive.
Read more →