CRA Compliance in Slovakia
National competent authority, Article 14 CSIRT contacts, and enforcement guidance for Slovakia manufacturers.
Slovakia's National Security Authority (NBU — Národný bezpečnostný úrad) serves as both the national cybersecurity authority and the CRA national competent authority, with SK-CERT operating as the national CSIRT. Slovakia has a significant automotive manufacturing sector — it produces more cars per capita than any other country in the world — creating substantial CRA obligations for automotive component and system manufacturers. NBU's technical capacity and active ENISA engagement position it as a capable CRA enforcement authority.
National Competent Authority (CRA)
NBU
Národný bezpečnostný úrad
NBU (National Security Authority) is Slovakia's national security and cybersecurity authority, responsible for protecting classified information and cybersecurity. It serves as Slovakia's CRA national competent authority and oversees SK-CERT as the national CSIRT. NBU actively participates in ENISA governance and EU cybersecurity policy coordination.
https://www.nbu.gov.sk →National CSIRT (Article 14 Reports)
SK-CERT
SK-CERT
https://www.sk-cert.sk/sk/kontakt/index.html
https://www.sk-cert.sk →CRA Enforcement in Slovakia
NBU serves as Slovakia's national competent authority for the CRA, with market surveillance for consumer and industrial products coordinated with the Slovak Trade Inspection (SOI) and sector-specific regulators. Slovakia's automotive dominance — with Volkswagen, Kia, Stellantis, and Jaguar Land Rover all operating major plants — means that CRA's application to automotive components is of significant national economic interest. NBU has established itself as an active participant in EU cybersecurity policy and technical working groups. SK-CERT operates Slovakia's national CSIRT function with coordination across the EU CSIRTs network.
Article 14 Incident Reporting for Slovak Manufacturers
Slovak manufacturers submit Article 14 notifications to SK-CERT through its secure reporting portal. SK-CERT maintains incident response capability and participates in the EU CSIRTs network for cross-border incident coordination. The Article 14 obligation requires an early warning within 24 hours of detecting active exploitation and a full notification within 72 hours. Slovakia's cybersecurity law framework, updated to transpose NIS2, designates SK-CERT as the CSIRT for essential and important entity incident coordination, and CRA Article 14 notifications will integrate with this framework. Manufacturers should pre-register with SK-CERT and document their Article 14 reporting procedure.
Market Surveillance & Penalties
Market surveillance for CRA products in Slovakia is coordinated between NBU and the Slovak Trade Inspection (SOI), with customs authorities involved for imported products. The full CRA penalty regime applies: up to €15 million or 2.5% of global annual turnover for violations of essential cybersecurity requirements. SOI has active market surveillance operations under EU product safety regulations including the Radio Equipment Directive. Slovak manufacturers, particularly in the automotive supply chain, should anticipate that their CRA compliance will be scrutinised as part of OEM supply chain audit requirements, adding a private sector enforcement dimension alongside public authority surveillance.
Support for Slovak Manufacturers
NBU and SK-CERT publish cybersecurity guidance in Slovak for businesses, including implementation guides and awareness resources. The Slovak Business Agency (SBA) provides SME support including subsidised cybersecurity advisory services through EU-funded programmes. The Slovak Chamber of Commerce and Industry (SOPK) provides regulatory compliance guidance. The Slovak University of Technology (STU) in Bratislava provides technical research and conformity assessment expertise relevant to CRA product evaluations. Slovakia's Industry 4.0 national strategy includes cybersecurity as a key component, with investments available for manufacturers through Operational Programme Integrated Infrastructure.
CVD Portal automates your Article 14 notification obligations.
Pre-built notification workflows for SK-CERT, deadline tracking, CSAF advisory generation, and a public CVD submission portal. Free forever.
Start your free portalFrequently asked
How do I contact NBU or SK-CERT as a manufacturer with a CRA compliance question?+
NBU can be contacted through nbu.gov.sk, and SK-CERT through sk-cert.sk. SK-CERT provides cybersecurity incident reporting and general enquiry services in Slovak and English. For CRA compliance questions, NBU's cybersecurity regulatory division handles manufacturer enquiries. SK-CERT engages industry through the annual Cybersec Europe conference held in Bratislava, which is a significant regional cybersecurity event.
Does Slovakia have national-level CRA implementing legislation?+
Slovakia has transposed NIS2 through amendments to the Zákon o kybernetickej bezpečnosti (Cybersecurity Act, Act No. 69/2018 Coll.). CRA implementing measures are expected through further amendments to the Cybersecurity Act and through product safety regulations. NBU and the Ministry of Investments, Regional Development and Informatisation are coordinating Slovakia's CRA implementation, with national measures expected ahead of December 2027.
How does the CRA affect Slovak automotive component manufacturers?+
Slovakia's automotive supply chain is directly in scope of the CRA for components with digital elements — including ECUs, sensors, communication modules, and control systems. Automotive OEMs purchasing components from Slovak suppliers are increasingly requiring UNECE WP.29 R155 and ISO/SAE 21434 compliance in supply contracts, which overlaps with CRA Annex I requirements. Slovak automotive component manufacturers should conduct a combined R155, ISO/SAE 21434, and CRA compliance assessment to identify additive obligations. NBU is expected to publish specific guidance for the automotive sector given its national economic significance.
CRA guides for neighbouring countries
Need a CRA compliance checklist for your product?
Browse free niche-specific checklists covering classification, Annex I obligations, and CVD requirements.