
The Government of the Slovak Republic has approved the draft Act on the Cybersecurity of Products with Digital Elements, also known as the Cyber Resilience Act. The draft was prepared by the National Security Authority (NBÚ).
The Cyber Resilience Act—Regulation (EU) 2024/2847 of the European Parliament and of the Council—introduces horizontal cybersecurity requirements for products with digital elements. It applies to a broad range of digital products whose security is important for protecting users, organisations and the digital economy.
What the draft Act regulates
The draft primarily regulates the powers of the NBÚ as the market surveillance authority for products with digital elements and the rights and obligations of economic operators. It also sets out rules for inspections performed by inspectors and penalties for breaches of obligations.
The new regulation concerns a broad range of products with digital elements. Special rules for free and open-source software depend on how it is distributed and whether it is supplied in the course of a commercial activity; the label “open source” does not automatically constitute an exemption. Areas already subject to specific European regulation, such as medical devices, aviation and the automotive industry, are also excluded from the scope of the CRA. A practical distinction is available on the Scope of the CRA page.
The draft also provides for supervision of the specific obligations of an open-source software steward. A steward is not a manufacturer solely for that reason and the full manufacturer regime does not automatically apply. However, where the steward places a project or version on the market under its own name or trademark in the course of a commercial activity, the role of manufacturer must also be assessed separately.
Connection with the existing framework
Slovakia has already introduced some of the requirements through Act No. 318/2025 Coll. It designated the NBÚ as the market surveillance authority and the Slovak Office of Standards, Metrology and Testing as the notifying authority for the purposes of the CRA.
Government approval of the draft is another step towards establishing a comprehensive system for supervising the cybersecurity of products with digital elements in Slovakia.