| Question | CRA | NIS2 / Slovak cybersecurity law |
|---|---|---|
| Subject | security of a product with digital elements | security of systems and service provision by a regulated entity |
| Typical reporter | manufacturer; within limits, open-source steward | the affected entity subject to the relevant regime |
| Channel | Start with SK-CERT’s route page. A CRA-related vulnerability is directed to CVD; for a severe incident, the route also depends on whether you have JISKB access. JISKB is Slovakia’s preferred route; direct SRP access is also available. | Start with SK-CERT’s route page. A user with assigned access signs in to JISKB; a user without access follows the public incident route. |
One event may trigger duties under both regimes. Do not merge the submissions merely because the technical event is the same.