Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

CRA and NIS2: which report should I submit?

Last updated:

Question CRA NIS2 / Slovak cybersecurity law
Subject security of a product with digital elements security of systems and service provision by a regulated entity
Typical reporter manufacturer; within limits, open-source steward the affected entity subject to the relevant regime
Channel Start with SK-CERT’s route page. A CRA-related vulnerability is directed to CVD; for a severe incident, the route also depends on whether you have JISKB access. JISKB is Slovakia’s preferred route; direct SRP access is also available. Start with SK-CERT’s route page. A user with assigned access signs in to JISKB; a user without access follows the public incident route.

One event may trigger duties under both regimes. Do not merge the submissions merely because the technical event is the same.

Choose the correct reporting route on SK-CERT