Status on 11 September 2026: Article 14 reporting obligations apply. Slovakia prefers the national reporting route. Start with SK-CERT’s route page, which distinguishes JISKB access and the type of occurrence. ENISA’s direct SRP entry point is also available; check current availability on ENISA’s status page.
Choose the correct reporting route on SK-CERT
Who submits
From 11 September 2026, Article 14 applies to manufacturers of products with digital elements. The Article 24(3) duties for open-source software stewards start to apply on 11 December 2027. Importers, distributors, users and researchers should first check whether they have a reporting duty.
How to choose a route from Slovakia
- Open the official SK-CERT reporting route page. For the most detailed current route list, the Slovak SK-CERT page also distinguishes vulnerabilities, threats and near misses.
- If you have assigned JISKB access, for example as an operator of essential services, sign in to JISKB.
- If you do not have JISKB access and are reporting an incident, including a severe CRA incident, use the public incident-reporting route.
- For a vulnerability, including one related to the CRA, use the CVD portal listed by SK-CERT.
- Use the separate forms for a cyber threat or near miss.
- Submit the early warning in the chosen channel and continue with later stages according to that service’s instructions. Do not create duplicate submissions for the same duty.
SK-CERT lists email only as a last-resort fallback when the designated electronic methods cannot be used. Do not rely on ordinary email as proof that a mandatory report has been completed; follow the selected secure service.
JISKB remains Slovakia’s preferred route. Once direct SRP access is available, the EU channel may also be used and the submission will be received and processed under the EU rules.