Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority
Legislative updateArchive

Slovak Cyber Resilience Act Was Subject to Public Consultation

Published: For: Economic operators and the public

Grafika k pripomienkovému konaniu zákona o kybernetickej odolnosti

Archived information

The consultation ended on 26 June 2026. The Government of the Slovak Republic approved the draft Act on 26 August 2026.

The National Security Authority submitted for consultation a draft Act on the Cybersecurity of Products with Digital Elements, also known as the Cyber Resilience Act.

The draft responded to Regulation (EU) 2024/2847 of the European Parliament and of the Council, which introduces horizontal cybersecurity requirements for products with digital elements. It regulates a broad range of products. Special rules for free and open-source software depend on how it is distributed and whether it is supplied in the course of a commercial activity; the label “open source” does not automatically constitute an exemption. Areas such as medical devices, aviation and the automotive industry are also specifically regulated. A practical distinction is available on the Scope of the CRA page.

The draft also provided for supervision of the specific obligations of an open-source software steward. A steward is not a manufacturer solely for that reason and the full manufacturer regime does not automatically apply. However, where the steward places a project or version on the market under its own name or trademark in the course of a commercial activity, the role of manufacturer must also be assessed separately.

What the draft regulated

The draft Act regulated the powers of the NBÚ as the market surveillance authority, the rights and obligations of economic operators, inspections performed by inspectors and penalties.

Slovakia had already introduced some of the requirements through Act No. 318/2025 Coll., which designated the NBÚ as the market surveillance authority and the Slovak Office of Standards, Metrology and Testing as the notifying authority.