Legal Journal: New Cybersecurity Obligations for Operators of Essential Services from January 1, 2025: What You Need to Know
Effective January 1, 2025, an amendment to Act No. 69/2018 Coll. on Cybersecurity (the "Act"), transposing the EU NIS 2 Directive, came into force. This amendment primarily broadens the scope of entities falling under the Act. The new rules apply to a wider range of organizations performing activities in newly regulated areas such as waste management, food production, and manufacturing. According to the National Security Authority (NBÚ), the estimated number of these entities is over 6,000. For many new organizations, this means new obligations to enhance their cybersecurity level. So, how do you find out if you fall under the Act?
Who is an Operator of Essential Services?
The amendment to the Act changed the method of identifying obligated entities and definitively specifies who is registered in the Register of Operators of Essential Services (OES).
As new entities, organizations are considered Operators of Essential Services if they are at least medium-sized enterprises, meaning they have a minimum of 50 employees and a turnover of at least EUR 10 million, and they perform activities in the sectors listed in Annex 1 and Annex 2 of the Act. These include sectors with a high level of criticality such as energy, transport, finance, healthcare, water, digital infrastructure, public administration, and space, as well as other critical sectors that are newly regulated, namely postal and courier services, waste management, production and distribution of chemical substances, food production, manufacturing (medical devices, electrical equipment, machinery, transport vehicles), and research.
In addition, the register will primarily include central state administration bodies, critical entities, and other entities performing activities in key areas such as public electronic communications, trust services, domain name management (TLDs), or providing critical services whose disruption could have a negative impact on public order or security.
A third-party supplier who has a significant impact on the cybersecurity of an operator and has a contract with them based on this, is also considered an Operator of Essential Services.
The amendment introduces self-identification. Therefore, every organization must assess for itself whether it meets the above criteria and performs the specified activities. For this purpose, the NBÚ has prepared an indicative guide in the form of an online questionnaire to help determine if an entity is an essential service provider.
What Obligations Do Operators of Essential Services Have and By When Must They Fulfill Them?
1. Notification to the NBÚ and Registration in the OES Register
If you have identified yourself as an OES, you must submit a notification to the NBÚ about performing activities under the Act by March 3, 2025 (60 days from the effective date of the Act amendment). Failure to comply with this obligation carries a risk of a fine ranging from EUR 300 to EUR 500,000. The NBÚ will then assess your notification or application and register you in the OES register. Your new obligations as an Operator of Essential Services arise on the day of registration.
2. Security Measures
Within 12 months of registration in the OES register, you are obligated to adopt general security measures.
Violation of this obligation may result in a fine for the Operator of Essential Services ranging from EUR 300 to EUR 7,000,000 or up to 1.4% of the total worldwide annual turnover, or a fine from EUR 500 to EUR 10,000,000 or up to 2% of the total worldwide annual turnover for an Operator of Essential Services operating a critical essential service.
3. Cybersecurity Audit
Within 2 years from the date of registration in the OES register, you are obligated to perform a cybersecurity audit. Only a certified cybersecurity auditor is authorized to conduct a cybersecurity audit. If you are not an operator of a critical essential service, you may substitute the audit with a self-assessment, which can only be performed by a cybersecurity manager through the unified cybersecurity information system. However, even in such a case, you cannot avoid a cybersecurity audit, which must be carried out within 5 years. Remember that the NBÚ subsequently monitors and evaluates the results of the audit or self-assessment to ensure that corrective measures are actually implemented.
Failure to fulfill these obligations may result in a fine ranging from EUR 300 to EUR 500,000.
4. Other Obligations that the OES Must Fulfill
- Appoint a cybersecurity manager who meets the knowledge standards for performing this role (including outsourced services).
- Implement processes for informing the statutory body about cybersecurity matters.
- Reporting – report all significant cybersecurity events (e.g., serious cybersecurity incidents or significant cyber threats) through the unified cybersecurity information system.
- Supply chain security – enter into contracts with third parties providing cybersecurity-related services.
Sanctions and Fines for Non-Compliance
For violations of cybersecurity obligations, not only Operators of Essential Services but also individual natural persons can be sanctioned.
In addition to financial penalties, the NBÚ may also require the adoption of corrective measures, the performance of a cybersecurity audit, or prohibit the provision of services until the obligations are fulfilled.
However, the statutory body of the Operator of Essential Services, the senior employee at the highest level of management responsible for the specified activity, and even an external person entrusted or authorized to perform the specified activity, can also be penalized for non-compliance. The NBÚ may prohibit these individuals from carrying out their activities until the obligations are fulfilled.
A natural person, such as an employee of an Operator of Essential Services, a cybersecurity manager, a statutory body, or another authorized natural person, can receive a fine from the NBÚ of up to EUR 5,000, especially if they did not proceed in accordance with the technical, organizational, or personnel measures adopted by the Operator of Essential Services, or if they perform a self-assessment through the unified cybersecurity information system in violation of the Act.
A fine of up to EUR 10 million or up to 2% of the total worldwide annual turnover threatens an Operator of Essential Services who fails to fulfill the obligation to a) adopt security measures within 12 months of registration in the OES register, or if these measures do not meet the requirements of the Act; b) deal with a cybersecurity incident or report a serious cybersecurity incident; c) propose and adopt security documentation.
If, within one year from the effective date of the decision imposing the fine, the same obligations for which the fine was imposed are violated again, the NBÚ may impose a fine of up to double the original amount.
Other Changes Introduced by the Act Amendment
1. Changes in Definitions and Newly Emerging Concepts
One of the key changes brought by the cybersecurity Act amendment is the modification of some existing definitions. Terms such as "cybersecurity incident" and "cyber threat" have been adjusted and refined. In addition, new definitions have been added to the legislation, such as "near-miss event", "significant impact", "significant threat", "cyber crisis", and "systemic risk". These new concepts help to describe more precisely the scope and severity of cyber threats and incidents.
2. Unification of Terms for Obligated Entities
The Act amendment unifies the names of obligated entities. The former term "digital service provider" is abolished and replaced by the unified term "operator of essential services". The amendment also introduces the new designation "operator of critical essential services".
3. Adjustment of the Scope of Security Measures
The amendment expands the concept of security measures. These measures no longer focus only on organizational, personnel, and technological areas, but also include physical security. The new measures aim to achieve, guarantee, and maintain cybersecurity throughout the entire lifecycle of not only networks and information systems but also so-called operational technologies, such as industrial control systems. At the same time, the amendment emphasizes supply chain risk management, meaning companies will have to pay more attention to the security of their partners and suppliers. Details of the security measures will be determined by a new decree, which is currently being prepared.
4. Sector-Specifics and Specialized Measures
Sector-specifics are becoming increasingly important. The amendment introduces the principle of "lex specialis derogat legi generali", meaning that if a special regulation governing security measures for a specific sector exists, it will take precedence over general security measures. This will allow for better adaptation of security measures to the specific needs of individual sectors.
5. Security Measures Based on Risk Analysis
While previously the adoption of security measures was tied to the classification of information and the categorization of networks and information systems, the amendment adjusts this process based on risk analysis. This takes into account current threats and vulnerabilities in specific areas, allowing for more effective and targeted adoption of necessary measures.
6. Stricter Regulation and Oversight
The amendment introduces stricter regulation in the field of cybersecurity. New control mechanisms are being introduced that will allow for more detailed monitoring and verification of compliance with obligations. For some entities, self-assessments are also permitted, representing a new way of self-regulation and better monitoring of the security status. Penalties for non-compliance are also being tightened, which aims to motivate entities to take greater responsibility for the security of their systems.
7. Fundamental Changes in Reporting
The obligations regarding the reporting of cyber incidents are also undergoing fundamental changes:
- Early warning – no later than 24 hours after the incident is detected.
- Notification – no later than 24 hours, including an initial analysis of the incident.
- Requested information – update or other information about the course of the incident at the request of the CSIRT unit.
- Final report – no later than one month after the notification; this must now also include a detailed description of the incident, including its severity and consequences.
The amendment to the Cybersecurity Act introduces several fundamental changes that address current challenges in protecting against cyber threats. The simplification of concepts, the expansion of security measures, and the emphasis on risk analysis allow for more effective protection of critical infrastructures and systems. At the same time, the introduction of stricter controls and new reporting mechanisms increases transparency and responsiveness to cyber threats, which is crucial for protecting not only individual organizations but also the entire digital ecosystem.
How Can We Help You?
- With identifying whether the Act applies to you and with registration in the OES register, so you can meet the March 3, 2025 deadline.
- We will provide you with comprehensive legal advice in the field of cybersecurity to ensure you are prepared for key requirements and prevent possible sanctions.
- We will analyze and propose effective IT service management processes.
- We will review your security documentation and contractual documentation with suppliers and set up appropriate measures.
- We will review your security architecture and propose appropriate security measures.
- We will provide you with the services of a certified cybersecurity manager who will help you implement the requirements of the Act in a timely manner, in cooperation with the best certified cybersecurity experts in Slovakia.
- We will assist you with investigating security incidents by engaging a team of elite experts from the field.
- We will ensure the performance of a cybersecurity audit through a certified cybersecurity auditor.
- We will provide training for members of the statutory body and selected employees.
- We will represent you during inspections and proceedings before the NBÚ.
If you need our help, contact our specialists.
Keywords: NIS2 SlovakiaSlovakia Cybersecurity ActCybersecurity Act SlovakiaNIS2 complianceEssential Service OperatorCybersecurity auditCybersecurity law SlovakiaNBÚ SlovakiaCybersecurity complianceCybersecurity legal services
