Slovakia - National Cybersecurity Strategy (5/2021)
National Cybersecurity Strategy 2021–2025
Národná stratégia kybernetickej bezpečnosti 2021–2025
Slovakia
RAI-SK-NA-NCS2XXX-2021The National Cybersecurity Strategy 2021–2025 (Slovakia) sets the strategic framework for strengthening national resilience, governance and cooperation in the cyber domain. Adopted by the Slovak Government on 7 January 2021, the Strategy defines strategic objectives, priority activities and the requirement for an action plan to operationalize measures across public administration, critical infrastructure and the private sector.
Summary
Read full text ↗Plain English
Overview
The National Cybersecurity Strategy 2021–2025 sets the Slovak Republic’s strategic orientation for strengthening national cyber resilience, governance and international cooperation. Adopted by government resolution on 7 January 2021, it was prepared by the Národný bezpečnostný úrad (NBÚ) and published with an associated Action Plan to detail responsibilities and timelines. The Strategy identifies the cyber domain as a priority for national security and public administration modernization and directs measures across institutional governance, incident response, critical infrastructure resilience, workforce development and public awareness. For the official text and Action Plan see the NBÚ portal and the SK-CERT repository: Národná stratégia kybernetickej bezpečnosti (NBÚ) and SK-CERT – Basic Documents.
Definitions
The Strategy defines key terms in line with EU and national law. Core definitions include: "cybersecurity" (measures to protect networks, information systems and data), "operator of essential services" (entities providing services whose disruption would have significant impacts), "incident" (a breach or threat to confidentiality, integrity or availability), "critical information infrastructure" (assets essential for national functions), and "digital service provider" (entities offering on-line services subject to specific reporting and security requirements). These definitions are applied for strategic prioritisation and align with Act No. 69/2018 and related NBÚ regulations.
Governance and Institutional Framework
The Strategy establishes a layered governance architecture centred on the NBÚ as the national lead for cybersecurity policy and coordination, supported by sectoral authorities (ministries and regulators), the national CSIRT (SK-CERT) for technical response and coordination, and law enforcement for criminal investigation. It mandates the preparation and adoption of a detailed Action Plan assigning tasks, timelines and accountable institutions. The framework foresees a permanent monitoring committee or steering group to oversee implementation and to report progress to the Government. It also calls for strengthened inter-agency information-sharing arrangements, formalised incident escalation paths and clearer responsibilities for operators of essential services and public sector entities. Key institutional pages: NBÚ and SK-CERT.
Key Focus Areas
The Strategy organises activity around several priority pillars: (1) Governance and legal coherence – ensuring policies, laws and institutional responsibilities are aligned; (2) Resilience of critical infrastructure and essential services – strengthening protective measures across energy, finance, health, transport, and public administration; (3) Incident detection and response – boosting CSIRT capabilities, information-sharing and forensic capacity; (4) Law enforcement and prosecution – improving investigative tools and cross-border cooperation against cybercrime; (5) Capacity building and workforce – expanding national training, education and certification paths for cybersecurity professionals; (6) Secure digital transformation – embedding security-by-design in e-government and public procurement; (7) Research, innovation and industry partnerships – promoting public-private collaboration and standards adoption; and (8) Awareness and societal preparedness – raising public understanding of cyber risks. These focus areas drive Action Plan measures and resource allocation.
Implementation Framework
Implementation is driven through a mandated Action Plan that specifies tasks, responsible entities, deliverables and timelines. The NBÚ is charged with coordinating the Action Plan, supported by sectoral leads and the Government Office for strategic oversight. The framework emphasises measurable deliverables (e.g., establishment of sectoral CSIRTs, completion of national risk assessments, deployment of security standards across public administration) and calls for funding, training programs and technical assistance. The Strategy encourages adoption of recognised standards and certification where appropriate and foresees integration with procurement and infrastructure modernisation projects to ensure security requirements are embedded early in digital projects.
Monitoring and Evaluation
The Strategy requires periodic monitoring of the Action Plan via a designated permanent monitoring committee or steering body, with scheduled progress reports to the Government. Monitoring indicators include completion of action items, maturity improvements in sectoral preparedness, incident metrics (frequency, impact, response times) and capacity-building milestones (number of trained personnel, certifications). The monitoring cycle includes annual reviews and a mid-term evaluation to recalibrate priorities and resource allocation as needed.
Penalties, Liability, and Appeals
While the Strategy is a policy document, it operates in the context of enforceable national legislation (notably Act No. 69/2018 on cyber security and relevant NBÚ implementing regulations) that establish reporting obligations, compliance duties and sanctioning mechanisms for non-compliance. The document stresses alignment with legal safeguards, proportionality and procedural fairness, and it references existing administrative and criminal routes for enforcement and appeals handled by designated authorities and courts.
Relationship to Other Instruments
The Strategy explicitly links to prior national documents (e.g., the 2015–2020 Concept) and to national legislation (Act No. 69/2018) and NBÚ regulations (technical and reporting rules). It also references EU instruments including the NIS framework and ENISA guidance and aligns with NATO cybersecurity policy. The Strategy anticipates updates to domestic regulations and technical standards to implement strategic objectives and to maintain coherence across the regulatory ecosystem.
International Alignment
The Strategy underlines the importance of international cooperation in information exchange, incident response, joint exercises and capacity building, prioritising coordination with EU partners, ENISA, NATO and bilateral partners. It seeks harmonisation with EU cybersecurity policy and cross-border incident handling mechanisms and promotes Slovakia’s participation in international fora to exchange best practices and to strengthen mutual assistance arrangements.
Implementation Timeline
| Period | Milestone |
|---|---|
| Q1 2021 | Government adoption (7 January 2021) and NBÚ tasked to prepare Action Plan |
| Q1–Q2 2021 | Draft Action Plan development and inter-ministerial consultation |
| Mid 2021 | Action Plan adoption and start of priority measures (sectoral risk assessments, CSIRT strengthening) |
| 2022–2023 | Roll-out of sectoral resilience measures, workforce development, standards adoption |
| 2024 | Mid-term review and evaluation of Strategy implementation |
| 2025 | Final review and transition planning for next strategic cycle |
Compliance Checklist
| Requirement | Compliant Action |
|---|---|
| Assign organisational lead | Designate NBÚ contact and sectoral responsible institution |
| Risk assessment | Complete sectoral and organisational risk assessments |
| Incident reporting | Implement reporting channels to SK-CERT and NBÚ per law |
| Security policy | Adopt security-by-design policies and procurement clauses |
| Workforce | Provide staff training and certification pathways |
Sources and References
| Source | Type |
|---|---|
| Národná stratégia kybernetickej bezpečnosti na roky 2021 – 2025 (NBÚ) | Primary Source |
| Akčný plán realizácie Národnej stratégie kybernetickej bezpečnosti na roky 2021 – 2025 (NBÚ) | Primary Source |
| SK-CERT – Basic Documents (list and downloads) | Primary Source |
Slovakia's National Cybersecurity Strategy 2021–2025 outlines a comprehensive plan to strengthen the nation's digital defenses, impacting government bodies, critical infrastructure operators, and private sector entities providing essential services.
This strategy applies broadly to anyone involved in the country's digital landscape, including public administration, operators of essential services like energy, finance, health, and transport, as well as digital service providers. It aims to boost resilience across the entire cyber domain. Adopted in January 2021, the strategy directs the National Security Authority (NBÚ) to coordinate an Action Plan with specific tasks and timelines. Key areas of focus include: - Strengthening protective measures for critical infrastructure and essential services. - Enhancing capabilities for detecting and responding to cyber incidents, including improved information sharing and forensic capacity. - Embedding security principles ("security-by-design") into government digital transformation projects and public procurement. - Developing a skilled cybersecurity workforce and raising public awareness of cyber risks.
The NBÚ was tasked with developing a detailed Action Plan, which was adopted mid-2021, kicking off the implementation of these strategic goals. The plan includes measurable deliverables, from establishing sectoral Computer Security Incident Response Teams (CSIRTs) to deploying security standards across public administration. While the Strategy itself is a policy document, it underpins and aligns with existing national cybersecurity laws, notably Act No. 69/2018. These laws establish reporting obligations and compliance duties, carrying administrative and criminal sanctions for non-compliance. This means the strategic goals translate into legally enforceable requirements for in-scope entities. A key takeaway is that this isn't just a high-level vision; it's a foundational document that mandates concrete actions through its Action Plan, which are then enforced via existing legislation. Companies might overlook its importance, but it directly shapes the regulatory landscape and compliance expectations, with the NBÚ as the central coordinating and enforcement authority.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
Related Regulations
Strategy of Digital Transformation of Slovakia 2030
Slovakia91% similar
Strategy and Action Plan to Improve Slovakia's Position in the DESI Index to 2025
Slovakia91% similar
Action Plan for Digital Transformation of Slovakia 2023–2026
Slovakia90% similar
Action Plan for the Digital Transformation of Slovakia 2019–2022
Slovakia90% similar
National Concept of Informatization of Public Administration (NKIVS) 2021 – 2026
Slovakia90% similar
© Regulations.AI — created on 13-Jun-2026