NIS2 COMPLIANCE  ·  ACT NO. 69/2018 COLL.  ·  EXTERNAL MKB

A Cybersecurity Manager
(MKB)
without hiring a full-time employee.

Slovak Act No. 69/2018 Coll. requires businesses, manufacturing plants and local governments in Slovakia to appoint a Cybersecurity Manager (MKB). CYSOPS takes on this role externally — with full statutory responsibility.

The NIS2 directive (EU 2022/2555) tightened the requirements for important and essential entities. We help you meet every obligation ahead of registration with Slovakia's National Security Authority (NBÚ) and the security audit.

Legislative framework
Slovak law

Act No. 69/2018 Coll.
on Cybersecurity

The act sets obligations for operators of essential services and digital service providers. It defines minimum security requirements, mandatory incident reporting, and the mandatory appointment of responsible persons.

Section Content
§ 20Obligations of essential-service operators
§ 21Security measures — technical and organizational
§ 22Reporting cybersecurity incidents
§ 23Cybersecurity Manager (MKB)
§ 36Penalties — fines of up to €300,000
European directive

NIS2 Directive
(EU) 2022/2555

NIS2 replaces the original NIS directive and broadens the scope of entities it covers, including new requirements for cyber risk management, the supply chain, and incident reporting within 24 hours.

!
Essential Entities
Energy, transport, healthcare, banking — stricter oversight, tougher penalties.
!
Important Entities
Manufacturing companies, postal services, research organizations — baseline obligations and an audit.
!
Incident reporting within 24 hours
Initial warning to NBÚ within 24 h, full report within 72 h of detection.
The MKB's role under the law

What is a Cybersecurity Manager,
and what does the law require of them?

Under Section 23 of Act No. 69/2018 Coll., every operator of an essential service must appoint a Cybersecurity Manager (MKB). This person is responsible for governing information security, overseeing measures, and communicating with NBÚ.

The MKB may not audit their own organization — the law explicitly separates the roles: governance and implementation (MKB = CYSOPS) versus an independent audit (an accredited third party).

For most Slovak SMBs and local governments, employing a full-time internal MKB isn't realistic. An external MKB from CYSOPS covers every statutory obligation at a fraction of the cost — with deeper expertise and no risk of losing a key employee.

MKB responsibilities (§ 23)
Drafting and updating the security policy
Cyber risk analysis and assessment
Oversight of technical measure implementation
Incident reporting and communication with NBÚ
Employee cybersecurity training
Preparing audit documentation for NBÚ
Regular reporting to organizational leadership
Final audit — performed by a third party
Implementation plan
6 phases · 3–6 months
01

Identification and classification

We determine whether your organization is an essential or important entity, and map your IT infrastructure, systems and critical dependencies.

→ Audit of existing infrastructure
→ Entity classification under NIS2
→ Identification of critical assets
02

NBÚ registration

We file the registration form with the National Security Authority, formally designate responsible persons, and set up communication channels.

→ Filing NBÚ registration
→ Appointing the MKB (CYSOPS)
→ Setting up contact channels
03

Security policy and documentation

We draft the security policy (ISMS), risk analysis, and the full documentation required by law.

→ Security policy (ISMS)
→ Risk analysis and assessment
→ Statutory documentation and records
04

Technical security measures

We implement the technical measures required under § 21 of the act — network segmentation, encryption, backups and a recovery plan.

→ Network segmentation, firewall, IAM
→ Encryption and backups (BCP/DRP)
→ SIEM event monitoring
05

Organizational measures

Employee training, incident management processes, and access, password and MFA policy.

→ Cybersecurity training
→ Incident management processes
→ Access, password and MFA policy
06

Audit readiness

Internal gap analysis and audit-documentation preparation. The final independent audit is performed by an accredited third party — CYSOPS provides full cooperation.

→ Gap analysis and remediation
→ Audit documentation preparation
→ Cooperation during the external NBÚ audit
What our service includes
Service Internal MKB CYSOPS external MKB
Statutory MKB function under § 23
Communication and reporting to NBÚ
Risk analysis and security policy
24/7 monitoring, incident response limited
Employee training
NBÚ audit preparation
Monthly reports and KPIs varies ✓ standard
Continuity (employee leaving) risk ✓ guaranteed
Cost vs. an internal FTE 100% FTE a fraction of the cost
Frequently asked questions

Who is required to have a Cybersecurity Manager (MKB)?

Under Section 23 of Act No. 69/2018 Coll., every operator of an essential service must appoint a Cybersecurity Manager. This applies to both essential and important entities as defined by the NIS2 directive — for example manufacturing companies, local governments, digital service providers and other essential-service operators.

Can the MKB also perform the final security audit of their own organization?

No. The law explicitly separates the roles — governance and implementation (the MKB's job) must be independent from the audit, which is performed by an accredited third party. CYSOPS, as external MKB, prepares the audit documentation and provides full cooperation, but an independent party performs the audit itself.

What are the penalties for non-compliance with Act No. 69/2018 Coll.?

Under Section 36 of the act, penalties for non-compliance can reach up to €300,000.

How quickly must a cybersecurity incident be reported to NBÚ?

The NIS2 directive requires an initial warning to Slovakia's National Security Authority (NBÚ) within 24 hours of detection, and a full report within 72 hours.

How long does NIS2 audit preparation take with CYSOPS?

CYSOPS's implementation plan has 6 phases — from identifying and classifying the entity, through NBÚ registration and security policy, to technical and organizational measures and final audit readiness. The whole process typically takes 3 to 6 months depending on the size of the organization.

What's the difference between an internal and an external MKB?

Both an internal and an external MKB perform the same statutory function under Section 23. An external MKB from CYSOPS additionally provides full technical implementation of measures, 24/7 monitoring and guaranteed continuity (no risk of losing know-how when an employee leaves) — at a fraction of the cost of a full-time internal hire.

Get started today

Don't delay your
NBÚ registration deadline.

Failing to meet the obligations under Act No. 69/2018 Coll. can carry a fine of up to €300,000. Book a free consultation — we'll work out exactly which obligations apply to you.

Preparing a municipal office, manufacturing plant or company for a NIS2 audit — get in touch with your specific case.

web
cysops.sk
country
Slovak Republic
Inquiry form — NIS2 consultation