Decree 212/2026: new cybersecurity audit rules in Slovakia

Decree 212/2026: new cybersecurity audit rules in Slovakia

Decree 212/2026 of the Slovak National Security Authority (NBÚ) took effect on 1 September 2026 and rewrites much of decree 493/2022 on cybersecurity audits. Periodicity is counted differently, self-assessment has its own regime, and operational technology is explicitly in audit scope for the first time.

The transition window closes on 31 December 2026

The decree carries two transitional rules. An audit started but not completed by 31 August 2026 is finished under the previous rules. An audit started by 31 December 2026 may also be carried out under the previous rules — but does not have to be. From 1 January 2027, every newly started audit follows the new wording only.

If you are scheduling an audit around the turn of the year, the start date decides the regime — worth fixing in the contract, not by verbal agreement.

Periodicity is counted differently

The old rule was an audit every two years, starting within two years of the final report. The new wording counts in calendar years and ties the deadline to completion, not the start:

  • an audit is carried out and completed by the end of the third calendar year following the year in which the last audit was completed,
  • or by the end of the fifth calendar year, for an operator that is not an operator of a critical essential service and that performs self-assessment every two years,
  • on every significant change, within six months of that change significantly affecting the implemented security measures — previously two months.

Going from two months to six is the biggest practical relief; the old window was effectively unachievable for larger migrations.

An audit now ends when the final report is handed to the operator, and may not run longer than twelve consecutive months. A remote audit may not exceed 30% of the planned on-site time.

Self-assessment does not replace the audit

Under section 29(8) of act 69/2018, self-assessment is open to an essential service operator that is not a critical essential service operator. It is performed by the cybersecurity manager, who answers for the accuracy and completeness of the report — in an audit that responsibility sits with the certified auditor.

What matters is what it does not do: it does not replace the audit, it extends the interval between audits from three to five calendar years. The act still requires an audit within five years of entry into the register, and self-assessment is not performed when the audit obligation falls due.

The report goes to the authority through the unified cybersecurity information system and contains the manager's name and surname, the date it was performed, a summary of findings, and a list of recorded evidence.

Operational technology and partial compliance

Throughout the decree, "networks and information systems" has been replaced by "networks, information systems and operational technology". That includes the audit checklist in annex 3, now completed for each network, information system or operational technology asset. Teams keeping OT records outside the main asset database must close that gap; the auditor asks for it in the same structure as IT.

Partial compliance was already a rating under the original decree. What changes is that it now carries the same consequence as non-compliance: the final report must include a report on the identified deficiencies, with a deadline for corrective measures (section 2(3)). A measure implemented only in part now gets its own remediation deadline in the report.

What to settle before year end

  • Find the completion date of the last audit — the new deadline runs from the year it ended.
  • Decide between a three-year audit cycle and two-year self-assessment with a five-year audit.
  • Add operational technology to the asset inventory and the security documentation.
  • If the audit is planned for 2027, scope it against the new wording only.

Need help with this topic?

Get in touch