NIS2 in plain terms: who the new cybersecurity law really affects and what to do about it

Since 1 January 2025 a new cybersecurity act has been in force in Slovakia. It transposes the European NIS2 directive into Slovak law, and most companies do not even know it exists. Yet it is not a draft or something that might come one day. It is a law in force, and the fines for breaking it run into the millions of euros. What surprises people most is who it affects.
If you run a company, you need to know three things: whether it concerns you, what you have to do, and what happens if you ignore it. Let us go through them in order, without the legal jargon.
Why NIS2 is different from the previous rules
The original NIS directive from 2016 covered seven sectors and a handful of large players. NIS2 expanded that to eighteen sectors and sharply lowered the threshold at which a company falls under the law. Energy, transport, healthcare, water and waste management, digital infrastructure and services, manufacturing, food and chemical industry, public administration, postal services, finance, science and education. That list is long on purpose.
Attacks on companies and institutions long ago stopped being a fringe IT problem. An encrypted hospital, a shut-down waterworks or an extorted factory are common headlines today. So Europe decided that security is no longer optional.
Does this affect my company? Two questions are enough
The law has a simple test with two conditions. Both must be true at once.
- You operate in a regulated sector. One of those eighteen. You do not have to be a power plant; it is enough to be, for example, a mid-sized manufacturer, a digital service provider or a public-sector body.
- You are at least a medium enterprise. That means more than 50 employees or turnover over 10 million euros. One of the two is enough.
If both are true, the law places you in one of two groups. Essential entities are the most important ones. Important entities are the other regulated ones. The difference is mainly in the strictness of oversight and the size of the fines. Always verify your exact classification directly with the National Security Authority, do not rely on a guess from an article.
Small company, big catch: the supply chain
This is what most people miss. Say you have ten people and do not fall under the law directly. It will still reach you.
NIS2 says that a regulated company must secure its suppliers too. Your larger client, who does fall under the law, cannot afford a weak point at a supplier. So they will start contractually requiring security measures, attestations, sometimes an audit. If you are their IT partner, software firm, cloud accounting or service provider, the law lands on you as well, just through the contract, not directly.
So even a small company that wants to work for larger clients will have to show it does not take security lightly. Those who have it ready win contracts. Those who do not will lose them over time.
What a regulated company actually has to do
The law does not care about paperwork for the drawer. It cares that you actually manage security. In short:
- Notify the regulator. Once you find that you meet the conditions, you have a statutory deadline to notify, generally within 60 days. This is the first and mandatory step.
- Do a risk analysis. Know what could take you down, which data and systems are critical, and where the weak spots are.
- Put measures in place. Backups and testing them, multi-factor authentication, access control, updates, encryption, network segmentation, an incident response plan. Nothing exotic; these are things any serious company should have anyway.
- Set up incident reporting. More on that below, because the windows are strict.
- Involve management. The law explicitly places responsibility on management. It is no longer just the IT person’s concern.
The law’s teeth: fines and reporting within 24 hours
To make sure companies do not take it lightly, the law also carries real penalties.
Fines. For essential entities up to 10 million euros or 2% of global annual turnover, whichever is higher. For important entities up to 7 million euros or 1.4% of turnover. Numbers like that can sink a company.
Incident reporting in three steps. When someone attacks you, the clock is running:
| Deadline | What to do |
|---|---|
| Within 24 hours | Notify the regulator that an incident occurred |
| Within 72 hours | Provide details of the incident |
| Within 30 days | Submit a final report |
Twenty-four hours is short. In the middle of an attack, when you are putting out fires, you have no time to work out who to report to and how. That is why this process is prepared in advance, rehearsed and has a clearly assigned person. Companies that underestimate it make their first mistake before they even start defending themselves.
Where a company should start, without panic
NIS2 looks like a heavy burden, but you do not have to do everything in a week. A sensible order is this.
- Find out whether you fall under the law. Go through the two-question test and verify your classification with the regulator.
- If yes, notify within the statutory deadline. This one cannot wait.
- Do a risk analysis and look soberly at where you are weak.
- Put basic measures in place, from backups through multi-factor authentication to an incident response plan.
- Set up the reporting process and decide who leads it.
Nobody expects you to be finished overnight. What matters is being able to show that you handle security continuously and keep track of it. Even a smaller company can manage that, if it starts in time and not at the last minute.
We write in more detail about the concrete measures in our articles 7 cybersecurity principles for small companies, Zero Trust for companies and how to defend against ransomware that encrypts your company. The regulation around data and the company follows on from GDPR and IT for a small company.
Sources for this topic: PwC on the NIS2 directive, Deloitte on NIS2 and the new act and an overview of NIS2 and the cybersecurity act 2026.
Conclusion
NIS2 is not a distant threat, it is a Slovak law in force since January 2025. It affects far more companies than they would expect: the larger ones directly, the smaller ones through the supply chain. The obligations are clear, the fines high, and when an attack hits, you have only hours to report it. Most of the measures, though, are plain common sense that a well-run company needs anyway. Start now and calmly, and you save yourself both the nerves and the money.
Not sure whether NIS2 affects you and where to start?
We will help you find out whether you fall under the law, do a risk analysis and put measures and incident reporting in place. In person for companies in Liptov, remotely elsewhere.
I want helpThis article is part of our Business and IT overview.
Frequently asked questions
Since when does NIS2 apply in Slovakia?
How do I find out whether NIS2 applies to my company?
Does NIS2 affect small companies and sole traders too?
What happens if we do not meet the obligations?
How quickly must a cyber incident be reported?
Where should a company start with NIS2?
Need help with IT?
We will take care of your computers, networks and security - for businesses and households in the Liptov region.
Contact us