Slovakia Has a National List of Critical Entities. The Operating Regime Is Changing for the Organisations Concerned
The Ministry of the Interior of the Slovak Republic has made public the open part of the National List of Critical Entities of the Slovak Republic. The list is based on Act No. 367/2024 Coll. on Critical Infrastructure and on Amendments to Certain Acts, by which the Slovak Republic transposed the European CER Directive on the resilience of critical entities, and it is the outcome of the critical entity identification process carried out at national level.
What the List Contains
The public part of the list is structured by the sectors and subsectors set out in Annex No. 1 to the Act on Critical Infrastructure. The Annex defines eleven sectors: energy, transport, finance, postal services, healthcare, water and the atmosphere, digital infrastructure, public administration, space, production, processing and distribution of food, and industry. Slovakia goes beyond the CER Directive here: it has included postal services and the pharmaceutical, metallurgical and chemical industries among the protected sectors over and above the European framework.
For each entity, the list states the name of the central authority, the sector, the subsector, the business name or title, the registered office and the essential service provided. The majority of the identified entities belong to the public sector – state enterprises, public authorities and organisations with an ownership interest held by the state or by municipalities – complemented by a group of private operators.
This has a practical consequence. In Slovakia, the state is not only the regulator but also the largest operator of strategic assets. Most of the obligations under the Act will therefore fall on organisations that the state owns or controls; at the same time, private operators hold parts of the chain that the state cannot replace.
Detailed data on critical infrastructure, contact persons and incidents remain in the non-public part of the list, administered by the Ministry of the Interior together with the relevant central authorities.
What It Means in Practice
Inclusion on the list is not an administrative formality. An entity must carry out a whole range of statutory tasks and ensure compliance with the obligations arising from its status as a critical entity.
The Act sets specific deadlines for this. Within nine months of receiving notification of its inclusion, an entity must prepare a risk assessment; within ten months, a security plan, and it must implement the measures arising from it. A significant incident must be reported within 24 hours of being detected. Failure to comply carries fines of up to EUR 300,000.
For some organisations this means a change in operating culture, not an addition to their documentation. At the same time, it raises a question the entire EU is grappling with: how to align CER requirements with cybersecurity regulation and with the rules applicable in the financial sector, so that banks and strategic enterprises do not undergo three almost identical audits under three different headings.
The practical value of the list will become apparent in a crisis. If state bodies know in advance which elements are critical and how they are interconnected, they can concentrate their capacities and their response where the most serious consequences threaten, instead of proceeding in the order in which reports come in.
The Domino Effect as the Key Criterion
The difference between an ordinary company and a critical entity does not lie in the size of its turnover, but in the reach of an outage. A technical problem at an e-shop is felt by its customers. An outage at a transmission system operator or a large waterworks hits hundreds of thousands of people at once, along with hospitals, production lines, ATMs and payment terminals. The degree of criticality is determined by the scale and severity of the cascading consequences a failure may trigger.
The Contribution of the Critical Infrastructure Association of the Slovak Republic in Practice
The Critical Infrastructure Association of the Slovak Republic (AKI SR) is among those bodies that have long called for the list to be finalised and have been preparing the organisations concerned for it. It provides a professional platform for cooperation between the state, regulators and operators of essential services across sectors – from energy through transport and healthcare to digital infrastructure.
“The process of identifying critical entities is not merely a legislative obligation. It is the moment that determines how resilient the state will be in real crisis situations,” said Tibor Straka, President of AKI SR.
The Association provides its members with methodological guidance, interpretation of the implementing rules under preparation, and space to share experience across sectors. That last point tends to be underestimated: sectors deal with very similar problems – dependence on a single supplier, a shortage of personnel for night shifts in control rooms, incompatible incident reporting – yet without a common platform each works its way towards solutions separately.
The Association’s cooperation with the state administration is anchored in memoranda with the Ministry of the Interior of the Slovak Republic, the Ministry of Economy of the Slovak Republic and the National Security Authority. These allow it to channel operators’ comments into the preparation of implementing regulations and, conversely, to convey to its members the interpretation of requirements before they are due to be reflected in practice.
The Law Knows the List, the Attacker Knows the Chain
The area causing the greatest difficulties under the new regime is supply chains. A critical entity’s obligations do not end at its gate. Resilience is determined by the weakest link – the supplier of spare parts, the provider of remote technology management, the service company with remote access to industrial systems, the carrier. Most of these suppliers do not appear on the list and formally have no obligations under the Act.
Yet responsibility for them rests with the critical entity. It must know who has access to its systems and premises, how long it can hold out without a particular supplier, and whether an alternative exists. In practice this cannot be resolved other than through contractual terms, supplier vetting and the testing of fallback scenarios. AKI SR addresses this topic systematically: it maps dependencies across sectors, prepares recommendations for the contractual safeguarding of suppliers, and creates space for operators to exchange experience of specific failures before they can be repeated.
AKI SR as a Platform for the Next Step
Publication of the list closes the identification phase and opens the more demanding one – putting measures into operation. The same applies to organisations already on the list and to those that may be added when it is updated: the nine- and ten-month deadlines run from the delivery of the notification, and setting up processes is cheapest right now.
It is precisely in this phase that AKI SR plays its most significant role: it conveys the interpretation of the rules, transfers experience between sectors, and helps members translate statutory requirements into concrete operating procedures and contractual relationships with suppliers.
For entities that want to have this knowledge before a first audit or a first incident forces it upon them, membership of the Critical Infrastructure Association of the Slovak Republic is the most direct route to making the transition to the new regime without operational complications.


Gas as a Test of Slovakia's Resilience: Energy Security Does Not End with the Price of the Commodity






