The Government Has Approved the Draft Cyber Resilience Act. What Could It Mean for Critical Infrastructure?

28. augusta 2026

The Government of the Slovak Republic has approved a draft act on the cybersecurity of products with digital elements, also referred to as the cyber resilience act. This is a further step in the legislative process; the bill will subsequently be debated in the National Council of the Slovak Republic.


The very focus of the forthcoming legislation opens up an important topic from the perspective of critical infrastructure. Energy, transport, water management, healthcare, digital networks and public administration are today heavily dependent on products containing digital elements. The security of these products therefore cannot be seen separately from the security and resilience of the services they support.

From the perspective of the Critical Infrastructure Association of the Slovak Republic, the broader idea is what matters most: the resilience of critical infrastructure begins with the technologies it is built from.


The forthcoming legislation will not, however, apply to all digital products without distinction. Exemptions cover, for example, certain open-source products, as well as areas already subject to specific European regulation – such as civil aviation or the automotive industry. A special regime also applies to products developed exclusively for national security or defence purposes.


Security Begins Before Procurement


In cybersecurity, attention often focuses on protecting one's own networks, systems, data and user accounts. That is essential, but it is not enough. An organisation may have sound internal security measures in place and still remain vulnerable if it uses a product with serious security shortcomings or inadequate support.


The risk therefore arises as early as the decision on which technology the organisation will buy and under what conditions it will operate it.

For products intended for critical processes, alongside price, functionality and technical parameters, their long-term security sustainability should also be assessed. What matters is how vulnerabilities are handled, the availability of updates, the length of technical support, the options for secure configuration and the extent of the supplier's remote access.


Security should thus not be a property addressed after the fact, but one of the criteria applied when the product is selected.


Technological Dependence Is an Operational Risk


Modern critical infrastructure operates within an extensive network of technological and supplier relationships. Besides manufacturers, it involves integrators, service companies, providers of communication and cloud services and other subcontractors.


For a critical entity it is therefore important to know which technologies are indispensable for providing the essential service, which components have no immediate substitute, and where there is a pronounced dependence on an external partner. Mapping of this kind makes it possible to identify the points at which technological or supplier dependence may turn into an operational risk in a crisis.

Recording them is not enough in itself.


Real preparedness is tested only by concrete scenarios – for example the unavailability of a manufacturer, the failure of a service company, the compromise of an update mechanism, or the unavailability of an external digital service. It is precisely such situations that can reveal the difference between formally established processes and an organisation's actual ability to cope with disruption.


The Long Service Life of Equipment Brings a Particular Challenge


In energy, transport, industry and water management, technologies are often in use for decades. The digital components within them, however, age considerably faster than the physical infrastructure itself.


A situation can therefore arise in which equipment is still technically functional, but its operating system, communication protocol or security feature is no longer supported by the manufacturer.


When making investment decisions it is therefore necessary to consider not only the purchase price and technical service life, but also future security maintenance and modernisation. Technological debt can gradually turn into a vulnerability whose removal will be costly or operationally complicated.


Cyber Resilience as Part of Strategic Decision-Making


Cyber resilience cannot be the exclusive task of the IT or security department. In critical infrastructure it concerns the organisation's management, operations, investment, procurement and continuity management. In major technological decisions it is therefore necessary to assess not only the likelihood of an incident, but also its possible consequences and the organisation's ability to restore safe operation.


Resilience presupposes readiness for a situation in which preventive measures fail to avert disruption. This may mean the option of temporary operation in a limited mode, the replacement of a critical component, or the use of an alternative procedure.


From Preventing an Incident to the Ability to Carry On


Cyber resilience does not mean a state in which an incident never occurs. It represents the ability to identify an incident in good time, limit its consequences and maintain the provision of the service, or restore it within an acceptable time.


For critical infrastructure it is therefore essential to link cybersecurity with operational continuity. The significance of an incident is measured not only by the extent of the information systems affected, but above all by its possible impact on the provision of essential services and on other interdependent sectors.


Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic, comments in this connection:

The resilience of critical infrastructure begins with the technologies it is built from. A critical entity needs to know not only what a given product can do, but also where it comes from, what dependencies arise from using it, and whether it will be secure and supported throughout the entire period during which the provision of an essential service depends on it.”


An Opportunity to Prepare in Advance


From the perspective of critical infrastructure, the government's approval of the bill can be seen as an impulse for a broader discussion on the security of the technologies that enter critical processes. Regardless of how the legislative process unfolds, it is already appropriate today to consider whether organisations know their key technological dependencies, the support conditions of the products they use, and the risks associated with their suppliers.


The Critical Infrastructure Association of the Slovak Republic is systematically developing professional capacities in assessing technological risks, monitoring supply chains and sharing information between individual sectors – activities that can contribute to the early identification of risks and to strengthening the resilience of critical infrastructure.


The forthcoming legislation thus opens up an opportunity to shift the view of cybersecurity from protecting individual products towards a broader goal: increasing the resilience of the services and systems on which the functioning of society depends.

 

28. augusta 2026
Vláda Slovenskej republiky schválila návrh zákona o kybernetickej bezpečnosti produktov s digitálnymi prvkami, označovaný aj ako zákon o kybernetickej odolnosti. Ide o ďalší krok v legislatívnom procese, návrh zákona bude následne predmetom prerokovania v Národnej rade Slovenskej republiky. 
27. augusta 2026
The digitalisation of industry, energy, transport, water management and other strategic sectors brings a marked increase in efficiency and opens up possibilities for automated control. At the same time, however, it creates an ever closer link between the digital and the physical world. It is precisely this link that represents one of the significant challenges for the protection and resilience of critical infrastructure. 
27. augusta 2026
Digitalizácia priemyslu, energetiky, dopravy, vodného hospodárstva či ďalších strategických odvetví prináša výrazné zvýšenie efektivity a možnosti automatizovaného riadenia. Zároveň však vytvára čoraz tesnejšie prepojenie medzi digitálnym a fyzickým svetom. Práve toto prepojenie predstavuje jednu z významných výziev pre ochranu a odolnosť kritickej infraštruktúry.
27. augusta 2026
The Ministry of the Interior of the Slovak Republic has made public the open part of the National List of Critical Entities of the Slovak Republic. The list is based on Act No. 367/2024 Coll. on Critical Infrastructure and on Amendments to Certain Acts, by which the Slovak Republic transposed the European CER Directive on the resilience of critical entities, and it is the outcome of the critical entity identification process carried out at national level.
27. augusta 2026
Ministerstvo vnútra SR sprístupnilo verejnú časť Národného zoznamu kritických subjektov Slovenskej republiky. Zoznam vychádza zo zákona č. 367/2024 Z. z. o kritickej infraštruktúre a o zmene a doplnení niektorých zákonov, ktorým Slovenská republika prebrala európsku smernicu CER o odolnosti kritických subjektov a je výsledkom procesu identifikácie kritických subjektov realizovaného na národnej úrovni.
25. augusta 2026
In our series gradually introducing the individual essential services under Act No. 367/2024 Coll. on Critical Infrastructure, we continue with another service in the Nuclear Energy subsector: the construction, commissioning, operation and decommissioning of a nuclear installation.
25. augusta 2026
V našej sérii, v ktorej postupne predstavujeme jednotlivé základné služby podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre, pokračujeme ďalšou službou v podsektore Jadrovej energetiky: výstavba, uvádzanie do prevádzky, prevádzka a vyraďovanie jadrového zariadenia.
21. augusta 2026
The upcoming heating season is a reminder that security of energy supply is not merely a question of the market. The Echo24 portal has drawn attention to an analysis by Oxford Economics, according to which this may be the European Union's most demanding winter in terms of energy supply since the crisis period of 2021–2022. The reasons cited are a combination of slower filling of storage facilities, geopolitical risks, supply outages, drought affecting electricity generation, and higher demand for gas in the power sector. 
21. augusta 2026
Nadchádzajúca vykurovacia sezóna pripomína, že bezpečnosť dodávok energie nie je len otázkou trhu. Portál Echo24 upozornil na analýzu Oxford Economics, podľa ktorej môže byť pre Európsku úniu najnáročnejšou zimou z hľadiska dodávok energie od krízového obdobia rokov 2021 – 2022. Dôvodom má byť kombinácia pomalšieho plnenia zásobníkov, geopolitických rizík, výpadkov dodávok, sucha ovplyvňujúceho výrobu elektriny a vyššieho dopytu po plyne v energetike.
17. augusta 2026
We continue our series dedicated to essential services under Act No. 367/2024 Coll. on critical infrastructure. This time we focus on a service whose importance is growing alongside the transformation of the energy sector – electricity storage.