NIS2 Country Guide

NIS2 Czech Republic: Act 264/2025 Coll. — zákon o kybernetické bezpečnosti

Czechia transposed NIS2 through the new zákon o kybernetické bezpečnostiAct No. 264/2025 Coll. — in force since 1 November 2025. It replaces Act No. 181/2014 Coll. and splits every regulated organisation into one of two obligation regimes. This page sets out which regime you fall into, the 60-day notification duty, what your deadlines actually run from, and the real fine scale in CZK.

Czech Republic In force: 1 November 2025 Notify within 60 days Authority: NÚKIB Last updated: 10 August 2026

Introduction: NIS2 and the Czech context

Czechia regulated cybersecurity long before NIS2, under Act No. 181/2014 Coll. The new zákon o kybernetické bezpečnostiAct No. 264/2025 Coll. — replaces it outright and widens the perimeter substantially.

The structure that matters is not the Directive's essential/important split. Czechia regulates the service rather than the organisation — the operative term throughout the Act is regulovaná služba, a regulated service — and it sorts providers into a higher or a lower obligations regime. Which one you land in decides what you must implement, how long you have, and even who you report incidents to.

The four things most readers need: you must notify NÚKIB within 60 days of meeting the criteria; your other deadlines run not from the Act but from the day your registration decision is delivered; you then have one year before security measures and incident reporting bite; and the maximum fine is 250,000,000 CZK or 2 % of net worldwide turnover. Each is set out below.
Quick link: New to NIS2? Start with our guides “What is NIS2?” and “NIS vs NIS2”.

The Cybersecurity Act 264/2025 Coll.

NIS2 is transposed by the zákon o kybernetické bezpečnosti, Act No. 264/2025 Coll., approved by Parliament on 26 June 2025, published in the Collection of Laws on 4 August 2025 and in force since 1 November 2025. It repeals and replaces Act No. 181/2014 Coll., the previous Czech cybersecurity act.

The Act on its own will not tell you what to implement. It sets the framework, the deadlines and the penalties, then delegates the actual security measures to implementing decrees (vyhlášky) — a different one depending on your regime. Both are named in the security-measures section below. NÚKIB drafted the Act and the decrees together.

Status

Transposed and in force. Act No. 264/2025 Coll. has applied since 1 November 2025, with both security-measure decrees in force alongside it.

Legal structure

The Act sets scope, regimes, registration, reporting, supervision and penalties. The security measures themselves sit in vyhláška 409/2025 Sb. and 410/2025 Sb., one per regime.

The unit of scope

Not the organisation but the regulovaná služba — the regulated service. You can provide several, and the Act asks about each of them.

Higher or lower obligations?

This is the most important structural fact about Czech NIS2, and the one most summaries omit. The Act and the decree on regulated services create two levels of regulation, which NÚKIB describes as dvourychlostní kybernetická bezpečnost — two-speed cybersecurity, designed so that smaller and mid-sized organisations are not held to the same standard as critical national providers.

Režim vyšších povinností

The higher obligations regime. The fuller set of security measures, under vyhláška 409/2025 Sb. Incidents are reported to NÚKIB.

Režim nižších povinností

The lower obligations regime, under vyhláška 410/2025 Sb. Incidents are reported to the Národní CERT, not to NÚKIB.

How your regime is decided

The basic criterion is enterprise size, but for some services further factors are assessed. The regime for each regulated service is set out in the annex to the decree on regulated services, not left to interpretation.

One organisation, one regime

NÚKIB states the rule plainly: jedna organizace = jeden režim. If you fall into the higher regime for even one service, that regime applies automatically to all the regulated services you provide.

Why this matters more than the essential/important distinction. A group that provides several regulated services cannot mix and match. One qualifying service pulls the whole organisation up. Conversely, if every service you provide sits in the lower regime, your measures come from a different decree and your incident reports go to a different body. Establish your regime before anything else — NÚKIB publishes a calculator for exactly this purpose, linked below.

Am I in scope in Czechia?

Scope in Czechia attaches to the regulovaná služba — the regulated service — rather than to the organisation as a whole. The question the Act asks is not simply “is this company large enough?” but “does it provide a service listed in the decree on regulated services, and at what size?” Answer that for each service you run, then read your regime off the decree's annex.

Who is in scope?

  • Providers of a regulovaná služba listed in the decree on regulated services, across the NIS2 Annex I and II sectors.
  • Size is the basic criterion, assessed per service; further factors apply to some services.
  • Certain providers are in scope regardless of size — DNS, TLD name registries, trust service providers and comparable digital infrastructure.
  • Public bodies are covered. Note the Act expressly provides that state organisational units, local authorities and the Czech National Bank are not treated as “undertakings” for the size test.

Core obligations

  • Notify your regulated service to NÚKIB within 60 days of meeting the criteria.
  • Report contact details within 30 days of your registration decision being delivered.
  • Implement the security measures in the decree for your regime, within one year of that delivery.
  • Report incidents on the 24-hour / 72-hour / 30-day chain, also from one year after delivery.
  • Keep NÚKIB informed of changes — 14 days for contact data, 60 days for changes that could alter your regime.

Standards & frameworks

No certification is mandated. The binding requirements are those in your regime's vyhláška. ISO/IEC 27001 remains a sensible way to structure and evidence the work, but it is not a substitute for reading the decree that applies to you.

Check it properly: NÚKIB publishes a calculator — „Kalkulačka – týkají se nové povinnosti i vás?“ — that tells you whether you provide a regulated service and which regime applies. It is the authoritative first step and it is linked in the resources section. Our own NIS2 scope check covers the Directive-level test if you operate in more than one member state.

Registration: the 60-day duty

Czechia does not wait for a regulator to find you. If you meet the criteria for a regulated service, the duty to come forward is yours, and it is time-limited.

Within 60 days — you must notify (ohlásit) the service to NÚKIB, counted from the day you met the conditions. NÚKIB notes that for most organisations that duty arose within 60 days of the Act taking effect.
NÚKIB issues a registration decision — and at the moment it is delivered to you, you legally become a provider of a regulated service.
Within 30 days of delivery — report contact details and the other required data through the NÚKIB Portal. You may supply them earlier, with the initial notification.

Keeping the register current

Changes to reported data that are not reference data held in the basic registers: 14 days. Changes to the service that could alter your regime, or bring it within the strategically significant category: 60 days.

Domain name registration services

A separate track: report to NÚKIB within 30 days of starting to provide the service, and update reported data within 90 days of any change.

Your deadlines, and what they run from

This is the mechanism that catches people out, and no competitor we audited explains it. Almost none of your deadlines run from the Act's commencement date. They run from the day your registration decision is delivered to you — which means two organisations in the same sector can have obligations biting months apart.

Obligation Deadline Counted from
Notify the regulated service 60 days The day you met the criteria
Report contact details and required data 30 days Delivery of the registration decision
Implement the security measures 1 year Delivery of the registration decision
Begin reporting incidents 1 year Delivery of the registration decision
Report changes to non-reference data 14 days The change
Report changes that could alter your regime 60 days The change
The one-year lead-in is real, and it is not a grace period you can rely on indefinitely. It runs from your own registration decision, so the earlier you notify, the earlier the clock starts — but also the sooner you have certainty about your regime and therefore about which decree governs you. Organisations that notified promptly after 1 November 2025 are working to deadlines around late 2026.

Incident reporting

Czechia runs the familiar three-stage chain, with two Czech particularities: where you report depends on your regime, and the final deadline is expressed in 30 days rather than the Directive's “one month”.

Within 24 hours of detecting the incident — the initial report (prvotní hlášení): your identification data, the basic facts, and whether you believe it was caused by an unlawful or malicious act.
Within 72 hours — a notification updating the initial report, with your first assessment of the incident, its impact and any indicators of compromise available. Derogation: providers of EU trust services file this within 24 hours.
Within 30 days of that notification — the final report on resolution. If the incident is still running at that point, you file a progress report instead, then the final report within 30 days of resolution.

Who you report to depends on your regime

Higher-regime providers report to NÚKIB. Lower-regime providers report to the Národní CERT — the national incident coordination team — under the same procedure. Getting this wrong is an easy and avoidable mistake.

They owe you a response in 24 hours

NÚKIB or the Národní CERT must give you their assessment of the incident within 24 hours of receiving your initial report. Separately, NÚKIB must tell a higher-regime provider within 24 hours whether the incident has significant impact on the state's cyberspace.

You can ask for help

On request, NÚKIB or the Národní CERT provides methodological support for mitigation measures and further technical support in handling the reported incident. Few readers realise this is a statutory entitlement rather than a favour.

When it starts

The reporting duty begins no later than one year after your registration decision is delivered — not on 1 November 2025.

Security measures: vyhlášky 409/2025 and 410/2025

The Act imposes the duty; the decrees contain the content. Which decree binds you follows directly from your regime, and reading the wrong one is a straightforward way to build the wrong programme.

Regime Decree Reporting destination
Režim vyšších povinností (higher) vyhláška č. 409/2025 Sb., on security measures for providers in the higher obligations regime NÚKIB
Režim nižších povinností (lower) vyhláška č. 410/2025 Sb., on security measures for providers in the lower obligations regime Národní CERT
What we are not doing here. We name the decrees, say which regime each governs and link them, but we do not reproduce their contents. Two decrees' worth of security measures is a separate document, and a summary of them would be exactly the kind of second-hand precis this page exists to replace. Read the one that applies to you. NÚKIB also publishes guidance on proportionality within the lower regime, on defining the scope of cybersecurity management, and on required security roles.

Competent authorities & CSIRTs

Czechia runs a centralised model. Supervision sits with NÚKIB throughout — the Act refers to it as „Úřad“ after naming it in full — and the other bodies the Act mentions have narrow, specific roles rather than general sectoral supervision.

Role Authority Notes
National competent authority & Single Point of Contact NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost Registration, supervision, inspections and penalties. Receives incident reports from higher-regime providers, and drafted both the Act and the decrees.
Incident reports, lower regime Národní CERT The national team for coordinating and handling cybersecurity incidents, events and threats. Lower-regime providers report here rather than to NÚKIB, and it shares the 24-hour duty to respond and to give technical support on request.
Avoiding double punishment Úřad pro ochranu osobních údajů (the data protection authority) NÚKIB and the DPA are entitled to require information and cooperation from each other specifically to prevent the same breach being punished twice — once under this Act and once under data protection law.
Critical infrastructure designations Ministries, other central administrative authorities and the Česká národní banka Where responsible for designating critical infrastructure elements under crisis-management law, they must inform NÚKIB without undue delay. This is an information duty, not sectoral cybersecurity supervision.

NIS2 timeline & key dates (Czechia)

2014 — Act No. 181/2014 Coll., the previous Czech cybersecurity act, which 264/2025 replaces.
26 June 2025 — Act No. 264/2025 Coll. approved by Parliament.
4 August 2025 — published in the Collection of Laws.
1 November 2025 — the Act takes effect, together with vyhláška 409/2025 Sb. and 410/2025 Sb.
Within 60 days of meeting the criteria — the notification duty. For most organisations this fell within 60 days of 1 November 2025.
Registration decision delivered — the date that matters. Every subsequent deadline is measured from it, so it differs for every organisation.
+30 days — contact details and required data reported to NÚKIB.
+1 year — security measures implemented and incident reporting begins. For early registrants this lands in late 2026.

Sector-specific notes for Czechia

  • Energy: extensive coverage of electricity, gas and district heating infrastructure.
  • Transport: includes air, rail and road operators essential to Czech logistics.
  • Finance: supervision still runs through NÚKIB. The Česká národní banka appears in the Act only in relation to critical infrastructure designations, and is expressly excluded from the “undertaking” test for sizing.
  • Healthcare: hospitals and essential medical service providers carry heavy obligations.
  • Public administration: core governmental bodies classified as essential.
  • Digital infrastructure: data centres, cloud providers and major ICT service operators are in scope regardless of size. Trust service providers file the 72-hour notification within 24 hours instead.
  • Domain name registration services: a separate reporting track — notify within 30 days of starting, update within 90 days of a change.

Penalties & the CZK fine scale

Czechia is not in the euro area, so its penalties are set in Czech koruna, and the Act does not stop at the Directive's two ceilings — it grades offences across several bands, then adds two further fine types that apply during a supervisory process rather than for the breach itself.

Band Maximum
Highest 250,000,000 CZK or up to 2 % of net worldwide annual turnover
Second 175,000,000 CZK or up to 1.4 % of net worldwide annual turnover
Then, by offence 100,000,000 · 50,000,000 · 35,000,000 CZK
Lower bands 20,000,000 · 2,000,000 · 50,000 CZK, depending on the offence

Procedural fines (pořádková pokuta)

NÚKIB may impose up to 100,000 CZK under the administrative procedure code, and may do so repeatedly. The cumulative total is capped at 10,000,000 CZK or 1 % of net turnover for the last completed accounting period, whichever is higher.

Coercive fines (donucovací pokuta)

To compel compliance with a decision it has already made, NÚKIB may impose up to 10,000,000 CZK or 1 % of net turnover. These are separate from the penalty for the underlying breach.

Obstructing an inspection

Failing to meet the duties of an inspected person under the inspection act is itself an offence, punishable by a fine of up to 10,000,000 CZK.

Not punished twice

NÚKIB and the data protection authority must cooperate specifically to prevent the same breach being penalised under both this Act and data protection law.

Which band applies depends on the specific offence, and the Act assigns them provision by provision rather than by entity type alone. The figures above are the statutory maxima, not expected outcomes — and the repeatable procedural fine is often the more realistic exposure for an organisation that is slow to respond to NÚKIB during an inspection.

How Czechia differs

Six features that will not transfer from a NIS2 programme designed in Germany, Italy or the Nordics.

  • Two obligation regimes, not essential/important. Your measures, your deadlines and your reporting destination all follow from which regime you are in.
  • One organisation = one regime. Qualifying for the higher regime on a single service pulls every regulated service you provide up with it.
  • Deadlines run from your registration decision, not from the Act. Two comparable companies can be a year apart.
  • Lower-regime incidents go to the Národní CERT, not to the national authority.
  • Fines are in CZK and finely graded — seven bands from 250,000,000 down to 50,000 — plus repeatable procedural fines and coercive fines.
  • Thirty days, not “one month”. The final incident report deadline is expressed in days, which is not always the same date.
Czech English / meaning
zákon o kybernetické bezpečnostiThe Cybersecurity Act — Act No. 264/2025 Coll.
regulovaná službaRegulated service — the unit that scope attaches to
režim vyšších povinnostíHigher obligations regime
režim nižších povinnostíLower obligations regime
ohlášeníThe notification that starts registration
vyhláškaImplementing decree — 409/2025 Sb. and 410/2025 Sb.
NÚKIBNárodní úřad pro kybernetickou a informační bezpečnost
prvotní hlášeníThe initial 24-hour incident report
pořádková pokutaProcedural fine, repeatable
stav kybernetického nebezpečíState of cyber danger — see below
One further Czech mechanism worth knowing. The Act provides for a stav kybernetického nebezpečí, a declared state of cyber danger, which NÚKIB may extend to a maximum of 60 days from declaration while informing the government. It is a national emergency power with no Directive equivalent, and it sits above the ordinary obligations described on this page.

How to prepare for NIS2 in Czechia

  1. Run NÚKIB's calculator first. It answers both questions that matter — whether you provide a regulated service, and which regime you are in — and it is the regulator's own tool.
  2. Check every service, not just the obvious one. Because one higher-regime service pulls the whole organisation up, a single overlooked service can change your entire programme.
  3. Notify within 60 days. If you met the criteria when the Act took effect and have not yet notified, that deadline has passed — deal with it now rather than waiting to be found.
  4. Record the date your registration decision was delivered. Every subsequent deadline is measured from it, so it belongs in your compliance calendar as a fixed reference point.
  5. Gap-assess against your decree — 409/2025 Sb. for the higher regime, 410/2025 Sb. for the lower. Not against the Directive, and not against the other regime's decree.
  6. Point your incident runbook at the right body. NÚKIB for the higher regime, the Národní CERT for the lower, on a 24-hour / 72-hour / 30-day chain.
  7. Use the year. Security measures and reporting bite one year after your registration decision. That is enough time to do the work properly and not enough to leave it.
  8. Brief the board on the real exposure — not only the 250,000,000 CZK headline, but the repeatable procedural fine that accrues when an organisation is slow to respond during an inspection.

Official links & resources

FAQ: NIS2 in Czechia

Has Czechia fully transposed NIS2?
Yes. The zákon o kybernetické bezpečnosti, Act No. 264/2025 Coll., has been in force since 1 November 2025 and replaced Act No. 181/2014 Coll. Both security-measure decrees took effect alongside it.
Do entities need to register?
Yes. If you provide a regulated service you must notify NÚKIB within 60 days of meeting the criteria. NÚKIB then issues a registration decision, and you become a provider of a regulated service on the day it is delivered — which is also the date all your other deadlines are counted from.
Which sectors are in scope?
The NIS2 Annex I and II sectors, but applied to regulated services rather than to organisations as a whole. The decree on regulated services lists them and, in its annex, sets which obligation regime each falls into. NÚKIB's calculator is the quickest way to check.
Is ISO 27001 required?
No. What binds you is the vyhláška for your regime — 409/2025 Sb. for the higher, 410/2025 Sb. for the lower. ISO/IEC 27001 is a reasonable way to organise the work and evidence it, but it is not a substitute for the decree and no certification is required by name.
What is the difference between the higher and lower obligations regime?
It determines three things: which decree sets your security measures (409/2025 Sb. or 410/2025 Sb.), how extensive those measures are, and who you report incidents to — NÚKIB for the higher regime, the Národní CERT for the lower. The basic criterion is enterprise size, with further factors for some services. NÚKIB calls the model two-speed cybersecurity. Note that if any one of your regulated services falls into the higher regime, that regime applies to all of them.
When do the obligations actually start?
Not on 1 November 2025 for most organisations. The notification duty runs 60 days from when you meet the criteria, and everything after that is measured from the day your registration decision is delivered: contact data within 30 days, and both the security measures and the incident reporting duty within one year. Organisations that notified promptly after the Act took effect are working to deadlines in late 2026.
What are the maximum fines?
250,000,000 CZK or 2 % of net worldwide annual turnover in the top band, and 175,000,000 CZK or 1.4 % in the second, with further bands at 100,000,000, 50,000,000, 35,000,000, 20,000,000, 2,000,000 and 50,000 CZK depending on the offence. Separately, NÚKIB can impose repeatable procedural fines of up to 100,000 CZK during a process, capped in total at 10,000,000 CZK or 1 % of net turnover, and coercive fines on the same ceiling to enforce a decision.

Sources & verification

Every date and figure on this page was checked against a primary source on 10 August 2026. Where sources conflicted we followed the statutory text and NÚKIB.

  • The Act — full text of Act No. 264/2025 Coll. All fine bands, the incident-reporting chain, the notification and change deadlines, and the roles of the Národní CERT and the data protection authority are taken from it directly.
  • NÚKIB's own guide to the new Act — the source for the two-regime model, the “one organisation = one regime” rule, the fact that deadlines run from delivery of the registration decision, the one-year lead-in, and the decree numbers.
  • vyhláška č. 409/2025 Sb. and 410/2025 Sb. — named and linked, not summarised.
Two errors that run through the English-language coverage. The previous Czech statute is routinely called “the 2017 Cybersecurity Act”. It is No. 181/2014 Coll., cited throughout the new Act; 2017 was the year of a significant amendment, not of the act itself. And summaries usually describe the operative split as essential and important entities, where the Czech regime turns on the higher and lower obligations regimes instead.
Why no sectoral regulators are listed. Advisory content routinely gives Czechia a row of unnamed “sectoral regulators”. The Act runs supervision through NÚKIB throughout and names no general sectoral cybersecurity supervisors, so the authorities table above gives only the bodies the Act does name, with the specific and limited functions it gives them.
What we deliberately do not state. An entity count — NÚKIB publishes none, and the figures circulating elsewhere are not its. A single registration deadline — the 60-day clock runs from when your own criteria were met and everything after it from your own registration decision, so any one date would be wrong for most readers. The contents of the two decrees — named and linked instead, because a second-hand summary of security measures is exactly what this page exists to replace.
Information provided for general guidance and current at 10 August 2026. Always consult the official Czech legislation, NÚKIB publications and legal counsel for definitive NIS2 compliance requirements.