NIS2 · ZoKB · Act 264/2025Regulatory compliance

    NIS2 and the new Czech Cybersecurity Act

    The new Czech Cybersecurity Act (264/2025 Coll.) has been in force since 1 November 2025. The NÚKIB notification deadline has passed, the one-year clock to implement measures is running, and non-compliance carries fines up to CZK 250m or 2% of turnover. Kybit doesn't build compliance out of slide decks. We build and run the exact measures the Act requires.

    Check if it applies to you
    Regulatory compliance

    Does the new Act apply to you?

    The Act introduces self-identification: each organisation determines for itself whether it is a regulated-service provider. Scope expanded from critical infrastructure to 22 sectors and 102 regulated services (decree 408/2025 Coll.). NÚKIB estimates around 6,000 entities in scope.

    01

    Essential entities

    The stricter, higher-obligation regime: energy, digital infrastructure, finance, transport, healthcare, public administration and other strategic sectors.

    02

    Important entities

    The lower-obligation regime. For example waste management, manufacturing, food, postal services, chemicals or research.

    03

    Newly in scope

    E-commerce, water utilities, public administration and dozens of sectors the old Act 181/2014 never covered.

    Regulatory compliance

    Key obligations and deadlines

    Specific deadlines run from the moment you meet the criteria. The essentials are below. Verify exact wording with NÚKIB or legal counsel.

    • 01

      NÚKIB notification

      Notify the regulated service within 60 days of meeting the criteria (for entities in scope from 1 Nov 2025 the deadline was 31 Dec 2025); NÚKIB then issues the registration decision.

    • 02

      Contact details

      Report contact details via the NÚKIB portal within 30 days of receiving the registration decision.

    • 03

      Security measures

      Implement, per your assigned regime, within 1 year of receiving the registration decision.

    • 04

      Incident reporting

      Two-stage reporting under NIS2: an initial report within roughly 24 hours and an incident notification within 72 hours.

    • 05

      Risk management

      Establish and maintain cyber-risk-management and supply-chain-security measures.

    • 06

      Penalties

      Fines up to CZK 250m or 2% of worldwide annual turnover in the higher-obligation regime (CZK 175m or 1.4% in the lower regime), whichever is higher. Liability extends to management.

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    The new Cybersecurity Act (264/2025 Coll.) has been in force since 1 November 2025 and replaces the original Act No. 181/2014 Coll. It transposes the EU NIS2 Directive into Czech law.

    The Act works on self-identification: each organisation determines for itself whether it is a regulated-service provider based on sector and size. Scope expanded from critical infrastructure to 22 sectors and 102 regulated services (decree 408/2025 Coll.), affecting thousands of previously unregulated companies.

    The regulated service is notified within 60 days of meeting the criteria. For entities in scope from 1 November 2025 the deadline was 31 December 2025. Those who missed it are in default and exposed to penalties.

    The maximum fine is up to CZK 250 million or 2% of worldwide annual turnover in the higher-obligation regime (CZK 175 million or 1.4% in the lower regime), whichever is higher. Liability can extend to members of the organisation's management.

    The Act adopts NIS2's two-stage reporting: an initial report within roughly 24 hours, then an incident notification within 72 hours. Verify the exact deadlines and format for your regime with NÚKIB. Kybit prepares this evidence as part of the SOC/MDR service.

    Security measures for your assigned regime must be implemented within one year of receiving the registration decision from NÚKIB. For many companies that clock is running now.

    We meet the obligations operationally, not with a deck. SOC/MDR covers detection, response and incident reporting. Penetration tests evidence control effectiveness. Security engineering and architecture implement the technical and organisational measures. And when you're short on people, we add capacity to your team.

    Meet NIS2 before an audit does

    Book a consultation with a senior specialist. We'll map your obligations, show you where the gaps are, and lay out a realistic path to compliance. No discovery-call deck.