Essential entities
The stricter, higher-obligation regime: energy, digital infrastructure, finance, transport, healthcare, public administration and other strategic sectors.
The new Czech Cybersecurity Act (264/2025 Coll.) has been in force since 1 November 2025. The NÚKIB notification deadline has passed, the one-year clock to implement measures is running, and non-compliance carries fines up to CZK 250m or 2% of turnover. Kybit doesn't build compliance out of slide decks. We build and run the exact measures the Act requires.
The Act introduces self-identification: each organisation determines for itself whether it is a regulated-service provider. Scope expanded from critical infrastructure to 22 sectors and 102 regulated services (decree 408/2025 Coll.). NÚKIB estimates around 6,000 entities in scope.
The stricter, higher-obligation regime: energy, digital infrastructure, finance, transport, healthcare, public administration and other strategic sectors.
The lower-obligation regime. For example waste management, manufacturing, food, postal services, chemicals or research.
E-commerce, water utilities, public administration and dozens of sectors the old Act 181/2014 never covered.
Specific deadlines run from the moment you meet the criteria. The essentials are below. Verify exact wording with NÚKIB or legal counsel.
Notify the regulated service within 60 days of meeting the criteria (for entities in scope from 1 Nov 2025 the deadline was 31 Dec 2025); NÚKIB then issues the registration decision.
Report contact details via the NÚKIB portal within 30 days of receiving the registration decision.
Implement, per your assigned regime, within 1 year of receiving the registration decision.
Two-stage reporting under NIS2: an initial report within roughly 24 hours and an incident notification within 72 hours.
Establish and maintain cyber-risk-management and supply-chain-security measures.
Fines up to CZK 250m or 2% of worldwide annual turnover in the higher-obligation regime (CZK 175m or 1.4% in the lower regime), whichever is higher. Liability extends to management.
Obligation by obligation, operationally and not just on paper. Each area maps to a specific service we actually run.
24/7 SOC/MDR that catches and contains the incident and prepares the NÚKIB notification within the statutory windows.
Threat hunting, risk analysis and CTI that underpin the cyber-risk-management obligation.
Penetration tests, red-team and threat-led testing (TLPT) that evidence control effectiveness for NIS2 and DORA.
SIEM/SOAR/XDR and detection-as-code: the technical measures the Act requires, deployed and tuned.
Zero Trust, IAM and PKI, ISMS and policy design: the organisational measures at governance level.
Cloud hardening, Infrastructure as Code and operational resilience: business continuity and supply-chain control.
Short on people to meet the obligations? We embed senior capacity into your team, short- or long-term.
NIS2 isn't the only regulation aimed at you. We cover the full spectrum, from finance to automotive.
Regulation (EU) 2022/2554, applicable since 17 Jan 2025. ICT-risk management, TLPT and incident reporting for finance.
The VDA ISA / ENX information-security assessment demanded across automotive suppliers. We get you assessment-ready.
The information-security management system NIS2, DORA and TISAX all build on. Design, implementation and operation.
Straight answers to what clients ask us most.
The new Cybersecurity Act (264/2025 Coll.) has been in force since 1 November 2025 and replaces the original Act No. 181/2014 Coll. It transposes the EU NIS2 Directive into Czech law.
The Act works on self-identification: each organisation determines for itself whether it is a regulated-service provider based on sector and size. Scope expanded from critical infrastructure to 22 sectors and 102 regulated services (decree 408/2025 Coll.), affecting thousands of previously unregulated companies.
The regulated service is notified within 60 days of meeting the criteria. For entities in scope from 1 November 2025 the deadline was 31 December 2025. Those who missed it are in default and exposed to penalties.
The maximum fine is up to CZK 250 million or 2% of worldwide annual turnover in the higher-obligation regime (CZK 175 million or 1.4% in the lower regime), whichever is higher. Liability can extend to members of the organisation's management.
The Act adopts NIS2's two-stage reporting: an initial report within roughly 24 hours, then an incident notification within 72 hours. Verify the exact deadlines and format for your regime with NÚKIB. Kybit prepares this evidence as part of the SOC/MDR service.
Security measures for your assigned regime must be implemented within one year of receiving the registration decision from NÚKIB. For many companies that clock is running now.
We meet the obligations operationally, not with a deck. SOC/MDR covers detection, response and incident reporting. Penetration tests evidence control effectiveness. Security engineering and architecture implement the technical and organisational measures. And when you're short on people, we add capacity to your team.
Book a consultation with a senior specialist. We'll map your obligations, show you where the gaps are, and lay out a realistic path to compliance. No discovery-call deck.