Czech Cybersecurity ActProcedure

    NÚKIB incident reporting: deadlines and procedure

    Act No. 264/2025 Coll. does not ask for two reports. It asks for five filings. This page sets them out as the Act and NÚKIB's own guidance state them, including the difference between the two regimes and an exception that is rarely published.

    Summary

    If you are short of time

    Three sentences that always hold.

    The initial report is due no later than 24 hours after you detect the incident, filed electronically through the NÚKIB portal and nowhere else. For an incident with significant impact, a notification follows within 72 hours of detection; providers of trust services get 24 hours, not 72. An incident is closed by the final report, not by stopping the attacker. In between, an interim report may fall due, either because NÚKIB asks for one or because the incident outlived the thirty-day window. Failing to file the initial report, or failing to supplement it, is an administrative offence. The clocks run from detection rather than from resolution, so the hours drain at exactly the moment the team is busiest.

    Deadlines

    The five filings and their deadlines

    Per Section 16 of Act No. 264/2025 Coll. and NÚKIB guidance.

    The five filings and their deadlines
    FilingDeadlineWhat goes in it
    Initial reportWithin 24 hours of detectionWho you are, the basic facts of the incident, and your view on whether it may have been caused by an unlawful act and whether it may have cross-border impact. Complete data is not expected at this stage.
    NÚKIB assessmentWithin 24 hours of the initial reportNot yours to file. In the higher regime NÚKIB states whether the incident has significant impact on the state's cyberspace. That determines what follows.
    NotificationWithin 72 hours of detection; 24 hours for trust servicesSignificant-impact incidents only. Updates the initial report and adds the first assessment, the impact, and indicators of compromise where you have them.
    Interim reportOn request, or once 30 days have passed since the notificationTwo different situations under one name. Either NÚKIB or the National CERT asks for one, or you file because the incident is still running past the thirty-day window, without undue delay.
    Final reportWithin 30 days of the notification; for a running incident, within 30 days of resolutionCloses the reporting duty and describes how the incident was resolved. Until it is filed, the regulator does not consider the incident closed.

    Filings go through the NÚKIB portal exclusively. The form is submitted by the statutory body or an authorised representative — a role that has to exist before an incident, not after one.

    Regime

    First work out which regime you are in

    It decides what you report at all. The difference is substantial and routinely missed.

    Higher-obligation regime

    • You report every incident meeting all of the conditions at once: it originates in cyberspace, it manifested within your defined scope, deliberate causation cannot be ruled out, and information security — integrity, availability or confidentiality — is breached.
    • You do not judge significance yourself. NÚKIB assesses it within 24 hours of your initial report.
    • The threshold is lower than most teams expect. What is tested is whether the conditions are met, not how large the damage was.

    Lower-obligation regime

    • You determine for yourself which incidents you consider significant, and report only those.
    • Which means you need your own significance criteria, written down before an incident rather than during one. Otherwise the judgement gets made under pressure with nothing to stand on.
    • For selected digital services, incidents meeting the conditions of Commission Implementing Regulation (EU) 2024/2690 count as significant automatically, whatever your internal rules say.

    Your regime is set by decree according to the regulated service you provide; it is not a choice. If you do not know which one you are in, that is the first thing to resolve, not a question for later.

    Evidence

    What the deadlines actually demand

    Not report text. Evidence that cannot be manufactured retrospectively in 24 hours.

    Incident timeline
    When it started, which asset went first, how it spread. Without deep enough logs you will not assemble one inside 72 hours, and the notification has nothing to say.
    Impact classification
    Which regulated services were hit and how. This is what decides whether the 72-hour branch applies to you at all.
    Indicators of compromise
    The Act asks for them where available. Whether they are available is decided months earlier, by what you collect and how long you keep it.
    Evidence of containment
    The final report describes how the incident was resolved. You have to be able to show what actually stopped it.
    Roles in place
    The form is filed by the statutory body or an authorised representative. That authorisation is arranged in advance, not on the day.
    Retention
    Eighteen months of logs in the higher regime is not a checklist line. It is the difference between assembling the timeline and writing that you cannot.
    Kybit

    What we do, and what stays with you

    A split worth stating plainly.

    From SOC operations we supply, inside the statutory windows, the part that cannot be caught up under pressure: the incident timeline, the impact classification and indicators of compromise, drawn from telemetry we already collect. We hold logs for 18 months, so there is something to draw on even for an incident that began long before anyone noticed it. The material is prepared in the structure the NÚKIB portal forms ask for. The filing is yours. The form is submitted by your organisation's statutory body or authorised representative, and statutory responsibility for meeting the reporting duty remains with the provider of the regulated service. No supplier can take that off you, and anyone claiming otherwise is not telling you the truth.

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    The initial report is due without undue delay and no later than 24 hours after you detect the incident, filed electronically through the NÚKIB portal and nowhere else. For an incident with significant impact, a notification follows within 72 hours of detection, updating the initial report and adding the first assessment, the impact and any indicators of compromise available. For providers of trust services the notification window is 24 hours, not 72. Every clock runs from detection, not from resolution. This follows from Section 16 of Act No. 264/2025 Coll.; guidance is issued by NÚKIB at portal.nukib.gov.cz.

    Five filings, not the two usually quoted. An initial report within 24 hours of detection. NÚKIB's significance assessment within 24 hours of that report, which is not yours to file. A notification within 72 hours of detection for significant-impact incidents. An interim report, either when NÚKIB or the National CERT requests one or without undue delay once the incident outlives 30 days from the notification. And a final report, which closes the duty. Until the final report is filed the regulator does not treat the incident as closed, however long ago you stopped the attacker.

    Within 30 days of the day you filed the notification under Section 16(3)(a). If the incident is still running when that window closes, you file an interim report on the current state of handling without undue delay, and then the final report no later than 30 days after the incident was resolved. The final report describes how the incident was resolved, and only it ends the reporting duty.

    Who judges significance. In the higher regime you report every incident that originates in cyberspace, manifested within your defined scope, cannot be ruled out as deliberate, and breaches information security; NÚKIB then assesses significance within 24 hours. In the lower regime you determine for yourself which incidents you consider significant and report only those, which means having your own significance criteria written down in advance. In both regimes, for selected digital services, incidents meeting the conditions of Commission Implementing Regulation (EU) 2024/2690 count as significant automatically. Your regime is set by decree according to the service you provide; it is not a choice.

    Failing to file the initial report under Section 16(1), or failing to supplement the details under Section 16(3), is not a formality — it is an administrative offence by the provider of the regulated service. The Act's penalty ceiling reaches CZK 250,000,000 or 2% of turnover in the higher-obligation regime, and CZK 175,000,000 or 1.4% in the lower, with the actual figure depending on the nature of the breach. The more practical risk is different: the clocks run from detection, so deadlines are usually missed because nobody knows who files, or because the evidence needed to complete the form does not exist.

    No. The form is submitted by your organisation's statutory body or an authorised representative, and statutory responsibility for the reporting duty stays with the provider of the regulated service. What a provider can supply is the evidence: the incident timeline, the impact classification and indicators of compromise from the telemetry it collects, inside the windows in which the filing is due. In practice that is the deciding part, because evidence cannot be manufactured retrospectively in 24 hours. The filing itself, and the liability for it, remain yours.

    Verify

    Sources

    Check it. These link to the primary material, not to our reading of it.

    This page reflects the position as at 31 August 2026. NÚKIB issues and revises the guidance, so verify the procedure on its portal before filing. This is not legal advice.

    Nothing to build that evidence from?

    That is not a problem you solve on the day. Tell us what you collect now and how long you keep it.