Act No. 264/2025 Coll. does not ask for two reports. It asks for five filings. This page sets them out as the Act and NÚKIB's own guidance state them, including the difference between the two regimes and an exception that is rarely published.
Three sentences that always hold.
The initial report is due no later than 24 hours after you detect the incident, filed electronically through the NÚKIB portal and nowhere else. For an incident with significant impact, a notification follows within 72 hours of detection; providers of trust services get 24 hours, not 72. An incident is closed by the final report, not by stopping the attacker. In between, an interim report may fall due, either because NÚKIB asks for one or because the incident outlived the thirty-day window. Failing to file the initial report, or failing to supplement it, is an administrative offence. The clocks run from detection rather than from resolution, so the hours drain at exactly the moment the team is busiest.
Per Section 16 of Act No. 264/2025 Coll. and NÚKIB guidance.
| Filing | Deadline | What goes in it |
|---|---|---|
| Initial report | Within 24 hours of detection | Who you are, the basic facts of the incident, and your view on whether it may have been caused by an unlawful act and whether it may have cross-border impact. Complete data is not expected at this stage. |
| NÚKIB assessment | Within 24 hours of the initial report | Not yours to file. In the higher regime NÚKIB states whether the incident has significant impact on the state's cyberspace. That determines what follows. |
| Notification | Within 72 hours of detection; 24 hours for trust services | Significant-impact incidents only. Updates the initial report and adds the first assessment, the impact, and indicators of compromise where you have them. |
| Interim report | On request, or once 30 days have passed since the notification | Two different situations under one name. Either NÚKIB or the National CERT asks for one, or you file because the incident is still running past the thirty-day window, without undue delay. |
| Final report | Within 30 days of the notification; for a running incident, within 30 days of resolution | Closes the reporting duty and describes how the incident was resolved. Until it is filed, the regulator does not consider the incident closed. |
Filings go through the NÚKIB portal exclusively. The form is submitted by the statutory body or an authorised representative — a role that has to exist before an incident, not after one.
It decides what you report at all. The difference is substantial and routinely missed.
Your regime is set by decree according to the regulated service you provide; it is not a choice. If you do not know which one you are in, that is the first thing to resolve, not a question for later.
Not report text. Evidence that cannot be manufactured retrospectively in 24 hours.
A split worth stating plainly.
From SOC operations we supply, inside the statutory windows, the part that cannot be caught up under pressure: the incident timeline, the impact classification and indicators of compromise, drawn from telemetry we already collect. We hold logs for 18 months, so there is something to draw on even for an incident that began long before anyone noticed it. The material is prepared in the structure the NÚKIB portal forms ask for. The filing is yours. The form is submitted by your organisation's statutory body or authorised representative, and statutory responsibility for meeting the reporting duty remains with the provider of the regulated service. No supplier can take that off you, and anyone claiming otherwise is not telling you the truth.
Straight answers to what clients ask us most.
The initial report is due without undue delay and no later than 24 hours after you detect the incident, filed electronically through the NÚKIB portal and nowhere else. For an incident with significant impact, a notification follows within 72 hours of detection, updating the initial report and adding the first assessment, the impact and any indicators of compromise available. For providers of trust services the notification window is 24 hours, not 72. Every clock runs from detection, not from resolution. This follows from Section 16 of Act No. 264/2025 Coll.; guidance is issued by NÚKIB at portal.nukib.gov.cz.
Five filings, not the two usually quoted. An initial report within 24 hours of detection. NÚKIB's significance assessment within 24 hours of that report, which is not yours to file. A notification within 72 hours of detection for significant-impact incidents. An interim report, either when NÚKIB or the National CERT requests one or without undue delay once the incident outlives 30 days from the notification. And a final report, which closes the duty. Until the final report is filed the regulator does not treat the incident as closed, however long ago you stopped the attacker.
Within 30 days of the day you filed the notification under Section 16(3)(a). If the incident is still running when that window closes, you file an interim report on the current state of handling without undue delay, and then the final report no later than 30 days after the incident was resolved. The final report describes how the incident was resolved, and only it ends the reporting duty.
Who judges significance. In the higher regime you report every incident that originates in cyberspace, manifested within your defined scope, cannot be ruled out as deliberate, and breaches information security; NÚKIB then assesses significance within 24 hours. In the lower regime you determine for yourself which incidents you consider significant and report only those, which means having your own significance criteria written down in advance. In both regimes, for selected digital services, incidents meeting the conditions of Commission Implementing Regulation (EU) 2024/2690 count as significant automatically. Your regime is set by decree according to the service you provide; it is not a choice.
Failing to file the initial report under Section 16(1), or failing to supplement the details under Section 16(3), is not a formality — it is an administrative offence by the provider of the regulated service. The Act's penalty ceiling reaches CZK 250,000,000 or 2% of turnover in the higher-obligation regime, and CZK 175,000,000 or 1.4% in the lower, with the actual figure depending on the nature of the breach. The more practical risk is different: the clocks run from detection, so deadlines are usually missed because nobody knows who files, or because the evidence needed to complete the form does not exist.
No. The form is submitted by your organisation's statutory body or an authorised representative, and statutory responsibility for the reporting duty stays with the provider of the regulated service. What a provider can supply is the evidence: the incident timeline, the impact classification and indicators of compromise from the telemetry it collects, inside the windows in which the filing is due. In practice that is the deciding part, because evidence cannot be manufactured retrospectively in 24 hours. The filing itself, and the liability for it, remain yours.
Check it. These link to the primary material, not to our reading of it.
This page reflects the position as at 31 August 2026. NÚKIB issues and revises the guidance, so verify the procedure on its portal before filing. This is not legal advice.
That is not a problem you solve on the day. Tell us what you collect now and how long you keep it.