NIS2 Czech Republic: Act 264/2025 Coll. — zákon o kybernetické bezpečnosti
Czechia transposed NIS2 through the new zákon o kybernetické bezpečnosti — Act No. 264/2025 Coll. — in force since 1 November 2025. It replaces Act No. 181/2014 Coll. and splits every regulated organisation into one of two obligation regimes. This page sets out which regime you fall into, the 60-day notification duty, what your deadlines actually run from, and the real fine scale in CZK.
Introduction: NIS2 and the Czech context
Czechia regulated cybersecurity long before NIS2, under Act No. 181/2014 Coll. The new zákon o kybernetické bezpečnosti — Act No. 264/2025 Coll. — replaces it outright and widens the perimeter substantially.
The structure that matters is not the Directive's essential/important split. Czechia regulates the service rather than the organisation — the operative term throughout the Act is regulovaná služba, a regulated service — and it sorts providers into a higher or a lower obligations regime. Which one you land in decides what you must implement, how long you have, and even who you report incidents to.
The Cybersecurity Act 264/2025 Coll.
NIS2 is transposed by the zákon o kybernetické bezpečnosti, Act No. 264/2025 Coll., approved by Parliament on 26 June 2025, published in the Collection of Laws on 4 August 2025 and in force since 1 November 2025. It repeals and replaces Act No. 181/2014 Coll., the previous Czech cybersecurity act.
The Act on its own will not tell you what to implement. It sets the framework, the deadlines and the penalties, then delegates the actual security measures to implementing decrees (vyhlášky) — a different one depending on your regime. Both are named in the security-measures section below. NÚKIB drafted the Act and the decrees together.
Status
Transposed and in force. Act No. 264/2025 Coll. has applied since 1 November 2025, with both security-measure decrees in force alongside it.
Legal structure
The Act sets scope, regimes, registration, reporting, supervision and penalties. The security measures themselves sit in vyhláška 409/2025 Sb. and 410/2025 Sb., one per regime.
The unit of scope
Not the organisation but the regulovaná služba — the regulated service. You can provide several, and the Act asks about each of them.
Higher or lower obligations?
This is the most important structural fact about Czech NIS2, and the one most summaries omit. The Act and the decree on regulated services create two levels of regulation, which NÚKIB describes as dvourychlostní kybernetická bezpečnost — two-speed cybersecurity, designed so that smaller and mid-sized organisations are not held to the same standard as critical national providers.
Režim vyšších povinností
The higher obligations regime. The fuller set of security measures, under vyhláška 409/2025 Sb. Incidents are reported to NÚKIB.
Režim nižších povinností
The lower obligations regime, under vyhláška 410/2025 Sb. Incidents are reported to the Národní CERT, not to NÚKIB.
How your regime is decided
The basic criterion is enterprise size, but for some services further factors are assessed. The regime for each regulated service is set out in the annex to the decree on regulated services, not left to interpretation.
One organisation, one regime
NÚKIB states the rule plainly: jedna organizace = jeden režim. If you fall into the higher regime for even one service, that regime applies automatically to all the regulated services you provide.
Am I in scope in Czechia?
Scope in Czechia attaches to the regulovaná služba — the regulated service — rather than to the organisation as a whole. The question the Act asks is not simply “is this company large enough?” but “does it provide a service listed in the decree on regulated services, and at what size?” Answer that for each service you run, then read your regime off the decree's annex.
Who is in scope?
- Providers of a regulovaná služba listed in the decree on regulated services, across the NIS2 Annex I and II sectors.
- Size is the basic criterion, assessed per service; further factors apply to some services.
- Certain providers are in scope regardless of size — DNS, TLD name registries, trust service providers and comparable digital infrastructure.
- Public bodies are covered. Note the Act expressly provides that state organisational units, local authorities and the Czech National Bank are not treated as “undertakings” for the size test.
Core obligations
- Notify your regulated service to NÚKIB within 60 days of meeting the criteria.
- Report contact details within 30 days of your registration decision being delivered.
- Implement the security measures in the decree for your regime, within one year of that delivery.
- Report incidents on the 24-hour / 72-hour / 30-day chain, also from one year after delivery.
- Keep NÚKIB informed of changes — 14 days for contact data, 60 days for changes that could alter your regime.
Standards & frameworks
No certification is mandated. The binding requirements are those in your regime's vyhláška. ISO/IEC 27001 remains a sensible way to structure and evidence the work, but it is not a substitute for reading the decree that applies to you.
Registration: the 60-day duty
Czechia does not wait for a regulator to find you. If you meet the criteria for a regulated service, the duty to come forward is yours, and it is time-limited.
Keeping the register current
Changes to reported data that are not reference data held in the basic registers: 14 days. Changes to the service that could alter your regime, or bring it within the strategically significant category: 60 days.
Domain name registration services
A separate track: report to NÚKIB within 30 days of starting to provide the service, and update reported data within 90 days of any change.
Your deadlines, and what they run from
This is the mechanism that catches people out, and no competitor we audited explains it. Almost none of your deadlines run from the Act's commencement date. They run from the day your registration decision is delivered to you — which means two organisations in the same sector can have obligations biting months apart.
| Obligation | Deadline | Counted from |
|---|---|---|
| Notify the regulated service | 60 days | The day you met the criteria |
| Report contact details and required data | 30 days | Delivery of the registration decision |
| Implement the security measures | 1 year | Delivery of the registration decision |
| Begin reporting incidents | 1 year | Delivery of the registration decision |
| Report changes to non-reference data | 14 days | The change |
| Report changes that could alter your regime | 60 days | The change |
Incident reporting
Czechia runs the familiar three-stage chain, with two Czech particularities: where you report depends on your regime, and the final deadline is expressed in 30 days rather than the Directive's “one month”.
Who you report to depends on your regime
Higher-regime providers report to NÚKIB. Lower-regime providers report to the Národní CERT — the national incident coordination team — under the same procedure. Getting this wrong is an easy and avoidable mistake.
They owe you a response in 24 hours
NÚKIB or the Národní CERT must give you their assessment of the incident within 24 hours of receiving your initial report. Separately, NÚKIB must tell a higher-regime provider within 24 hours whether the incident has significant impact on the state's cyberspace.
You can ask for help
On request, NÚKIB or the Národní CERT provides methodological support for mitigation measures and further technical support in handling the reported incident. Few readers realise this is a statutory entitlement rather than a favour.
When it starts
The reporting duty begins no later than one year after your registration decision is delivered — not on 1 November 2025.
Security measures: vyhlášky 409/2025 and 410/2025
The Act imposes the duty; the decrees contain the content. Which decree binds you follows directly from your regime, and reading the wrong one is a straightforward way to build the wrong programme.
| Regime | Decree | Reporting destination |
|---|---|---|
| Režim vyšších povinností (higher) | vyhláška č. 409/2025 Sb., on security measures for providers in the higher obligations regime | NÚKIB |
| Režim nižších povinností (lower) | vyhláška č. 410/2025 Sb., on security measures for providers in the lower obligations regime | Národní CERT |
NIS2 timeline & key dates (Czechia)
Sector-specific notes for Czechia
- Energy: extensive coverage of electricity, gas and district heating infrastructure.
- Transport: includes air, rail and road operators essential to Czech logistics.
- Finance: supervision still runs through NÚKIB. The Česká národní banka appears in the Act only in relation to critical infrastructure designations, and is expressly excluded from the “undertaking” test for sizing.
- Healthcare: hospitals and essential medical service providers carry heavy obligations.
- Public administration: core governmental bodies classified as essential.
- Digital infrastructure: data centres, cloud providers and major ICT service operators are in scope regardless of size. Trust service providers file the 72-hour notification within 24 hours instead.
- Domain name registration services: a separate reporting track — notify within 30 days of starting, update within 90 days of a change.
Penalties & the CZK fine scale
Czechia is not in the euro area, so its penalties are set in Czech koruna, and the Act does not stop at the Directive's two ceilings — it grades offences across several bands, then adds two further fine types that apply during a supervisory process rather than for the breach itself.
| Band | Maximum |
|---|---|
| Highest | 250,000,000 CZK or up to 2 % of net worldwide annual turnover |
| Second | 175,000,000 CZK or up to 1.4 % of net worldwide annual turnover |
| Then, by offence | 100,000,000 · 50,000,000 · 35,000,000 CZK |
| Lower bands | 20,000,000 · 2,000,000 · 50,000 CZK, depending on the offence |
Procedural fines (pořádková pokuta)
NÚKIB may impose up to 100,000 CZK under the administrative procedure code, and may do so repeatedly. The cumulative total is capped at 10,000,000 CZK or 1 % of net turnover for the last completed accounting period, whichever is higher.
Coercive fines (donucovací pokuta)
To compel compliance with a decision it has already made, NÚKIB may impose up to 10,000,000 CZK or 1 % of net turnover. These are separate from the penalty for the underlying breach.
Obstructing an inspection
Failing to meet the duties of an inspected person under the inspection act is itself an offence, punishable by a fine of up to 10,000,000 CZK.
Not punished twice
NÚKIB and the data protection authority must cooperate specifically to prevent the same breach being penalised under both this Act and data protection law.
How Czechia differs
Six features that will not transfer from a NIS2 programme designed in Germany, Italy or the Nordics.
- Two obligation regimes, not essential/important. Your measures, your deadlines and your reporting destination all follow from which regime you are in.
- One organisation = one regime. Qualifying for the higher regime on a single service pulls every regulated service you provide up with it.
- Deadlines run from your registration decision, not from the Act. Two comparable companies can be a year apart.
- Lower-regime incidents go to the Národní CERT, not to the national authority.
- Fines are in CZK and finely graded — seven bands from 250,000,000 down to 50,000 — plus repeatable procedural fines and coercive fines.
- Thirty days, not “one month”. The final incident report deadline is expressed in days, which is not always the same date.
| Czech | English / meaning |
|---|---|
| zákon o kybernetické bezpečnosti | The Cybersecurity Act — Act No. 264/2025 Coll. |
| regulovaná služba | Regulated service — the unit that scope attaches to |
| režim vyšších povinností | Higher obligations regime |
| režim nižších povinností | Lower obligations regime |
| ohlášení | The notification that starts registration |
| vyhláška | Implementing decree — 409/2025 Sb. and 410/2025 Sb. |
| NÚKIB | Národní úřad pro kybernetickou a informační bezpečnost |
| prvotní hlášení | The initial 24-hour incident report |
| pořádková pokuta | Procedural fine, repeatable |
| stav kybernetického nebezpečí | State of cyber danger — see below |
How to prepare for NIS2 in Czechia
- Run NÚKIB's calculator first. It answers both questions that matter — whether you provide a regulated service, and which regime you are in — and it is the regulator's own tool.
- Check every service, not just the obvious one. Because one higher-regime service pulls the whole organisation up, a single overlooked service can change your entire programme.
- Notify within 60 days. If you met the criteria when the Act took effect and have not yet notified, that deadline has passed — deal with it now rather than waiting to be found.
- Record the date your registration decision was delivered. Every subsequent deadline is measured from it, so it belongs in your compliance calendar as a fixed reference point.
- Gap-assess against your decree — 409/2025 Sb. for the higher regime, 410/2025 Sb. for the lower. Not against the Directive, and not against the other regime's decree.
- Point your incident runbook at the right body. NÚKIB for the higher regime, the Národní CERT for the lower, on a 24-hour / 72-hour / 30-day chain.
- Use the year. Security measures and reporting bite one year after your registration decision. That is enough time to do the work properly and not enough to leave it.
- Brief the board on the real exposure — not only the 250,000,000 CZK headline, but the repeatable procedural fine that accrues when an organisation is slow to respond during an inspection.
Official links & resources
FAQ: NIS2 in Czechia
Has Czechia fully transposed NIS2?
Do entities need to register?
Which sectors are in scope?
Is ISO 27001 required?
What is the difference between the higher and lower obligations regime?
When do the obligations actually start?
What are the maximum fines?
Sources & verification
Every date and figure on this page was checked against a primary source on 10 August 2026. Where sources conflicted we followed the statutory text and NÚKIB.
- The Act — full text of Act No. 264/2025 Coll. All fine bands, the incident-reporting chain, the notification and change deadlines, and the roles of the Národní CERT and the data protection authority are taken from it directly.
- NÚKIB's own guide to the new Act — the source for the two-regime model, the “one organisation = one regime” rule, the fact that deadlines run from delivery of the registration decision, the one-year lead-in, and the decree numbers.
- vyhláška č. 409/2025 Sb. and 410/2025 Sb. — named and linked, not summarised.
