Czech Republic NIS2 Transposition (Cybersecurity Act 2025)

New Czech Cybersecurity Act replacing the 2014 law, overseen by NÚKIB, with a higher and lower regime of obligations for regulated services.

JurisdictionCzech Republic
CategoryCybersecurity
StatusActive
Effective date
Latest development

Analysis

The Czech NIS2 transposition is implemented through the new Czech Cybersecurity Act – Act No. 264/2025 Coll., on Cybersecurity, effective 1 November 2025, replacing Act No. 181/2014 Coll. (2014 Cybersecurity Act) and overseen by NÚKIB (National Cyber and Information Security Agency).Transposition overview NIS2 status Czechia NÚKIB info (EN) Portal NÚKIB – New Act

Below is a structured, compliance‑oriented analysis following your requested sections.


Key Requirements

1. Scope and regulated entities

  • The Act applies to entities providing services in 18 sectors and around 60 types of regulated services, aligned with NIS2 sectors such as energy, transport, banking, financial market infrastructures, health, digital infrastructure, public administration, and more.EBE – NIS2 overview CZ NIS2 Czechia – sector summary

2. Registration and self‑identification obligations

  • According to implementation guidance, entities must notify NÚKIB within 60 days of meeting the criteria for a regulated service; for entities in scope from 1 November 2025, the initial window closed on 31 December 2025.NIS2 Czechia – deadlines Kybit – NIS2 and Czech Act

3. Security measures and risk management

  • The framework works via implementing decrees, notably:
  • Decree No. 408/2025 Coll. – regulated services list
  • Decree No. 409/2025 Coll. – security measures for higher‑obligations regime
  • Decree No. 410/2025 Coll. – security measures for lower‑obligations regime
  • Decree No. 334/2025 Coll. – NÚKIB portal These decrees define detailed security controls and process requirements.Directive NIS2 – Czechia Směrnice NIS2 – Czech wiki
  • Security measures include standard NIS2‑aligned risk management practices, such as:
  • Asset and risk analysis
  • Incident management and business continuity
  • Supply‑chain and vendor risk management
  • Secure system development and vulnerability management This is derived from NIS2 requirements as implemented nationally.Act No. 264/2025 Coll. – general obligations NIS2 Directive official text

4. Incident reporting obligations

5. Supervisory powers and sanctions


Compliance Challenges

1. Self‑identification and scoping complexity

2. Tight registration and implementation timelines

3. Integration with existing frameworks (ISO 27001, GDPR, etc.)

4. Supply‑chain risk and vendor oversight


Implementation Best Practices

1. Structured compliance program and gap analysis

2. Align with recognized frameworks

3. Practical steps for registration and timelines

  • Once the registration decision is delivered, plan for:
  • Submission of contact details within 30 days via the NÚKIB portal
  • Implementation of security measures within one year
  • Activation of incident reporting obligations after that one‑year period These timelines are summarized in implementation guides.Kybit – NIS2 timeline NIS Solutions – action list

4. Tools and resources


Recent Updates

1. Entry into force and transition dates

2. Implementing decrees and portal launch

  • Portal NÚKIB for registration and notifications is live and provides English‑language information

Recent developments

  • — Deloitte’s update explains that the Czech Republic missed the original NIS2 transposition deadline and finalized the Cybersecurity Act only in 2025. It frames the current issue as implementation and operational compliance rather than legislative drafting. (source)
  • — Industry guidance notes that the Act has been in force since 2025-11-01 and that the NÚKIB registration wave is over. It emphasizes the practical impact on regulated organizations across 18 sectors, including energy, healthcare, transport, manufacturing, waste, and IT. (source)
  • — NÚKIB’s English-language page provides official context on the Czech NIS2 transposition process. It refers to the proposal of the new Cybersecurity Act and the national implementation of NIS2 requirements. (source)
  • — The Czech Republic’s NIS2 transposition is described as complete, with the new Cybersecurity Act in force since 2025-11-01. The update says attention has shifted to self-identification of regulated entities, implementation of obligations, supply-chain security, and NÚKIB supervision. (source)
  • — A status update says Czechia’s Act No. 264/2025 Coll. is transposed and in force, replacing the previous cybersecurity law. It highlights the new two-tier regime for regulated services and the expanded compliance scope across sectors. (source)
  • — The European Commission’s NIS2 transposition page provides EU-level context for national implementation tracking. While not Czech-specific in the excerpt, it is useful as an official reference point for monitoring transposition status and related policy developments. (source)
  • — This industry page says the new Cybersecurity Act expanded the number of regulated entities and their obligations under Czech NIS2 implementation. It also notes spillover effects on subsidiaries and suppliers of regulated entities. (source)
  • — A timeline/status update says Czech law carries NIS2 obligations into the national framework, with supervision by NÚKIB and penalties of up to CZK 250 million. The page also highlights incident-reporting duties and the higher/lower significance service split. (source)
  • — NÚKIB says the new Act on Cybersecurity took effect on 2025-11-01 and transposes the NIS2 Directive into Czech law. The portal information is relevant for entities handling registration and compliance under the new regime. (source)
  • — This update reports that NÚKIB issued more than 4,800 administrative decisions designating providers of regulated services, with the expected total above 6,000. It underscores the scale of the rollout and the compliance burden on affected entities. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates