Czech Republic NIS2 Transposition (Cybersecurity Act 2025)
New Czech Cybersecurity Act replacing the 2014 law, overseen by NÚKIB, with a higher and lower regime of obligations for regulated services.
| Jurisdiction | Czech Republic |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
The Czech NIS2 transposition is implemented through the new Czech Cybersecurity Act – Act No. 264/2025 Coll., on Cybersecurity, effective 1 November 2025, replacing Act No. 181/2014 Coll. (2014 Cybersecurity Act) and overseen by NÚKIB (National Cyber and Information Security Agency).Transposition overview NIS2 status Czechia NÚKIB info (EN) Portal NÚKIB – New Act
Below is a structured, compliance‑oriented analysis following your requested sections.
Key Requirements
1. Scope and regulated entities
- NIS2 is transposed via Act No. 264/2025 Coll., on Cybersecurity (Zákon o kybernetické bezpečnosti), which repeals and replaces Act No. 181/2014 Coll. and serves as the primary legal framework for network and information security in Czechia.
- Act No. 264/2025 Coll. – English text (PDF)
- NIS2 status – Czechia
- Transposition in the Czech Republic
- The Act implements NIS2 categories of “essential” and “important” entities via the concept of “providers of regulated services” (poskytovatel regulované služby), split into a higher‑obligations regime and a lower‑obligations regime.Directive description – Czechia Shard Cyber – CZ transposition summary
- The Act applies to entities providing services in 18 sectors and around 60 types of regulated services, aligned with NIS2 sectors such as energy, transport, banking, financial market infrastructures, health, digital infrastructure, public administration, and more.EBE – NIS2 overview CZ NIS2 Czechia – sector summary
2. Registration and self‑identification obligations
- Regulated entities must self‑identify and register via the NÚKIB portal once they meet the criteria for providing a regulated service.Portal NÚKIB – New Act NIS2 status – Czechia
- According to implementation guidance, entities must notify NÚKIB within 60 days of meeting the criteria for a regulated service; for entities in scope from 1 November 2025, the initial window closed on 31 December 2025.NIS2 Czechia – deadlines Kybit – NIS2 and Czech Act
- After registration, NÚKIB issues a registration decision, which triggers subsequent deadlines (contact details, implementation of measures, incident reporting).NIS2 Czechia – timelines Shard Cyber – registration & regimes
3. Security measures and risk management
- The Act imposes mandatory organizational and technical security measures for regulated entities, implemented through decrees (vyhlášky) that differentiate higher and lower regimes.Act No. 264/2025 Coll. – PDF Directive NIS2 – Czechia decrees summary
- The framework works via implementing decrees, notably:
- Decree No. 408/2025 Coll. – regulated services list
- Decree No. 409/2025 Coll. – security measures for higher‑obligations regime
- Decree No. 410/2025 Coll. – security measures for lower‑obligations regime
- Decree No. 334/2025 Coll. – NÚKIB portal These decrees define detailed security controls and process requirements.Directive NIS2 – Czechia Směrnice NIS2 – Czech wiki
- Security measures include standard NIS2‑aligned risk management practices, such as:
- Asset and risk analysis
- Incident management and business continuity
- Supply‑chain and vendor risk management
- Secure system development and vulnerability management This is derived from NIS2 requirements as implemented nationally.Act No. 264/2025 Coll. – general obligations NIS2 Directive official text
4. Incident reporting obligations
- The Act and its decrees set NIS2‑aligned incident notification timelines, typically:
- Early warning within 24 hours
- Detailed incident notification within 72 hours
- Final report within 30 days These follow NIS2 requirements adapted for Czech templates and the NÚKIB portal.Shard Cyber – incident notification summary NIS2 Directive – incident reporting
- Incidents must be reported to NÚKIB, and where personal data is affected, entities must also notify the Office for Personal Data Protection (ÚOOÚ) under GDPR obligations.EBE – NIS2 CZ obligations ÚOOÚ – personal data protection authority
5. Supervisory powers and sanctions
- NÚKIB is the lead supervisory authority for the Act, responsible for oversight, guidance, inspections, and enforcement.NÚKIB main page NIS2 status – Czechia
- The Act allows administrative fines up to 250,000,000 CZK or 2% of net worldwide turnover, depending on the seriousness of non‑compliance and entity category.NIS2 Czechia – fines summary EBE – NIS2 CZ
- Additional enforcement measures can include corrective orders, mandatory remedial actions, and potentially suspension of services in severe cases, consistent with NIS2 enforcement mechanisms.Act No. 264/2025 Coll. – enforcement provisions NIS2 Directive – enforcement
Compliance Challenges
1. Self‑identification and scoping complexity
- Organizations struggle with correctly determining whether they qualify as providers of a regulated service in the higher or lower regime, given sectoral criteria and size thresholds.NÚKIB info on NIS2 transposition Directive NIS2 – Czechia regimes
- Legal and consulting analyses note that entities in adjacent sectors or with mixed activities (e.g., IT service providers, cloud, managed services) face uncertainty over classification and scope.Two Birds – Czech Republic NIS2 implementation analysis Právní prostor – “NIS2 po česku”
2. Tight registration and implementation timelines
- The requirement to notify NÚKIB within 60 days of meeting criteria and the one‑year implementation window for security measures and incident reporting after registration decision can be challenging for organizations with limited resources.NIS Solutions – Czechia timelines Kybit – timeline explainer
- Commentary from law firms highlights that the transition period is short relative to the breadth of controls required, particularly for smaller “important” entities.Two Birds – NIS2 implementation CZ EBE – NIS2 overview CZ
3. Integration with existing frameworks (ISO 27001, GDPR, etc.)
- Organizations already certified to ISO/IEC 27001 or subject to GDPR face challenges in mapping existing controls to NIS2‑specific obligations, especially around supply chain and incident reporting.NIS2 Directive – risk management scope Anurag Verma – Czechia cybersecurity compliance overview
- Legal practice notes that duplicative or overlapping obligations (e.g., GDPR breach notification vs. NIS2 incident reporting) require coordinated processes to avoid inconsistent reports.ÚOOÚ – breach notification guidance NIS2 incident reporting – EU
4. Supply‑chain risk and vendor oversight
- The new Act imposes obligations to regularly check and audit suppliers, which can be complex for entities with large or global supply chains.EBE – NIS2 CZ supply chain requirements Directive NIS2 – supply chain risk
- Industry commentary points out that vendors may not be prepared for Czech‑specific requirements, leading to contractual challenges and re‑negotiations.Kybit – NIS2 practical notes NIS Solutions – vendor obligations summary
Implementation Best Practices
1. Structured compliance program and gap analysis
- Conduct a formal NIS2/Czech Cybersecurity Act gap analysis against the security measures in the relevant implementing decree (higher or lower regime) and your existing controls (e.g., ISO 27001).
- Act No. 264/2025 Coll. – obligations
- Directive NIS2 – Annex I and II sectors and obligations
- Use NÚKIB guidance and portal documentation as the authoritative reference for classification and obligations.Portal NÚKIB – information NÚKIB – NIS2 info page
2. Align with recognized frameworks
- Map requirements to ISO/IEC 27001 and related standards (e.g., ISO 27005, ISO 27035) to leverage existing information security management systems.
- ISO/IEC 27001 overview – ISO
- NIS2 Directive – alignment with existing standards
- For incident management, use NÚKIB templates (via the portal) and align with ENISA’s NIS2 guidance on incident reporting and security measures.
- ENISA – NIS2 cybersecurity risk management guidance
- NÚKIB portal documentation
3. Practical steps for registration and timelines
- Establish an internal trigger process to detect when your organization meets the regulated service criteria and ensure notification to NÚKIB within 60 days.
- NIS Solutions – Czechia deadlines
- Shard Cyber – registration workflow overview
- Once the registration decision is delivered, plan for:
- Submission of contact details within 30 days via the NÚKIB portal
- Implementation of security measures within one year
- Activation of incident reporting obligations after that one‑year period These timelines are summarized in implementation guides.Kybit – NIS2 timeline NIS Solutions – action list
4. Tools and resources
- Use the NÚKIB portal as the central operational tool for registration, reporting, and communication.
- Portal NÚKIB
- NÚKIB main site
- Leverage ENISA NIS2 implementation guides and sector‑specific good practices for detailed technical/organizational control design.
- ENISA – NIS2 implementation
- NIS2 official directive text
Recent Updates
1. Entry into force and transition dates
- The new Czech Cybersecurity Act (No. 264/2025 Coll.) entered into force on 1 November 2025, replacing the 2014 Act.NIS2 status – Czechia Transposition overview
- The Act was adopted on 11 June 2025 and published in the Collection of Laws on 4 August 2025.NIS2 status – Czechia Directive NIS2 – Czechia summary
2. Implementing decrees and portal launch
- Multiple implementing decrees (408/2025, 409/2025, 410/2025, 334/2025) became effective on the same date (1 November 2025), operationalizing the Act’s obligations, regulated service list, and portal.Directive NIS2 – Czechia Czech NIS2 Wikipedia entry
- Portal NÚKIB for registration and notifications is live and provides English‑language information
Recent developments
- — Deloitte’s update explains that the Czech Republic missed the original NIS2 transposition deadline and finalized the Cybersecurity Act only in 2025. It frames the current issue as implementation and operational compliance rather than legislative drafting. (source)
- — Industry guidance notes that the Act has been in force since 2025-11-01 and that the NÚKIB registration wave is over. It emphasizes the practical impact on regulated organizations across 18 sectors, including energy, healthcare, transport, manufacturing, waste, and IT. (source)
- — NÚKIB’s English-language page provides official context on the Czech NIS2 transposition process. It refers to the proposal of the new Cybersecurity Act and the national implementation of NIS2 requirements. (source)
- — The Czech Republic’s NIS2 transposition is described as complete, with the new Cybersecurity Act in force since 2025-11-01. The update says attention has shifted to self-identification of regulated entities, implementation of obligations, supply-chain security, and NÚKIB supervision. (source)
- — A status update says Czechia’s Act No. 264/2025 Coll. is transposed and in force, replacing the previous cybersecurity law. It highlights the new two-tier regime for regulated services and the expanded compliance scope across sectors. (source)
- — The European Commission’s NIS2 transposition page provides EU-level context for national implementation tracking. While not Czech-specific in the excerpt, it is useful as an official reference point for monitoring transposition status and related policy developments. (source)
- — This industry page says the new Cybersecurity Act expanded the number of regulated entities and their obligations under Czech NIS2 implementation. It also notes spillover effects on subsidiaries and suppliers of regulated entities. (source)
- — A timeline/status update says Czech law carries NIS2 obligations into the national framework, with supervision by NÚKIB and penalties of up to CZK 250 million. The page also highlights incident-reporting duties and the higher/lower significance service split. (source)
- — NÚKIB says the new Act on Cybersecurity took effect on 2025-11-01 and transposes the NIS2 Directive into Czech law. The portal information is relevant for entities handling registration and compliance under the new regime. (source)
- — This update reports that NÚKIB issued more than 4,800 administrative decisions designating providers of regulated services, with the expected total above 6,000. It underscores the scale of the rollout and the compliance burden on affected entities. (source)
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
- Belgium NIS2 Transposition — Belgium, Active, effective 2024-10-18
Put it into practice
- Generate the policy: NIS2 policy generator (generatepolicy.com)
- Buy the policy pack: NIS2 Compliance Policy (cyberpolicy.shop)
- Build it yourself: DORA + NIS2 EU Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates