Outside the regulation · recommended minimum

OUTSIDE THE REGULATION

The act does not apply to you directly — but that does not mean you can ignore cybersecurity. Recommended minimum: where to start and which frameworks to use.

The calculator showed that, on the criteria you entered, Act No. 264/2025 Coll. does not apply directly to your organisation. You do not have to register with NÚKIB or meet the specific requirements of decrees 409/2025 (higher regime) and 410/2025 (lower regime).

That does not mean you can leave cybersecurity alone. Attacks hit small companies just as much as large ones, contractual requirements from regulated clients will push security standards onto you, and other regulation (GDPR, sector-specific rules) may still apply. A note for English readers: Act No. 264/2025 Coll. is the Czech transposition of the NIS2 Directive, so anyone familiar with Directive (EU) 2022/2555 will recognise the structure of the obligations. Only the Czech wording published in the Collection of Laws is binding; this page is an unofficial working translation — see the Czech text of the act in the e-Sbírka.

Why deal with it anyway

1. Attacks do not care about your revenue

Ransomware, BEC fraud and data theft hit small companies as hard as large ones. The median ransomware demand in 2024 was around EUR 150,000, downtime ran to 21 days, and 60 % of the small companies affected go under within 6 months. For a small company the cost of an incident is typically terminal.

2. Contractual pressure from clients

Your regulated clients (banks, hospitals, distributors) will now start vetting their suppliers. Security questionnaires (SIG, CAIQ), DPA requirements, incident reporting, the right to audit — all of that can reach you through the contract even where the law does not. Preparing in advance means not losing the business.

3. Other regulation still applies

GDPR (processing of personal data), eIDAS (electronic signatures), the Electronic Communications Act, the Payments Act, sector-specific regulation (healthcare, finance) — all of those keep pushing you towards security controls. Add insurance terms and contractual relationships on top.

Minimum security baseline (10 controls)

Our pragmatic list — the 10 most important controls for a small company that wants to be secure on a sensible budget and timeline. It covers roughly 80 % of typical attacks for about 20 % of the cost of full compliance with the act.

01

MFA on every administrative and remote access

Multi-factor authentication on: the cloud console (Microsoft 365, AWS, Azure, GCP), VPN, RDP, e-mail and the SaaS that matters (CRM, finance, code repositories). For IT admin accounts use a FIDO2 / hardware key (YubiKey) rather than SMS — SIM swap and AiTM attacks are real. Cost: EUR 0–50 per user, one-off.

02

EDR / antivirus on every endpoint

Endpoint Detection & Response — not just classic antivirus. Options: Microsoft Defender for Endpoint P2 (P1 only has antivirus and attack surface reduction; full EDR and threat hunting start at P2 — part of M365 E5 or a standalone licence), ESET Protect Advanced (support in Czech), SentinelOne. The key part: alerts to an on-call e-mail or SMS, not just a daily look at the console.

03

Backups 3-2-1 with an offline / immutable copy

3 copies of the data, 2 media, 1 offline or immutable. Ransomware encrypts online backups together with production. For M365 specifically, use third-party backup (Veeam M365, AvePoint) — the Microsoft retention policy is not a backup. Test restores monthly on a sample of data and run a full dry-run restore at least once a year.

04

Patch management prioritised by KEV / EPSS

Regular updates with defined deadlines: actively exploited (CISA KEV) 24–48 h, critical (CVSS ≥ 9.0) 72 h, high 14 days, medium 30 days. Automate through Windows Update / WSUS and unattended-upgrades on Linux. The key part: do not skip firmware and IoT devices.

05

E-mail security — DMARC, anti-phishing

SPF + DKIM + DMARC, moving step by step to p=reject (a 3–6 month process: monitor → quarantine → reject). Anti-phishing with impersonation protection (Defender for O365 P1 or an equivalent). BEC fraud is the number one financial threat for small companies — DMARC at reject is the single most effective defence.

06

Encryption of devices and sensitive data

BitLocker on Windows, FileVault on macOS, LUKS on Linux — on every laptop. Encryption of e-mails carrying personal data (Microsoft Information Protection). TLS 1.2+ for your own website and API. Endpoints have to be encrypted from the moment they are first switched on.

07

Awareness training + phishing simulations

Security awareness training for every employee once a year (KnowBe4, Cofense, or the NÚKIB training portal — free of charge). Phishing simulations 2–4 times a year with escalation: one-to-one training after a third click. Target: a click rate below 5 % after 12 months of the programme.

08

Incident response plan (at least the basics)

A short document (3–5 pages) — contact matrix, 3–4 key scenarios (ransomware, BEC, data breach, outage at a critical supplier), steps 1-2-3 for each of them. Reporting templates: for the Czech data protection authority (GDPR), for the insurer, for clients. A tabletop exercise once a year (3 hours).

09

Least privilege

Administrative rights only for the accounts that genuinely need them. Separate admin accounts (user@ for ordinary work, user-admin@ for IT operations). An annual review of active accounts and permissions. Off-boarding: privileged accounts removed or blocked within an hour, standard ones within 24 h.

10

Inventory of devices and software + regular review

Without an asset register (who has which laptop, what software runs where) nothing can be managed. Automate discovery with Microsoft Intune (included with M365 Business Premium), Lansweeper or Snipe-IT. Annual review: decommissioned devices, software that is no longer updated, unapproved SaaS applications.

Professional frameworks — what to read next

If you want to go beyond the minimum, these are the frameworks we recommend. Structured, proven, practical. For a small company it is enough to start at the lowest tier of each of them.

NÚKIB · CZ · free

NÚKIB supporting materials

Methodologies and guidance from the agency on security measures — supplier management, penetration testing, a glossary of terms, requirements for security levels. Free to download, in Czech.

Open the overview ↗
CIS · EN · free after registration

CIS Controls v8.1 — Implementation Group 1 (IG1)

An international standard from the Center for Internet Security. IG1 is the “basic cyber hygiene” baseline for small companies with no dedicated security team — 56 specific safeguards. If you can manage IG1, you are in the top 30 % of small companies by security readiness.

Open CIS Controls ↗
NIST · EN · free

NIST Cybersecurity Framework 2.0

An American framework, but accepted globally. Six functions: Govern, Identify, Protect, Detect, Respond, Recover. A good fit for companies that expect to grow into regulated territory and want a structure they can later map onto the Czech act or ISO 27001.

Open NIST CSF ↗
NÚKIB · CZ · free

NÚKIB training portal — free courses

Online courses for employees and for IT specialists, run by the Czech agency. Good quality, localised, with Czech context. Works as the basis of an awareness programme or for self-study by the IT team.

Open the training portal ↗
ISO · paid

ISO/IEC 27001:2022

The international standard for an information security management system. If you are heading for certification (because of clients, B2B contracts or an IPO), expect 12–18 months of work and roughly CZK 500,000–1,500,000 for the audit. If you know you will end up regulated, build the system to ISO from the start.

About the standard ↗

What if the act starts to apply to us?

If you grow (more employees, higher turnover) or change what your business does, you can move from “outside the regulation” into the lower or the higher regime of obligations.

Practical advice:

When that happens, go back to the calculator and find out which regime you fall into. The investment in the minimum baseline on this page is not lost — the vast majority of the controls hold across regulations.

Need a hand?

We will build
your security baseline.

You do not have to be regulated to need a security programme. We can help you put the minimum baseline in place (typically 3–6 months) or build a structure you can extend later as the company grows.