FAQ · Frequently asked questions
Answers to common questions about the new Czech Cybersecurity Act (264/2025 Coll.). Filter the questions by category or search them by keyword.
No question matches your search.
Act No. 264/2025 Coll. reaches providers of regulated services in 15 sectors (Section 4) — public administration, energy, manufacturing, food, chemicals, water management, waste management, transport, digital infrastructure and services, financial markets, healthcare, science, research and education, postal and courier services, defence and space. The specific list of services, and the conditions under which they become regulated, is set out in Decree No. 408/2025 Coll. on regulated services.
Whether the Act reaches you depends on a combination of three factors: (1) the sector and type of service, (2) the size of the organisation (micro / small / medium / large under the EU SME definition), (3) in some cases a specific criterion — a licence from the Energy Regulatory Office, the Czech National Bank or the Czech Telecommunication Office, or the accreditation of a medical laboratory.
The quickest way to find out where you stand is our calculator. For a definitive answer use the official NÚKIB calculator.
The Act splits regulated entities into two categories according to how serious the impact of their service would be:
The key difference: entities in the higher tier have to go through a mandatory external audit and run a fully developed ISMS, entities in the lower tier do not. The incident reporting deadlines are the same in both tiers — early warning within 24 h of detection, notification within 72 h, final report within 30 days of the notification (Section 16). What differs is the recipient: the higher tier reports to the Authority, the lower tier to the National CERT, in both cases through the NÚKIB portal.
Size is calculated under Commission Recommendation 2003/361/EC from three figures:
The thresholds:
Between turnover and balance sheet total you take the more favourable (lower) category. Between headcount and the financial figures you take the higher one — with 300 employees you are a large company even on a turnover of EUR 5 million.
Watch out: in groups of companies, partner and linked enterprises count towards the totals, per the SME user guide. Our calculator does not account for that.
Short answer: now, if the Act reaches you.
The Act expects the entity itself to assess whether it is regulated and to notify the service to the Authority within 60 days of the day the conditions were met (Section 6). NÚKIB then decides on registration; only once that decision is delivered does the 30-day deadline for supplementary details start to run (Section 11). You have one year from delivery of the registration decision to implement the security measures (Section 13) — the clock runs from your own registration, not from a fixed date tied to the Act taking effect.
A realistic schedule for a mid-sized company in the lower tier:
For the higher tier, plan on 12–18 months and an external audit.
The new Act No. 264/2025 Coll. replaces the original cybersecurity act (181/2014 Coll.) and transposes the NIS2 Directive (Directive (EU) 2022/2555) into Czech law.
The main changes against the old act:
If you were regulated under the old act, your regime changes and typically widens. A fresh assessment is worth doing.
Our own materials: guide to the Act, the Act interactive, higher-tier decree, lower-tier decree, higher-tier cheatsheet, lower-tier cheatsheet.
In the lower tier (important entity) the expectation is a set of measures proportionate to the size and the risk profile of the organisation:
In detail: the lower-tier decree, interactive or the two-page cheatsheet PDF.
What gets reported is a cybersecurity incident with an impact on the regulated service — a breach of availability, integrity or confidentiality, or a financial or societal impact. A breach with no demonstrated impact (a security event) is not reported, but document it internally.
The deadlines are the same in both tiers:
“Detection” means the moment the accountable person, typically the MKB, has reasonable grounds for suspicion — not the moment the attack took place.
Practical advice: when in doubt, report. Under this Act a late report carries more risk than a report that turns out to have been unnecessary.
The lower tier does not require a formal “cybersecurity manager” (MKB) in the full sense the higher tier does, but you do have to designate a person accountable for cybersecurity. That person needs a mandate from management, sufficient authority, and a documented role.
For a mid-sized company there are three realistic options:
Whichever you pick, three things matter: a written mandate from management, access to company leadership at least on an ad hoc basis, and documentation of the key decisions.
The higher tier (essential entity) means the full set of obligations — typically 12–18 months of structured implementation. The main pillars:
In detail: the higher-tier decree, interactive or the two-page cheatsheet PDF.
ISO 27001 is a strong foundation for the higher tier, but it is not an automatic substitute. The Act imposes specific duties that ISO 27001 does not cover explicitly:
In practice: if your ISO 27001 scope covers the regulated service, you are roughly 70–80 % of the way there. Add a gap analysis against the Act and Decree 409/2025, close the missing points, notify the service to the Authority, and document it.
Maximum fines (the higher of the fixed amount and the percentage of turnover):
In setting the amount, NÚKIB weighs the nature, seriousness and duration of the breach, whether it is repeated, any financial gain from it, cooperation with the Authority and the security posture actually achieved. Maximum fines are rare in NIS2 practice elsewhere in the EU, and decisions in the first Czech cases are not public yet.
The main risk point: a late or missing incident report — it is the obligation that can be tested most easily, and in NIS2 practice it is the most common reason for a penalty.
Combined with GDPR (4 % of turnover), a single incident can produce two parallel fines: one from NÚKIB and one from the Czech data protection authority (ÚOOÚ).
Yes. The new Act explicitly establishes personal liability of members of statutory bodies for putting security measures in place and keeping them working. In cases of serious breach they can be sanctioned personally.
In practice the statutory body needs a demonstrable record that it:
A note on D&O insurance: standard directors and officers policies generally do not cover breaches of regulatory duties, nor intent or gross negligence. If you are relying on a policy, check the scope with the insurer in advance — a penalty for failing to report an incident or failing to implement measures can land on the individual.
The duty to notify a regulated service to the Authority within 60 days follows directly from the Act (Section 6), not from any letter from the regulator — so “nobody told us” is not an argument. NÚKIB then decides on registration by a formal decision; you cannot register yourself.
Practical advice: notify the service yourself and as soon as possible, even late. Mitigating circumstances — cooperation with the Authority, the security posture actually achieved — are weighed when a penalty is considered, and alongside a fine the Authority can order a remedial measure under Section 56, that is, fix the shortcomings within a set deadline.
If you are only now finding out that the Act reaches you, take it in this order:
An incident = a security breach with a demonstrated impact on the regulated service (availability, integrity, confidentiality, financial loss, physical or societal impact). Incidents have to be reported within 24 h / 72 h / 30 days through the NÚKIB portal — in the higher tier the recipient is the Authority, in the lower tier the National CERT (Section 15).
An event = a security breach with no demonstrated impact on the regulated service. Events are not reported, but document them internally.
The line is not always clear. Our recommendation: when in doubt, report. A false alarm will not count against you with NÚKIB; a late or missing report of a real incident can lead to a penalty.
Examples of incidents: ransomware encrypting even part of your data, theft of a customer database, an outage of the service longer than 4 hours, unauthorised access to an administrator account, a supply chain compromise that reaches your service.
Primarily through the NÚKIB portal, alternatively by e-mail or data box. NÚKIB runs a 24/7 hotline for the first notification.
What the sequence looks like during an incident:
Prepare in advance: a template with the static details pre-filled (company ID, contacts, sector), a contact matrix (who calls NÚKIB, who calls the lawyer, who handles external communication), playbooks for the typical scenarios.
An incident involving personal data typically triggers parallel duties under this Act and under GDPR. The deadlines differ slightly:
In practice, run one reporting process that covers both sides. Penalties can stack — one incident can mean a fine from NÚKIB and a fine from ÚOOÚ.
For a specific GDPR case we recommend a data protection specialist — the interaction of the Czech Act, GDPR and NIS2 is not always intuitive.
Recommended priorities for the first 90 days:
That is the narrow foundation that gets you to the point where you can handle most real attacks. The rest — policies, audit, supply chain monitoring — fills in over 12–18 months.
Formally the duty attaches to the regulated service and to every asset, process and supplier involved in providing it. In practice the boundary is porous — an attacker who compromises your “unrelated” systems usually reaches the regulated service as well.
We recommend one ISMS for the whole organisation, with the formal scope covering the regulated service. The reasons:
The exception: genuinely isolated areas, an R&D lab with no connection to production for example, can be excluded from scope as long as you document it.
It depends on size, budget and available capacity. A realistic decision matrix:
What matters when choosing an external service:
No. Even if the Act does not reach you directly, you still have to deal with cybersecurity, for three reasons:
We recommend putting in place at least a sensible minimum — see our page on the recommended security baseline or the NÚKIB support materials.
The Act applies to you from the moment you meet the criteria, typically when you cross a size threshold. You then have 60 days from the day the conditions are met to notify the service to the Authority (Section 6). NÚKIB then decides on registration.
How this plays out:
If you drop below the criteria and stop being regulated, tell NÚKIB and keep the measures you have implemented at least as a baseline. What you are saving is administration, not real security — the attacks do not change.
Have a specific question?
If your question is not in the FAQ, or you need your own situation assessed, book a no-obligation consultation. We will go through the scope of your obligations and what to deal with first.