ZKB · from knowing to complying
The calculator told you the act applies. The readiness check showed where you stand. Here that turns into a concrete plan — what is missing and in what order.
Arrange a consultation →Why do this in a structured way
Act No. 264/2025 Coll. and its implementing decrees do not describe what you should buy — they describe what you have to be able to evidence. The difference between “we have backups” and “we can show that we test them and when we last did” decides whether an inspection goes well.
A gap analysis is the map between what the decree requires and what you actually have. The output is not a list of shortcomings to reflect on, but a plan with an order, owners and an effort estimate — one you can defend to your board and to an auditor alike. A note for English readers: the act is the Czech transposition of the NIS2 Directive (Directive (EU) 2022/2555), so if you know NIS2 you will recognise the structure of the obligations; only the Czech wording published in the Collection of Laws is binding and this text is an unofficial working translation. NIS2 in English is on EUR-Lex (CELEX 32022L2555), the Czech text of the act in the e-Sbírka at e-sbirka.gov.cz/sb/2025/264.
How it works
First we confirm whether you fall under the lower or the higher obligations — and whether you fall under the act at all. The classification drives the scope of everything else, so it pays to be certain before you start spending.
We go through the requirements of the applicable decree and match your actual state against them. For each point it is clear whether it is met fully, partly or not at all — and what you would produce as evidence.
We rank the gaps by risk and effort. Each one gets an accountable role, an effort estimate and its dependencies. The plan works with the capacity you actually have, not with an ideal team.
If you want, we stay with it. We lead the roll-out of the controls, write the policies, prepare the submissions for NÚKIB and see you through to a state you can evidence.
What you get
The scope differs by regime. The lower obligations usually take 2–3 weeks, the higher ones 4–6 weeks depending on the size of the organisation.
Who it is for
The classification is confirmed and now you need the text of the decree translated into tasks that someone will actually do.
The controls do work, but the records, policies and logs that would prove it to an inspection are missing.
Management wants to know what is mandatory, what can wait and what it will cost. Without that, the investment does not get approved.
Builds on
Before you start a gap analysis, go through our free tools. They take a few minutes and tell you whether it makes sense to continue.
How we deliver it
We deliver the analysis itself as the regulatory variant of our Security Assessment service. If you then want someone to run compliance long term, Security Leadership follows on — including the cybersecurity manager role that the act requires of some entities.
Next step
In a 30-minute consultation we will verify how your organisation is classified and suggest what to do next. No commitment and no sales pressure — if it turns out the act does not apply to you, we will tell you so.