ZKB · from knowing to complying

GAP ANALYSIS AND IMPLEMENTATION

The calculator told you the act applies. The readiness check showed where you stand. Here that turns into a concrete plan — what is missing and in what order.

Arrange a consultation →

Why do this in a structured way

KNOWING THE GAP
IS NOT CLOSING IT

Act No. 264/2025 Coll. and its implementing decrees do not describe what you should buy — they describe what you have to be able to evidence. The difference between “we have backups” and “we can show that we test them and when we last did” decides whether an inspection goes well.

A gap analysis is the map between what the decree requires and what you actually have. The output is not a list of shortcomings to reflect on, but a plan with an order, owners and an effort estimate — one you can defend to your board and to an auditor alike. A note for English readers: the act is the Czech transposition of the NIS2 Directive (Directive (EU) 2022/2555), so if you know NIS2 you will recognise the structure of the obligations; only the Czech wording published in the Collection of Laws is binding and this text is an unofficial working translation. NIS2 in English is on EUR-Lex (CELEX 32022L2555), the Czech text of the act in the e-Sbírka at e-sbirka.gov.cz/sb/2025/264.

How it works

FOUR
STEPS

01

Confirming the regime

First we confirm whether you fall under the lower or the higher obligations — and whether you fall under the act at all. The classification drives the scope of everything else, so it pays to be certain before you start spending.

02

Mapping the requirements

We go through the requirements of the applicable decree and match your actual state against them. For each point it is clear whether it is met fully, partly or not at all — and what you would produce as evidence.

03

Remediation plan

We rank the gaps by risk and effort. Each one gets an accountable role, an effort estimate and its dependencies. The plan works with the capacity you actually have, not with an ideal team.

04

Implementation

If you want, we stay with it. We lead the roll-out of the controls, write the policies, prepare the submissions for NÚKIB and see you through to a state you can evidence.

What you get

CONCRETE
DELIVERABLES

The scope differs by regime. The lower obligations usually take 2–3 weeks, the higher ones 4–6 weeks depending on the size of the organisation.

Who it is for

WHO IT
FITS

You know you are in scope, but not what comes next

The classification is confirmed and now you need the text of the decree translated into tasks that someone will actually do.

You have security, but cannot evidence it

The controls do work, but the records, policies and logs that would prove it to an inspection are missing.

You need to defend a budget

Management wants to know what is mandatory, what can wait and what it will cost. Without that, the investment does not get approved.

Builds on

Not sure how you are classified?

Before you start a gap analysis, go through our free tools. They take a few minutes and tell you whether it makes sense to continue.

How we deliver it

The gap analysis is the input, not the goal

We deliver the analysis itself as the regulatory variant of our Security Assessment service. If you then want someone to run compliance long term, Security Leadership follows on — including the cybersecurity manager role that the act requires of some entities.

Next step

Not sure about the result?

In a 30-minute consultation we will verify how your organisation is classified and suggest what to do next. No commitment and no sales pressure — if it turns out the act does not apply to you, we will tell you so.