Guide · Cybersecurity Act / 264/2025

GUIDE TO THE NEW ACT

A plain-language guide to the new Czech Cybersecurity Act (No. 264/2025 Coll.) — who, what, when and how. No statutory prose, with links to the official text.

What is on this page

  1. What the Act is and why it exists
  2. Who the Act applies to
  3. Two tiers: lower and higher obligations
  4. The obligations in practice
  5. How to notify a service and get registered
  6. Deadlines and what to report when
  7. Penalties for non-compliance
  8. Official sources and links

What the Act is and why it exists

Act No. 264/2025 Coll., the Cybersecurity Act (locally shortened to “ZKB” or “the new ZKB”), is the Czech transposition of the European NIS2 Directive, Directive (EU) 2022/2555. If you already work with NIS2, you will recognise the structure of the obligations; the Czech Act adds national detail on top of it. It replaces and substantially widens the previous Act No. 181/2014 Coll.

The main difference against the old act is the far wider set of organisations it reaches. The 2014 act covered mostly public administration, critical infrastructure and a handful of digital services. The new Act covers 15 sectors (Section 4) and thousands of further organisations — from mid-sized manufacturers through IT providers to hospitals and transport operators.

The intent is straightforward: make the Czech economy and its critical services more resilient. After waves of ransomware, attacks on hospitals (Benešov, Brno) and supply chain compromises (SolarWinds, Kaseya, 3CX), the regulator responded by widening both its powers and the duties it imposes. The Act also puts personal responsibility on senior management — a failure to comply reaches the statutory body directly, not only the organisation as a whole.

Who the Act applies to

The Act applies to regulated entities — organisations that provide a regulated service in one of the 15 sectors listed in Section 4 and that also meet the size criteria.

Sectors covered:

Size criteria under Commission Recommendation 2003/361/EC (simplified):

Higher obligations — typically large entities (250 employees or more, or turnover above EUR 50 million together with a balance sheet total above EUR 43 million; between turnover and balance sheet total the more favourable figure applies, so turnover alone is not enough) and key infrastructure regardless of size.

Lower obligations — medium-sized entities (50 to 249 employees, or turnover above EUR 10 million together with a balance sheet total above EUR 10 million) in selected sectors.

Some organisations are regulated regardless of size — typically electricity and gas distributors, hospitals providing acute inpatient care, and public authorities above a certain level.

To check whether the Act reaches you, use our calculator or the official NÚKIB calculator.

Two tiers: lower and higher obligations

The Act sets up two levels of regulation. What exactly you have to do depends on the tier you fall into.

Lower obligations

Important entities

Medium-sized entities in selected sectors, and smaller critical entities.

  • A designated person accountable for cybersecurity, with demonstrable expertise
  • Risk management and security controls derived from a risk analysis
  • Policies for the security of information systems
  • Regular staff training
  • Reporting of significant incidents through the NÚKIB portal (the recipient is the National CERT, Section 15)
  • Business continuity and backup arrangements
  • Cyber hygiene (MFA, encryption, segmentation)

Fines up to CZK 175 million or 1.4 % of net worldwide annual turnover, whichever is higher.

Higher obligations

Essential entities

Large entities in critical sectors and key infrastructure — energy, banks, hospitals, telecommunications.

  • Everything in the lower tier, plus the following:
  • A cybersecurity manager (MKB) as a separate formal role (the lower tier only needs a designated accountable person)
  • A cybersecurity architect
  • Regular security audits, internal as well as external
  • A specific incident response plan with escalation to the statutory body
  • Security requirements across the supply chain
  • Reporting to fixed deadlines (early warning within 24 h, notification within 72 h, final report within 30 days of the notification)

Fines up to CZK 250 million or 2 % of net worldwide annual turnover, whichever is higher.

The obligations in practice — what you actually have to do

Whichever tier you are in, most obligations fall into these five areas. The detail is set out in Decree 409/2025 (higher tier) and Decree 410/2025 (lower tier).

01

Governance and organisation

  • A named person accountable for security (MKB or equivalent)
  • Security policies approved by management
  • A change management process that is approved and auditable
  • Regular staff training — at least once a year, and in our view more often
02

Risk management

  • An up-to-date asset register with classification (confidentiality / integrity / availability)
  • A risk register following the NÚKIB methodology, reassessed regularly
  • Controls tied to specific risks, not a generic template
  • Supplier risk — assessment of ICT vendors and third parties
03

Detection and response

  • Monitoring of security events (logs, EDR, SIEM)
  • An incident response plan (IRP) with 24/7 contacts and an escalation matrix
  • Forensic readiness — evidence preservation and documented procedures
  • Incident reporting to NÚKIB within the statutory deadlines
04

Operations and hygiene

  • MFA on all administrative and remote access
  • Patch management with defined deadlines
  • Backups following the 3-2-1 rule, with restores tested regularly
  • Network segmentation and least privilege
05

Continuity and recovery

  • Business continuity (BCP) and disaster recovery (DRP) plans
  • Defined RTO/RPO for key systems
  • Regular recovery tests and tabletop exercises
  • Crisis communication, internal and external

How to notify a service and get registered

If the Act reaches your organisation, you have to notify the service you provide to the Authority within 60 days (Section 6). NÚKIB then decides on registration by a formal decision — notification and registration are not the same thing. The filing is made electronically through the NÚKIB portal and has to come from the statutory body or a person it authorises.

What you will need:

Once the service is notified, NÚKIB decides on registration and the compliance schedule starts to run. You have one year from delivery of the registration decision to implement the security measures (Section 13); contact and supplementary details are filed within 30 days of registration (Section 11).

This is work we do regularly — preparing the paperwork, walking you through registration, building a minimum viable compliance position with you. If you want to talk it through, get in touch.

Deadlines and what to report when

The Act has applied since 1 November 2025, with a single date of effect for the whole Act (Section 73). The individual deadlines are rolling, though — they run from the moment you meet the conditions, or from delivery of the registration decision.

Once you are in scope
Notify the service to the Authority
Within 60 days of the day you met the conditions (Section 6).
Within 24 hours
Early warning for a significant incident
First notification to NÚKIB with a basic description of the impact.
Within 72 hours
Incident notification
A structured notification with the current state, the response so far and the impacts.
Within 30 days of the notification
Final incident report
The post-mortem — what happened, how you responded, what measures you put in place.
Recurring
Updates to registers and policies
Asset register, risk register, policies — reviewed regularly, typically once a year.

Penalties for non-compliance

The penalty regime is strict, and it reaches members of the statutory body personally. It cannot simply be pushed onto the company.

Higher tier

Up to CZK 250,000,000 or 2 % of net worldwide annual turnover — whichever is higher.

Lower tier

Up to CZK 175,000,000 or 1.4 % of net worldwide annual turnover — whichever is higher.

Failure to report an incident

A concealed or late report falls under the same caps in Section 59 — it is not a separate penalty on top of them. In practice it is the obligation a regulator can check most easily.

Liability of the statutory body

NÚKIB can temporarily bar a member of the statutory body from holding office (Section 58) — this is a ban, not a duty on the company to remove the person.

A practical note: alongside fines, the Act gives the Authority a separate remedial measure (Section 56) — an order to fix identified shortcomings within a set deadline. Maximum fines are rarely used in NIS2 practice elsewhere in the EU, and decisions in the first Czech cases are not public yet. The risk is real all the same.

Official sources and links

This guide is informative. Act No. 264/2025 Coll. transposes the European NIS2 Directive, so anyone who knows NIS2 will recognise the structure of the obligations. There is no official English wording of the Act or its decrees: only the Czech text in the Collection of Laws is binding, and everything on this page is our own orientation translation, not an official one. For the authoritative wording see the Czech text of the Act in the e-Sbírka; for the directive behind it, the English text of NIS2 on EUR-Lex. For a quick overview we have also put together a cheatsheet PDF and an interactive version of the Act:

Related

MORE
TOOLS

Gap analysis

What exactly is missing and in what order to deal with it.

Otevřít →

Calculator

Does the Act apply to you? Thirty seconds and you know.

Otevřít →

Readiness check

A 13-question self-check — how far you are from full compliance.

Otevřít →

The Act interactive

Sections of 264/2025 with notes, search and a floating table of contents.

Otevřít →

Higher-tier decree

The specific requirements of 409/2025 for essential entities.

Otevřít →

Lower-tier decree

Implementation requirements for important entities.

Otevřít →

Help with the Act

Not sure
where to start?

If the Act reaches you and you do not know where to begin, or you are mid-implementation and need outside expertise — a gap analysis shows what exactly is missing and in what order to deal with it. From there it goes either into one-off remediation or into long-term security leadership.