Guide · Cybersecurity Act / 264/2025
A plain-language guide to the new Czech Cybersecurity Act (No. 264/2025 Coll.) — who, what, when and how. No statutory prose, with links to the official text.
What is on this page
Act No. 264/2025 Coll., the Cybersecurity Act (locally shortened to “ZKB” or “the new ZKB”), is the Czech transposition of the European NIS2 Directive, Directive (EU) 2022/2555. If you already work with NIS2, you will recognise the structure of the obligations; the Czech Act adds national detail on top of it. It replaces and substantially widens the previous Act No. 181/2014 Coll.
The main difference against the old act is the far wider set of organisations it reaches. The 2014 act covered mostly public administration, critical infrastructure and a handful of digital services. The new Act covers 15 sectors (Section 4) and thousands of further organisations — from mid-sized manufacturers through IT providers to hospitals and transport operators.
The intent is straightforward: make the Czech economy and its critical services more resilient. After waves of ransomware, attacks on hospitals (Benešov, Brno) and supply chain compromises (SolarWinds, Kaseya, 3CX), the regulator responded by widening both its powers and the duties it imposes. The Act also puts personal responsibility on senior management — a failure to comply reaches the statutory body directly, not only the organisation as a whole.
The Act applies to regulated entities — organisations that provide a regulated service in one of the 15 sectors listed in Section 4 and that also meet the size criteria.
Higher obligations — typically large entities (250 employees or more, or turnover above EUR 50 million together with a balance sheet total above EUR 43 million; between turnover and balance sheet total the more favourable figure applies, so turnover alone is not enough) and key infrastructure regardless of size.
Lower obligations — medium-sized entities (50 to 249 employees, or turnover above EUR 10 million together with a balance sheet total above EUR 10 million) in selected sectors.
Some organisations are regulated regardless of size — typically electricity and gas distributors, hospitals providing acute inpatient care, and public authorities above a certain level.
To check whether the Act reaches you, use our calculator or the official NÚKIB calculator.
The Act sets up two levels of regulation. What exactly you have to do depends on the tier you fall into.
Important entities
Medium-sized entities in selected sectors, and smaller critical entities.
Fines up to CZK 175 million or 1.4 % of net worldwide annual turnover, whichever is higher.
Essential entities
Large entities in critical sectors and key infrastructure — energy, banks, hospitals, telecommunications.
Fines up to CZK 250 million or 2 % of net worldwide annual turnover, whichever is higher.
Whichever tier you are in, most obligations fall into these five areas. The detail is set out in Decree 409/2025 (higher tier) and Decree 410/2025 (lower tier).
If the Act reaches your organisation, you have to notify the service you provide to the Authority within 60 days (Section 6). NÚKIB then decides on registration by a formal decision — notification and registration are not the same thing. The filing is made electronically through the NÚKIB portal and has to come from the statutory body or a person it authorises.
What you will need:
Once the service is notified, NÚKIB decides on registration and the compliance schedule starts to run. You have one year from delivery of the registration decision to implement the security measures (Section 13); contact and supplementary details are filed within 30 days of registration (Section 11).
This is work we do regularly — preparing the paperwork, walking you through registration, building a minimum viable compliance position with you. If you want to talk it through, get in touch.
The Act has applied since 1 November 2025, with a single date of effect for the whole Act (Section 73). The individual deadlines are rolling, though — they run from the moment you meet the conditions, or from delivery of the registration decision.
The penalty regime is strict, and it reaches members of the statutory body personally. It cannot simply be pushed onto the company.
Up to CZK 250,000,000 or 2 % of net worldwide annual turnover — whichever is higher.
Up to CZK 175,000,000 or 1.4 % of net worldwide annual turnover — whichever is higher.
A concealed or late report falls under the same caps in Section 59 — it is not a separate penalty on top of them. In practice it is the obligation a regulator can check most easily.
NÚKIB can temporarily bar a member of the statutory body from holding office (Section 58) — this is a ban, not a duty on the company to remove the person.
A practical note: alongside fines, the Act gives the Authority a separate remedial measure (Section 56) — an order to fix identified shortcomings within a set deadline. Maximum fines are rarely used in NIS2 practice elsewhere in the EU, and decisions in the first Czech cases are not public yet. The risk is real all the same.
This guide is informative. Act No. 264/2025 Coll. transposes the European NIS2 Directive, so anyone who knows NIS2 will recognise the structure of the obligations. There is no official English wording of the Act or its decrees: only the Czech text in the Collection of Laws is binding, and everything on this page is our own orientation translation, not an official one. For the authoritative wording see the Czech text of the Act in the e-Sbírka; for the directive behind it, the English text of NIS2 on EUR-Lex. For a quick overview we have also put together a cheatsheet PDF and an interactive version of the Act:
Related
What exactly is missing and in what order to deal with it.
Otevřít →Does the Act apply to you? Thirty seconds and you know.
Otevřít →A 13-question self-check — how far you are from full compliance.
Otevřít →Sections of 264/2025 with notes, search and a floating table of contents.
Otevřít →The specific requirements of 409/2025 for essential entities.
Otevřít →Implementation requirements for important entities.
Otevřít →Help with the Act
If the Act reaches you and you do not know where to begin, or you are mid-implementation and need outside expertise — a gap analysis shows what exactly is missing and in what order to deal with it. From there it goes either into one-off remediation or into long-term security leadership.