Self-check · ZKB / Decree 410/2025

Readiness Check Lower obligations

Is your company one of the newly regulated entities under the Czech Cybersecurity Act? A few minutes of questions will tell you what to deal with first.

This self-check is built on the key obligations of Act No. 264/2025 Coll. (the Czech Cybersecurity Act, ZKB) and Decree No. 410/2025 Coll., which applies to providers of a regulated service in the lower-obligations regime. The act transposes the NIS2 Directive (EU) 2022/2555, so if you know NIS2 you will recognise how the duties are structured. Only the Czech wording in the Collection of Laws is legally binding — the authentic text is published in the e-Sbírka and everything here is an orientation translation, not an official one. If you fall into the higher-obligations regime, use the version for higher obligations. For each question you pick Yes / Partly / No and at the end you will see:

A self-check is not an audit — it is an indicator. A full assessment is done by an auditor with access to your documentation. If a professional assessment is of interest, get in touch once you have finished the questionnaire.

01Governance

Have you appointed a cybersecurity manager, or an equivalent role, with a formal mandate from senior management?

The act requires a named person accountable for cybersecurity at management level.

02Risk management

Do you keep an up-to-date register of cyber risks with classification (likelihood × impact) and controls linked to each risk?

In the lower regime, putting in place measures proportionate to threats and vulnerabilities is the core of Section 3 of Decree 410/2025 — there is no standalone section on risk management. In the higher regime, risk management is covered by Section 8 of Decree 409/2025.

03Assets

Do you maintain an asset inventory (systems, data, processes, suppliers) with named owners and a confidentiality / integrity / availability classification?

Without an asset inventory there is no meaningful way to manage risk or respond to incidents.

04Incident response

Do you have a documented and tested incident response plan, including escalation contacts and report templates for the NÚKIB portal?

Decree 410/2025, Section 10 (handling cybersecurity incidents) — you must have incident handling procedures and contacts in place.

05Incident response

Do you know exactly who to report a cybersecurity incident to and within what deadlines — the National CERT in the lower regime, the authority in the higher one, always through the NÚKIB portal (initial report within 24 h of detection, notification within 72 h, final report within 30 days of the notification)?

Fines for failing to report run into millions of crowns. The process has to be ready before an incident, not after it.

06Operations

Do you run a formal change management process (change request, approval, roll-back plan) for changes in the IT environment?

Change management is governed by Section 11 of Decree 409/2025 (higher regime). The lower regime has no standalone section on change management — the requirement follows from Section 3 of Decree 410/2025 and from the contractual terms agreed with suppliers under Annex No. 2.

07Operations

Do you enforce MFA on all administrative and remote access (VPN, RDP, cloud consoles, e-mail, administrator accounts)?

80 % of attacks start with a compromised password. MFA is among the most effective single controls available.

08Operations

Do you have a defined patch management process with deadlines for critical and high vulnerabilities (typically 72 h / 14 days)?

Most exploited vulnerabilities have had a patch available for 6+ months.

09Operations

Do your backups follow the 3-2-1 rule (3 copies, 2 media types, 1 offline / immutable) and do you test restores regularly?

Ransomware encrypts online backups at the same time as production. An offline or immutable copy is not optional.

10Suppliers

Do you keep a register of third-party suppliers with an assessment of their security level (DPA, contractual duties including incident reporting, restricted access, evidenced controls)?

Suppliers are covered by Section 9 of Decree 409/2025 (higher regime); in the lower regime by Section 3 of Decree 410/2025 and by contractual terms under Annex No. 2.

11People

Do your staff go through regular cybersecurity training (at least once a year) and phishing simulations?

90 % of ransomware campaigns start with phishing. Section 5 of Decree 410/2025 requires induction and recurring training but sets no specific frequency; to actually change behaviour we recommend a short 5–10 minute refresher every month and simulations 2–4 times a year.

12Detection

Do you collect security logs centrally (AD, EDR, firewall, e-mail gateway) with a retention of at least 90 days?

Without logs, forensic analysis after an attack is a dead end.

13Governance

Do you have approved and formally published security policies (information security, access management, acceptable use, incident response) that staff have demonstrably been briefed on?

The auditor will ask who approved the current version and which employees were briefed on it.

Evaluate the questionnaire

Your score appears straight away. For the full PDF report with recommendations, enter your e-mail below.