Self-check · ZKB / Decree 409/2025
Does your company fall into the higher-obligations regime of the Czech Cybersecurity Act? A few minutes will show which requirements you are still missing.
This self-check is built on the obligations of Act No. 264/2025 Coll. (the Czech Cybersecurity Act, ZKB) and Decree No. 409/2025 Coll., which applies to providers of a regulated service in the higher-obligations regime. The act transposes the NIS2 Directive (EU) 2022/2555, so if you know NIS2 you will recognise how the duties are structured. Only the Czech wording in the Collection of Laws is legally binding — the authentic text is published in the e-Sbírka and everything here is an orientation translation, not an official one. If you fall into the lower-obligations regime, use the version for lower obligations. For each question you pick Yes / Partly / No and at the end you will see:
A self-check is not a cybersecurity audit under Section 16 of the decree — it is an indicator. A real audit is carried out by an independent person meeting the conditions of Section 5(4) of the decree. If a professional assessment is of interest, get in touch once you have finished the questionnaire.