Self-check · ZKB / Decree 409/2025

Readiness Check Higher obligations

Does your company fall into the higher-obligations regime of the Czech Cybersecurity Act? A few minutes will show which requirements you are still missing.

This self-check is built on the obligations of Act No. 264/2025 Coll. (the Czech Cybersecurity Act, ZKB) and Decree No. 409/2025 Coll., which applies to providers of a regulated service in the higher-obligations regime. The act transposes the NIS2 Directive (EU) 2022/2555, so if you know NIS2 you will recognise how the duties are structured. Only the Czech wording in the Collection of Laws is legally binding — the authentic text is published in the e-Sbírka and everything here is an orientation translation, not an official one. If you fall into the lower-obligations regime, use the version for lower obligations. For each question you pick Yes / Partly / No and at the end you will see:

A self-check is not a cybersecurity audit under Section 16 of the decree — it is an indicator. A real audit is carried out by an independent person meeting the conditions of Section 5(4) of the decree. If a professional assessment is of interest, get in touch once you have finished the questionnaire.

01Governance

Has senior management appointed people to the security roles of cybersecurity manager, cybersecurity architect, asset guarantor and cybersecurity auditor, and is the manager kept separate from roles responsible for operating technical assets?

The roles are set out in Section 4(4) and detailed in Section 5 of Decree 409/2025. The manager, the architect and the auditor must be trained for the role and evidence at least 3 years of practice; the auditor may not be entrusted with any other security role. Senior management ensures cover for the manager and the architect.

02Governance

Has senior management set up a cybersecurity management committee that includes at least one member of senior management, or a person they designate, and the cybersecurity manager?

Section 4(3) of Decree 409/2025 requires the committee to meet at least once a year and to minute its proceedings. It should be made up of people with the authority and expertise to run and develop the information security management system.

03Governance

Do you have an information security management system with defined objectives and a security policy, and do you evaluate its effectiveness at least once a year in a review report?

Sections 3 and 6 of Decree 409/2025. The effectiveness review covers, among other things, progress on the risk treatment plan, audit results, the impact of incidents and significant changes. Senior management must demonstrably be made familiar with the review report under Section 4(2).

04Audit

Do you have a cybersecurity audit plan, and has an audit been carried out in the last two years by someone who independently assesses whether the measures in place are correct and effective?

Section 16 of Decree 409/2025: the audit is performed according to the plan, on significant changes and at regular intervals of at least once every 2 years. Where a full-scope audit is not feasible for justified reasons, it may proceed in systematic blocks so that the entire scope is covered at least once every 5 years.

05Risk management

Do you have a methodology for identifying and assessing risks, including criteria for risk acceptability, and do you run a risk assessment at least once a year and on significant changes?

Section 8 of Decree 409/2025. The outputs are a risk assessment report and a risk treatment plan naming responsible people, resources and deadlines. Results of audits, penetration tests, vulnerability scans and past incidents feed into the assessment.

06Risk management

Do you have a statement of applicability that describes how each implemented measure is met and, for measures not implemented, gives the justification and any compensating controls?

Section 8(1)(f) of Decree 409/2025. The statement of applicability covers every security measure the decree requires and is the fastest way to demonstrate during an inspection what is in place, what is not, and why.

07Assets

Do you have a methodology for identifying and valuing assets, recorded asset guarantors, and do you assess primary assets for confidentiality, integrity and availability including their links to supporting assets?

Section 7 of Decree 409/2025. This also covers protection rules by asset level — permitted ways of using and handling assets, classification and labelling, management of removable media and the method of disposing of information, data and storage media.

08Suppliers

Do you keep a record of your significant suppliers, have you demonstrably informed them in writing that they are on it, and do you regularly review contract performance from a security perspective?

Section 9 of Decree 409/2025. Contracts with significant suppliers should contain the provisions listed in Annex No. 5 to the decree, and the risks associated with performance are assessed before the contract is signed.

09People

Do you have a security awareness development plan, and does it drive induction and recurring training for users, administrators, people in security roles and senior management?

Section 10 of Decree 409/2025. Records of briefings and training are kept, covering the subject of the training and the list of people who completed it. The decree sets no specific frequency — training is to be given on induction and regularly thereafter.

10Operations

Do you have rules and criteria for identifying significant changes, and for those changes documented change control, testing before go-live and the ability to revert to the previous state?

Section 11 of Decree 409/2025. For a significant change, the associated risks are managed, security and operational documentation is updated, and the outcome of risk management decides whether penetration testing is needed.

11Operations

Do you verify the identity of users, administrators and technical assets with multi-factor authentication using at least two different types of factor?

Section 19(2) of Decree 409/2025 also allows currently resistant continuous authentication based on a zero-trust model. Until the requirement is met, you keep a record of the technical assets, accounts and authentication mechanisms that do not meet it, together with the reasons.

12Operations

Do you separate a person's user account from their administrator account, manage access through groups or roles, and withdraw permissions without delay when someone changes position or leaves?

Sections 13 and 20 of Decree 409/2025. A regular review of all access rights and permissions is required, as is a centralised tool for managing them that takes account of the links between assets.

13Operations

Do you have documented network segmentation separating production, backup, development, test and administrative environments, and do you control remote access and remote administration?

Section 18 of Decree 409/2025; separation of environments is also required by Section 12(1)(e). Only the communication necessary to properly deliver the regulated service is permitted, and the network and infrastructure topology has to be documented.

14Detection

Do you use a centrally managed tool that gives technical assets continuous protection against malicious code and detects events based on the behaviour of assets, administrators and users?

Section 21 of Decree 409/2025. Besides protecting technical assets, the decree requires verification and inspection of data transferred within the network and at its perimeter, and regular updates of the tool including its detection rules.

15Detection

Do you collect event logs with a centralised tool, protect them against unauthorised reading and modification, retain them for at least 18 months and evaluate them continuously?

Sections 22 and 23 of Decree 409/2025. Beyond the retention of at least 18 months, continuous time synchronisation across technical assets is required, as is timely alerting of designated security roles when an event is detected.

16Incident response

Do you have processes for handling cybersecurity incidents with assigned responsibilities, rules for preserving trustworthy evidence for analysis and a prepared reporting procedure?

Section 14 of Decree 409/2025; the recipient and the reporting deadlines are set by Sections 15 and 16 of Act No. 264/2025 Coll. For an incident with a significant impact, a final report is prepared including a description of the cause where it is known.

17Continuity

Have you run a business impact analysis with a defined recovery time objective and recovery point objective, do you test continuity and recovery plans regularly, and are backups encrypted with documented restore tests?

Sections 15 and 26 of Decree 409/2025. The backup environment must be separated from the other environments, and backups are tested for integrity, availability and restorability — with the test results documented.

18Testing

Do you scan for vulnerabilities at least once a year from both the internal and the external network, and run penetration testing at least once every two years, including retesting of the findings?

Section 24 of Decree 409/2025. Penetration testing is also performed before an asset goes live and in connection with a significant change; the results of both scans and tests feed into risk management.

Evaluate the questionnaire

Your score appears straight away. For the full PDF report with recommendations, enter your e-mail below.