Summary · cheatsheet · lower-tier obligations
Important entities · Act No. 264/2025 Coll. + Decree 410/2025 · print to PDF
Lower-tier obligations
This overview sums up the key duties of entities that fall into the lower-tier regime. It is a quick reference for company management and IT — not a legal interpretation.
Entities in the sectors set out in Section 4 of the Act (the specific list of services is defined by Decree No. 408/2025 Coll.) that meet the criteria for a medium-sized organisation (50 to 249 employees, or turnover above EUR 10 million together with a balance sheet total above EUR 10 million) and do not meet the criteria for the higher-tier regime. In some sectors (manufacturing or managed ICT services, for instance) most medium-sized companies land here.
Designate a person responsible for cybersecurity (a cybersecurity manager or equivalent). Have the basic policies approved (information security, access control, incident response plan, backup). Review the policies at least once a year.
An asset inventory (at least the main systems and data) with owners. A risk assessment at a basic level (a simplified methodology is acceptable here, unlike in the higher tier). Update at least once a year.
MFA on remote and administrative access (FIDO2 preferably for administrator accounts). EDR on endpoints as the default state. Patch management with KEV / EPSS prioritisation for critical vulnerabilities. Backups including an offline / immutable copy and regular restore testing. Central logging of key systems with retention ≥ 90 days. Encryption of data at rest and in transit.
An incident response plan with contacts and a reporting procedure; alerts routed to an on-call rota, not just to a daily check. Incident reporting: initial report within 24 h, notification within 72 h, final report within 30 days of the notification (the deadlines are the same in both regimes; in the lower tier the addressee is the National CERT). Review the plan annually, ideally with a tabletop exercise.
Basic security awareness training for employees (at least once a year) plus phishing simulations. An offboarding procedure (revoke privileged accounts immediately). Assessment of key suppliers (security terms in contracts, checks on critical ICT services, incident reporting by the supplier).
A fine of up to CZK 175,000,000 or up to 1.4 % of net worldwide annual turnover, whichever is higher, under Section 59 of Act No. 264/2025 Coll. Management is accountable for putting the controls in place, but the amount of mandatory documentation is smaller than in the higher tier.
Pomůžeme s implementací
Pokud potřebujete posoudit vlastní situaci, určit režim, připravit politiky nebo se připravit na audit — domluvte si nezávaznou konzultaci.