Summary · cheatsheet · lower-tier obligations

LOWER OBLIGATIONS

Important entities · Act No. 264/2025 Coll. + Decree 410/2025 · print to PDF

← Back to the Cybersecurity Act guide
Summary · cheatsheet · lower-tier obligations
Important entities · Act No. 264/2025 Coll. + Decree 410/2025 · print to PDF
Informational document This document is a simplified informative overview of the key duties under Act No. 264/2025 Coll. and Decree 410/2025. It is not a binding legal opinion or a complete interpretation of the Act. The Act transposes the NIS2 Directive, so if you know Directive (EU) 2022/2555 you will recognise the structure of the obligations. Only the Czech wording published in the Collection of Laws is binding (e-Sbírka) — the English text here is an unofficial translation. CypherOn is a cybersecurity consultancy, not a law firm — for legal opinions turn to an attorney registered with the Czech Bar Association. For a definitive determination of your regime and duties we recommend asking NÚKIB directly.
Lower-tier obligations Important entities · Act No. 264/2025 Coll. + Decree 410/2025 · print to PDF

This overview sums up the key duties of entities that fall into the lower-tier regime. It is a quick reference for company management and IT — not a legal interpretation.

Who it applies to

Entities in the sectors set out in Section 4 of the Act (the specific list of services is defined by Decree No. 408/2025 Coll.) that meet the criteria for a medium-sized organisation (50 to 249 employees, or turnover above EUR 10 million together with a balance sheet total above EUR 10 million) and do not meet the criteria for the higher-tier regime. In some sectors (manufacturing or managed ICT services, for instance) most medium-sized companies land here.

What you have to do (5 pillars — reduced scope)

1. Governance & management

Designate a person responsible for cybersecurity (a cybersecurity manager or equivalent). Have the basic policies approved (information security, access control, incident response plan, backup). Review the policies at least once a year.

2. Risk & asset management

An asset inventory (at least the main systems and data) with owners. A risk assessment at a basic level (a simplified methodology is acceptable here, unlike in the higher tier). Update at least once a year.

3. Security controls

MFA on remote and administrative access (FIDO2 preferably for administrator accounts). EDR on endpoints as the default state. Patch management with KEV / EPSS prioritisation for critical vulnerabilities. Backups including an offline / immutable copy and regular restore testing. Central logging of key systems with retention ≥ 90 days. Encryption of data at rest and in transit.

4. Incident response

An incident response plan with contacts and a reporting procedure; alerts routed to an on-call rota, not just to a daily check. Incident reporting: initial report within 24 h, notification within 72 h, final report within 30 days of the notification (the deadlines are the same in both regimes; in the lower tier the addressee is the National CERT). Review the plan annually, ideally with a tabletop exercise.

5. People & suppliers

Basic security awareness training for employees (at least once a year) plus phishing simulations. An offboarding procedure (revoke privileged accounts immediately). Assessment of key suppliers (security terms in contracts, checks on critical ICT services, incident reporting by the supplier).

Administrative duties

Penalties

A fine of up to CZK 175,000,000 or up to 1.4 % of net worldwide annual turnover, whichever is higher, under Section 59 of Act No. 264/2025 Coll. Management is accountable for putting the controls in place, but the amount of mandatory documentation is smaller than in the higher tier.

Recommended first steps (90 days)

Days 0–30
Designate the responsible person, assess your gaps against Decree 410/2025, notify the Authority of the regulated service.
Days 30–60
Basic policies, asset inventory, MFA on key access paths.
Days 60–90
Incident response plan, backup audit, security awareness campaign, supplier contracts.

Pomůžeme s implementací

Nejste si jistí,
jak začít?

Pokud potřebujete posoudit vlastní situaci, určit režim, připravit politiky nebo se připravit na audit — domluvte si nezávaznou konzultaci.