Summary · cheatsheet · higher-tier obligations

HIGHER OBLIGATIONS

Essential entities · Act No. 264/2025 Coll. + Decree 409/2025 · print to PDF

← Back to the Cybersecurity Act guide
Summary · cheatsheet · higher-tier obligations
Essential entities · Act No. 264/2025 Coll. + Decree 409/2025 · print to PDF
Informational document This document is a simplified informative overview of the key duties under Act No. 264/2025 Coll. and Decree 409/2025. It is not a binding legal opinion or a complete interpretation of the Act. The Act transposes the NIS2 Directive, so if you know Directive (EU) 2022/2555 you will recognise the structure of the obligations. Only the Czech wording published in the Collection of Laws is binding (e-Sbírka) — the English text here is an unofficial translation. CypherOn is a cybersecurity consultancy, not a law firm — for legal opinions turn to an attorney registered with the Czech Bar Association. For a definitive determination of your regime and duties we recommend asking NÚKIB directly.
Higher-tier obligations Essential entities · Act No. 264/2025 Coll. + Decree 409/2025 · print to PDF

This overview sums up the key duties of entities that fall into the higher-tier regime. It is a quick reference for company management and IT — not a legal interpretation.

Who it applies to

Entities in the sectors set out in Section 4 of the Act (the specific list of services is defined by Decree No. 408/2025 Coll.) that meet the criteria for a large organisation (250 or more employees, or turnover above EUR 50 million together with a balance sheet total above EUR 43 million — under Recommendation 2003/361/EC the more favourable of turnover and balance sheet total applies). Some entities (DNS providers, TLD registries, qualified eIDAS trust service providers, central government bodies) fall into this regime regardless of size.

What you have to do (5 pillars)

1. Governance & management

Appoint a cybersecurity manager (MKB) formally mandated by top management. Approve policies (information security, access control, incident response, acceptable use, backup, supplier risk management). Run controlled documentation with versioning and a periodic review (at least once a year).

2. Risk & asset management

Keep an asset register (hardware, software, data, processes, suppliers) with owners and CIA classification. Keep a risk register using the NÚKIB methodology (likelihood × impact → controls). Reassess at least once a year and after every major change.

3. Security controls

MFA on all administrative and remote access, FIDO2 / WebAuthn for privileged accounts. EDR / XDR on endpoints, MDM with enforced compliance. Patch management prioritised by KEV / EPSS (critical within 72 h, actively exploited within 24–48 h). 3-2-1 backups including an offline / immutable copy and regular restore testing. Central logging ≥ 90 days (12 months for key systems). Encryption of data at rest and in transit, with documented key rotation. Network segmentation, DMARC with a reject policy.

4. Incident response

An incident response plan (IRP) with escalation contacts and templates, detection mapped to MITRE ATT&CK. Reporting to NÚKIB: initial report within 24 h, notification within 72 h, final report within 30 days of the notification. Tabletop exercise at least once a year (ransomware, supply chain, insider threat). Tied to BCP / DR for key services (RTO / RPO).

5. People & suppliers

Regular cybersecurity training for all employees (at least once a year) and phishing simulations. An offboarding process that separates privileged accounts (revoke within the hour) from standard ones (≤ 24 h). Supplier risk management — a supplier register with tiering (DPA, contractual duties including incident reporting, restricted access, audit trail and evidence of controls), an SBOM for critical software, ideally with continuous monitoring (SecurityScorecard / BitSight).

Administrative duties

Penalties

A fine of up to CZK 250,000,000 or up to 2 % of net worldwide annual turnover, whichever is higher, under Section 59 of Act No. 264/2025 Coll. Top management is personally accountable for putting the controls in place and overseeing them — the Act states the responsibility of statutory bodies explicitly.

Recommended first steps (90 days)

Days 0–30
Gap analysis, appoint the cybersecurity manager, notify the Authority of the regulated service, get policies approved at management level.
Days 30–60
Asset register, risk register (first iteration), MFA on admin and VPN access, draft incident response plan.
Days 60–90
Patch SLAs, backup audit, tabletop exercise, security questionnaire for the top 5 suppliers.

Pomůžeme s implementací

Nejste si jistí,
jak začít?

Pokud potřebujete posoudit vlastní situaci, určit režim, připravit politiky nebo se připravit na audit — domluvte si nezávaznou konzultaci.