Summary · cheatsheet · higher-tier obligations
Essential entities · Act No. 264/2025 Coll. + Decree 409/2025 · print to PDF
Higher-tier obligations
This overview sums up the key duties of entities that fall into the higher-tier regime. It is a quick reference for company management and IT — not a legal interpretation.
Entities in the sectors set out in Section 4 of the Act (the specific list of services is defined by Decree No. 408/2025 Coll.) that meet the criteria for a large organisation (250 or more employees, or turnover above EUR 50 million together with a balance sheet total above EUR 43 million — under Recommendation 2003/361/EC the more favourable of turnover and balance sheet total applies). Some entities (DNS providers, TLD registries, qualified eIDAS trust service providers, central government bodies) fall into this regime regardless of size.
Appoint a cybersecurity manager (MKB) formally mandated by top management. Approve policies (information security, access control, incident response, acceptable use, backup, supplier risk management). Run controlled documentation with versioning and a periodic review (at least once a year).
Keep an asset register (hardware, software, data, processes, suppliers) with owners and CIA classification. Keep a risk register using the NÚKIB methodology (likelihood × impact → controls). Reassess at least once a year and after every major change.
MFA on all administrative and remote access, FIDO2 / WebAuthn for privileged accounts. EDR / XDR on endpoints, MDM with enforced compliance. Patch management prioritised by KEV / EPSS (critical within 72 h, actively exploited within 24–48 h). 3-2-1 backups including an offline / immutable copy and regular restore testing. Central logging ≥ 90 days (12 months for key systems). Encryption of data at rest and in transit, with documented key rotation. Network segmentation, DMARC with a reject policy.
An incident response plan (IRP) with escalation contacts and templates, detection mapped to MITRE ATT&CK. Reporting to NÚKIB: initial report within 24 h, notification within 72 h, final report within 30 days of the notification. Tabletop exercise at least once a year (ransomware, supply chain, insider threat). Tied to BCP / DR for key services (RTO / RPO).
Regular cybersecurity training for all employees (at least once a year) and phishing simulations. An offboarding process that separates privileged accounts (revoke within the hour) from standard ones (≤ 24 h). Supplier risk management — a supplier register with tiering (DPA, contractual duties including incident reporting, restricted access, audit trail and evidence of controls), an SBOM for critical software, ideally with continuous monitoring (SecurityScorecard / BitSight).
A fine of up to CZK 250,000,000 or up to 2 % of net worldwide annual turnover, whichever is higher, under Section 59 of Act No. 264/2025 Coll. Top management is personally accountable for putting the controls in place and overseeing them — the Act states the responsibility of statutory bodies explicitly.
Pomůžeme s implementací
Pokud potřebujete posoudit vlastní situaci, určit režim, připravit politiky nebo se připravit na audit — domluvte si nezávaznou konzultaci.