What this page is and what it is not
The page follows the
real structure of Decree No. 410/2025 Coll. (4 parts, 15 sections, 3 annexes) for the lower-obligations regime. For every § we give the official heading, our short paraphrase of what it regulates, and a separate CypherOn note on the practical impact.
This is neither the official wording nor the full text of the decree. The decree implements Act No. 264/2025 Coll., which is the Czech transposition of the NIS2 Directive —
Directive (EU) 2022/2555 — so if you know NIS2, you will recognise the structure of the obligations. Neither the act nor its decrees have an official English version:
only the Czech wording in the Collection of Laws is binding and the English text on this page is an orientation translation. For the definitive wording and current status always check the Czech text of the decree in the
e-Sbírka or on
Zákony pro lidi, and the Czech text of the act itself in the
e-Sbírka. The higher obligations are covered by a separate
Decree 409/2025 Coll.
Žádný paragraf neodpovídá hledanému výrazu.
Part One
Introductory provisions
The decree transposes the NIS 2 Directive and, for the obliged entity (= a provider of a regulated service under the lower regime), governs (a) the content of the security measures and how they are introduced and applied, and (b) how to determine that the impact of a cybersecurity incident is significant.
CypherOn note
If you fall under the lower regime (NÚKIB, the national cybersecurity agency, puts you there in the registration decision under § 6 of the act), this decree is your primary implementation document. Deadline for putting the measures in place: 1 year from registration (§ 13 para. 4 of the act). Compared with Decree 409/2025 (higher regime), 410/2025 is markedly shorter — the measures sit on a single level, with no split into organisational and technical.
Definitions: user, privileged user, administrator, security policy.
CypherOn note
Shorter definitions than in 409/2025 — matching the smaller scope of obligations. The key split: user (an ordinary account), privileged user (permissions beyond an ordinary user), administrator (system administration). This split determines which measures apply to whom — typically stricter authentication and closer monitoring for privileged users and administrators.
Part Two
Security measures
§ 3
System for ensuring minimum cybersecurity
¶
The umbrella provision: the obliged entity applies proportionate measures; it maintains a “security measures overview” under Annex 1 (status, description, deadlines, priorities, responsibility); it updates the overview annually and archives it for 4 years. Policy and documentation, asset management, supplier contracts with the clauses set out in Annex 2, security requirements for acquisition / development / maintenance.
CypherOn note
This is the backbone of the lower regime — instead of a full ISMS as in 409/2025, the core of it is the security measures overview in tabular form (Annex 1). In practice: a SharePoint list or a spreadsheet with 6 columns (measure, status: Implemented / In progress / Not implemented, description, deadline, priority 1–4, responsibility). Annual update plus 4-year archiving. For a mid-sized company expect 30–80 rows.
§ 4
Requirements on top management
¶
The statutory body appoints a person responsible for cybersecurity and makes sure they are trained. It goes through training of its own. It provides resources, keeps itself informed about the state of the measures, supports improvement and sets the recovery priority of primary assets.
CypherOn note
Under the lower regime the law does not require a formal cybersecurity manager in the full sense of the higher regime (409/2025), but you do have to appoint someone responsible for cybersecurity. Realistically, for a mid-sized company: the existing IT manager with an extended role (formally appointed and with added capacity, typically 20–40 % of working time), an external consultant as a “virtual cybersecurity manager” 2–4 days a month, or CISO-as-a-Service on a flat fee. Whichever option you pick, two things matter: a written appointment by management and access to company management at least on an ad-hoc basis. Note that the statutory body itself also has to complete training — that is new compared with the old cybersecurity act.
§ 5
Human resources security
¶
A policy of safe behaviour (topics in Annex 3). Rules for developing awareness. Checking compliance. Rules for breaches. Induction and recurring training (management, users, administrators). Keeping training records.
CypherOn note
Realistically: induction training as part of onboarding, annual security awareness training for all staff (KnowBe4, Cofense, the NÚKIB awareness portal, free of charge), specialised training for privileged roles, phishing simulations 2–4 times a year. Target: a click rate under 5 % after 12 months of the programme. Keeping records (who, when, which training) matters — the auditor or NÚKIB will ask: show me which employees completed training in the last 12 months. Have a defined procedure for breaches of the policy (warning → sanction → employment consequences).
§ 6
Business continuity management
¶
Priority of technical assets and recovery procedures. Named people responsible. Regular backups.
CypherOn note
For a mid-sized company this is enough: a list of 5–10 critical processes, RTO / RPO for each (typically 4 h–24 h for operations, 1 h–4 h for data), a dependency map (which systems and suppliers are critical), fallback procedures (manual processes, an alternative supplier). Backups on the 3-2-1 rule (3 copies, 2 media, 1 offline or immutable) — ransomware encrypts online backups together with production. A restore test on a sample of data monthly, a full end-to-end DR test annually. For M365 specifically, use third-party backup (Veeam M365, AvePoint) — Microsoft retention is not a backup.
Access rights limited to what is strictly necessary. Separation of user and administrator accounts. Mobile devices. Review of permissions. Revoking rights on role change or termination. Physical security.
CypherOn note
In practice: RBAC through roles (sales, marketing, dev, admin) instead of individual grants. Separate admin accounts (user@ for everyday work, user-admin@ for IT operations). Recertification once a year — a review of active accounts and permissions. Differentiate off-boarding by scenario: privileged account + involuntary departure = revoke within the hour, ideally before the person is told; standard + voluntary = within 24 h. A monthly reconciliation of active accounts against HR data uncovers the “zombie” accounts (typically 5–10 % of accounts in a company with no process in place).
§ 8
Identity and permission management
¶
A tool for managing identities (limiting failed attempts, re-authentication, resilient authentication credentials). The goal: multi-factor authentication or zero-trust continuous authentication. Cryptographic keys or certificates as an interim option. Passwords as an interim option, with rules (12/17/22 characters for a user / administrator / technical asset, change once every 18 months, 12 passwords remembered, no simple patterns). Detailed rules for default passwords and for restoring access.
CypherOn note
A key section with concrete technical parameters. The decree accepts that MFA is the goal but provides an interim regime built on password rules. We recommend going straight to MFA on all admin accounts, VPN, RDP, the cloud console and e-mail — the password rules (12 characters for a user, 17 for an administrator, 22 for a technical asset) are hard to sustain in day-to-day operation. For privileged accounts we recommend a FIDO2 hardware key (a YubiKey costs around EUR 50 a piece) instead of SMS — SMS and TOTP MFA is still better than nothing, but not enough against advanced phishing or AiTM. In M365, turn on conditional access (the device has to be compliant, block legacy authentication protocols).
§ 9
Detection and logging of cybersecurity events
¶
Control of the network perimeter. Anti-malware on servers and endpoints. Control over automatic execution of content. Continuous information and early warning. Keeping the tools updated. Event records (date and time, type of activity, identification of the asset and the account, success or failure). Retention period according to your own needs.
CypherOn note
For a mid-sized company: EDR on every endpoint (not just a classic antivirus). Careful — for real EDR functionality pick Microsoft Defender for Endpoint P2 (P1 only gives you antivirus plus attack surface reduction; full EDR and threat hunting are in P2, which comes with M365 E5 or as a standalone licence). Alternatives: ESET Protect Advanced (support in Czech), SentinelOne, CrowdStrike Falcon Go for small teams. The point: with ransomware breakout times under an hour, “somebody looks at the alerts once a day” is an illusion of defence. A realistic minimum: either an MDR service (Managed Detection & Response — an external 24/7 SOC, typically EUR 5–15 per seat per month) or your own on-call rota with a defined response SLA under 30 minutes outside working hours. The decree says retention is “according to your own needs” — we recommend at least 90 days in primary storage and 12 months in an archive, the same as under the higher regime. The global median dwell time before detection of sophisticated attacks (Mandiant M-Trends 2024) ranges from a few days for ransomware to hundreds of days for supply chain attacks; shorter retention can destroy your forensics.
§ 10
Handling cybersecurity incidents
¶
Duty of employees to report. A methodology for assessing incidents, including the significance of the impact (§ 14). Detection of cybersecurity events. Assessment against the methodology. Reporting under § 15 of the act. Final report under § 16 of the act.
CypherOn note
For a mid-sized company 5–10 pages are enough, covering: a contact matrix, 3–4 key scenarios (ransomware, BEC / fraud, data breach, loss of a critical supplier), steps 1-2-3 for each, and report templates for the National CERT (under the lower regime you report to the National CERT, not to NÚKIB — see § 15 of the act). Test the plan at least once a year as a tabletop exercise (3 hours of discussion plus a gap list as the output). The reporting deadlines (24 h / 72 h / 30 days) come from § 16 of the act and are the same for both regimes.
§ 11
Communication network security
¶
Network segmentation. Separation of the production and the backup environment. Restricted communication at the perimeter. Resilient protocols. Secure remote connection and remote administration.
CypherOn note
For a mid-sized company: a next-gen firewall (Fortinet, Palo Alto, Sophos, Cisco) with threat intelligence feeds; guest WiFi on an isolated VLAN; basic segmentation of servers / user workstations / the management zone. Cloud-first companies have the firewall in the cloud (Azure Firewall, AWS Security Groups + Network Firewall). Review firewall rules annually — remove the forgotten “temporary allow ANY” rules. Remote connection: VPN with MFA, not RDP exposed to the internet. Remote administration: a bastion host or a zero-trust solution (Tailscale, Cloudflare Access).
§ 12
Application security
¶
Applying security updates without undue delay. Specific measures for technical assets that are out of support. Regular vulnerability scanning.
CypherOn note
Recommended SLA for a mid-sized company: actively exploited (CISA KEV) 24–48 h; critical (CVSS 9.0 and above) 72 h; high 14 days; medium 30 days. Use CISA KEV (Known Exploited Vulnerabilities) and EPSS (Exploit Prediction Scoring System) to prioritise, not CVSS alone. Automate through Windows Update / WSUS, Linux unattended-upgrades, a container image rebuild pipeline. For unsupported software (a legacy ERP, an old PLC) put compensating controls in place: isolation on a separate VLAN, restricted access, closer monitoring. Vulnerability scanning: OpenVAS (free), Nessus, Qualys.
§ 13
Cryptographic algorithms
¶
Algorithms that are currently resilient. NÚKIB recommendations. Secure voice / text / audiovisual / e-mail communication. Emergency communication within the organisation.
CypherOn note
Practical minimum for a mid-sized company: TLS 1.2+ (1.3 preferred) for web and API, BitLocker / FileVault / LUKS on every laptop, a cloud KMS for keys (AWS KMS / Azure Key Vault — around USD 1 per key per month). For most mid-sized companies the built-in encryption of the cloud platforms is enough — no need for your own HSM. Two policies matter: full automation of TLS certificate renewal over ACME / Let's Encrypt (in 2025 the CA/Browser Forum approved a stepped shortening of certificate lifetimes, so manual renewal is ceasing to be sustainable), and no credential hard-coded in source (use a vault or a secret manager). For emergency communication when the main systems are down: an alternative channel (Signal, encrypted e-mail with S/MIME or PGP, a separate messenger for the crisis team).
Part Three
Determining the significance of the impact of a cybersecurity incident
§ 14
Determining the significance of the impact
¶
The obliged entity sets (a) the tolerable level of harm and (b) the areas against which significance is assessed (operational impact, number of users affected, resources needed for recovery, type and location of the assets, sensitivity of the data, cause). The impact is significant if it exceeds the tolerable level and the area is assessed as significant at the same time.
CypherOn note
The key section for deciding when to report an incident. The decree gives you the framework; the concrete thresholds are set by each organisation itself (the “tolerable level of harm”). Practical advice: document it formally — approved by the statutory body, with concrete thresholds (for example “outage longer than 4 h” = significant, “breach of more than 1 000 personal data records” = significant). When in doubt, report — a late or missing report is riskier than sending one that turns out to be moot. Under the lower regime the report goes to the National CERT (CSIRT.CZ), not to NÚKIB.
The decree takes effect on 1 November 2025.
CypherOn note
Together with Act No. 264/2025 Coll. and Decree No. 409/2025 Coll. (higher regime). The deadline for putting the measures in place comes from § 13 para. 4 of the act — 1 year from registration. Decree 410/2025 has no transitional provisions of its own (unlike § 28 of 409/2025).
Annexes
Annexes to the decree
Annex 1
Security measures overview
¶
A table for evaluating how effective the implemented measures are. 6 columns: measure, status, description, deadline, priority, responsibility. Status: “Implemented” / “In progress” / “Not implemented”. Priority: low (1), medium (2), high (3), critical (4). Set out in detail across 7 sub-tables (Table 1 as the umbrella plus Tables 2–7 describing the individual columns).
CypherOn note
A practical governance tool. Implementation: a SharePoint list, a spreadsheet with filters, or a dedicated compliance tool such as Vanta or Drata. Annual update plus 4-year archiving under § 3. The auditor or NÚKIB will ask for this table first — it is the evidence you can actually put on the desk. For a mid-sized company a realistic size is 30–80 rows (one row = one measure or control).
Annex 2
Requirements on contractual clauses with suppliers
¶
14 types of relevant contract clauses (a–n): confidentiality / integrity / availability of information, auditing the supplier, subcontracting chains, exit clause, penalties, right to use the data, ownership of the code, confidentiality of the contract, the supplier security policies, change management, incidents affecting performance of the contract, continuity, SLA, secure development.
CypherOn note
The contract package that belongs in every key supplier contract, ICT suppliers above all. Practical advice: prepare a standard security annex to the contract that you can attach to every new contract with an ICT supplier. For suppliers outside the EU (transfers of personal data) add SCCs or BCRs. For critical suppliers, negotiate an explicit right to audit after an incident.
Annex 3
Topics for security awareness development
¶
25 topics (a–y): securing devices, the firewall and the antivirus and their limits, malicious programs, the risks of downloading programs and applications, software updates, macros, executable files, securing user accounts, passwords, multi-factor authentication, social engineering, online identity and the digital footprint, working on a computer network, remote connection (VPN), secure electronic communication, website security, backing up and encrypting data, removable media, cloud computing, reporting unusual behaviour and suspected vulnerabilities, responding to a security event or incident, private use of work devices, BYOD, personal responsibility of the employee, current threats.
CypherOn note
The decree gives a broad list of topics. Standard programmes cover them: KnowBe4, Cofense, the NÚKIB awareness portal (
osveta.nukib.gov.cz — free of charge, in Czech). A workable approach: annual training for all staff covering the basics (phishing, passwords, MFA, incident reporting), specialised training for higher-risk roles (developers, finance, management). Measure the phishing click rate — the target is under 5 % after 12 months of the programme.