What this page is and what it is not
The page follows the
real structure of Act No. 264/2025 Coll. (2 parts, 6 chapters, 73 sections) and covers
the key sections in a practical selection — not all 73 provisions (procedural and final sections are summarised briefly in the intro to the relevant part). For every section included we give the official heading from the Collection of Laws, our short paraphrase of what it regulates, and a separate CypherOn note on the practical impact.
This is neither the official wording nor the full text of the Act. For the definitive formulation, a citable source and all 73 sections, always open
e-Sbírka or
zákony pro lidi. The
“CypherOn note” blocks are our reading, not the text of the Act.
If you are coming from NIS2: this Act transposes Directive (EU) 2022/2555 into Czech law, so the structure of the obligations will look familiar — the English text of the directive is on
EUR-Lex. The Act itself has no official English version: only the Czech wording in the Collection of Laws is binding and everything below is an unofficial working translation for orientation.
Žádný paragraf neodpovídá hledanému výrazu.
Part One · Chapter I
General provisions
Sets out who the Act binds (entities established in the Czech Republic, and operators of electronic communications networks wherever they are seated). Transposes the NIS2 Directive into Czech law. Does not apply to systems handling classified information.
CypherOn note
The Act replaces the original Cybersecurity Act (181/2014 Coll.) and widens the field of regulated entities considerably. If you were regulated under the old Act, your regime changes and typically expands (transitional provisions in § 71). New entities — mainly medium-sized companies in ICT, manufacturing and logistics — come under regulation through this Act for the first time.
Defines the key terms: data, information, asset (primary / supporting / technical), cyberspace, threat, significant threat, cybersecurity event and incident, vulnerability; plus specific terms for digital infrastructure (DNS, cloud computing, data centre, CDN, social network, managed service and managed security service).
CypherOn note
The most important pair of terms in practice: cybersecurity event versus incident. An incident triggers a reporting duty (§ 15–16), an event does not. The line is drawn by the impact on the regulated service — see § 14 of Decree 410/2025 Coll., which sets out how to assess the significance of the impact in the lower regime. The term “asset” splits into primary (data, information, processes) and supporting (hardware, software, networks, people) — that split matters for § 12 (scope of cybersecurity management) and for risk management.
Part One · Chapter II · Division 1
The regulated service and the regime of its provider
A regulated service is a service that NÚKIB has brought under regulation by a decision in the registration procedure under § 6(2), on the basis of the conditions in § 4 and § 5.
CypherOn note
A regulated service is not automatically everything that “might fall under” the Act — it arises only from a NÚKIB decision in the registration procedure. That decision is an administrative act and can be challenged. Practical consequence: until NÚKIB registers the service you are formally not a provider of a regulated service — but the notification clock is already running and the liability for failing to notify is yours (§ 6, § 71).
§ 4
Conditions for registering a regulated service
¶
Lists the 15 sectors in which a regulated service can arise (public administration, energy, manufacturing, food, chemicals, water management, waste management, transport, digital infrastructure, finance, healthcare, science / research / education, postal and courier services, defence industry, space) plus a company-size condition (medium / large under Commission Recommendation 2003/361/EC). NÚKIB sets the details by decree.
CypherOn note
This is “filter no. 1” for the question “am I regulated?” — sector plus size. To work out size, use
our calculator (it follows 2003/361/EC) or the official
NÚKIB calculator. Some entities are regulated regardless of size (DNS providers, TLD registries, qualified eIDAS trust service providers, central government bodies) — that follows from later sections and from the decrees.
§ 5
Further conditions for registration
¶
Additional conditions that lead to registration in the higher-obligations regime even for smaller entities: sole provider of the service, impact on the security of the Czech Republic, systemic risks, regional or nationwide significance, a service affecting more than 125,000 people, a service feeding into one in the higher regime, and critical infrastructure entities.
CypherOn note
This section is why even a small company is not automatically outside the scope — if you run the only regional water utility serving 130,000 inhabitants, you are probably in the higher regime with 30 employees. It is “filter no. 2” for determining the regime, alongside size under § 4. If
our calculator puts you inside the scope but you are unsure about the regime, we recommend a consultation.
§ 6
Notification and registration of a regulated service
¶
A duty to notify NÚKIB of the service provided within 60 days of meeting the conditions. NÚKIB then decides on registration. An appeal against the decision has no suspensive effect.
CypherOn note
60 days is a short deadline — if you are growing (M&A, organic expansion) or changing your line of business, keep the conditions under review continuously. Practical advice: if you suspect the thresholds are close, contact NÚKIB yourself and find out whether registration applies to you. A cooperating entity fares better than one the authority discovers during an inspection or after an incident (§ 71 on transitional provisions has special rules for existing entities).
§ 7
Special rules on determining the size of an enterprise
¶
Departures from Commission Recommendation 2003/361/EC: Article 3(4) (linkage through public bodies) does not apply; state bodies and municipalities are not “enterprises”; separated assets mean the enterprise is not linked; special rules for science and research.
CypherOn note
Practical impact: if you are a state organisational unit, a self-governing region or municipality, a health insurance company or the Czech National Bank,
you are not an enterprise — your size is not calculated under the EU SME definition. Instead the Act places you according to your status (central government body → higher regime, region or municipality with extended powers → lower regime, and so on). In
our calculator this is the “not an enterprise” checkbox.
§ 8
Regime of the provider of a regulated service
¶
Two regimes: higher obligations (considerable importance for the Czech Republic) and lower obligations (everyone else). NÚKIB sets the split between the regimes by decree. Registration under § 5 means the higher regime automatically.
CypherOn note
The decrees setting out the obligations in each regime are
409/2025 Coll. for the
higher obligations and
410/2025 Coll. for the
lower obligations. The main differences: the higher regime requires a full ISMS with organisational and technical measures including an audit (§ 16 of Decree 409); the lower regime has a narrower single-tier set of measures (Decree 410). The incident reporting deadlines (24 h / 72 h / 30 days) are the same in both regimes.
§ 9
Reporting changes to the service and change of regime
¶
A duty to report changes to the service within 60 days. Moving from the lower to the higher regime starts fresh deadlines for the obligations.
CypherOn note
Moving from the lower to the higher regime means a marked increase in obligations (an audit is added, documentation gets more detailed, technical measures follow the scope of Decree 409/2025 Coll.). Plan the transition actively — if you are growing, count on 6–12 months to put the new obligations in place before the registration is formally changed.
§ 10
Cancelling the registration of a regulated service
¶
The procedure for when a service stops meeting the conditions for registration. Proceedings either on application by the provider or ex officio.
CypherOn note
A cancelled registration does not mean you should stop doing security. Contracts with regulated clients often keep the security requirements alive (supplier questionnaires, DPAs, audit rights) even after registration ends. The investment in a
minimum security baseline still holds its value.
Part One · Chapter II · Division 2
Obligations of the provider and countermeasures
Within 30 days of registration, report contact and supplementary data (ownership structure, technical details, geographical reach). Changes within 14 days.
CypherOn note
A minor obligation, but an easy one to miss. Keep a contact matrix on file and update it whenever people change (especially the cybersecurity manager and the statutory body). 14 days for reporting changes is short — automate the reminder in your HR system.
§ 12
Determining the scope of cybersecurity management
¶
Defines the “determined scope” — the assets connected with the regulated service. A duty to keep records of it and keep them current.
CypherOn note
The determined scope is what falls under your ISMS and your security measures. We recommend documenting it formally (one document approved by management) and mapping it onto the asset inventory. In practice you decide whether to include the whole organisation or only a selected domain — it depends on the dependencies. The auditor will ask: show me where your determined scope ends, and why.
Defines security measures and the duty to introduce and operate them. The specific content is set by NÚKIB by decree (409/2025 and 410/2025). Deadline for implementation: 1 year from registration. Also sets requirements for the selection of suppliers.
CypherOn note
One year from registration to implement all the security measures. That is a realistic horizon for the lower regime and a tight one for the higher regime (ISMS, audit). Start on a schedule no later than the month of registration — gap analysis, risk treatment plan, then step-by-step rollout of the measures from Decree 409 or 410. For supplier selection see § 31 (obligations for security-significant supplies).
§ 14
List of security measures
¶
The key section, carrying the catalogue of measures. Subsection 1 (higher regime): 14 organisational and 11 technical measures (ISMS, top management, roles, policy and documentation, management of assets / risks / suppliers, human resources, change management, acquisition / development / maintenance, access control, incident handling, continuity, audit; physical security, networks, identity, privileges, detection, logging, evaluation, applications, cryptography, availability, ICS). Subsection 2 (lower regime): 13 merged measures (minimum cybersecurity system, top management, assets, risks, human resources, continuity, access, identities, detection and logging, incident handling, networks, applications, cryptography).
CypherOn note
The measures are worked out in detail in the decrees:
409/2025 Coll. for the higher regime and
410/2025 Coll. for the lower regime. How to read § 14: it is the formal anchor, but in practice work directly with the decrees. What is worth knowing about § 14 is that the measures are split into
organisational and
technical ones — that split carries over into the structure of Decree 409.
§ 15
Reporting cybersecurity incidents
¶
The higher regime reports incidents to the Office (NÚKIB), the lower regime reports to the National CERT. Criteria: in the higher regime, incidents caused intentionally or serious ones are reported; in the lower regime, incidents with a significant impact (criteria in § 14 of Decree 410). The duty starts 1 year after registration.
CypherOn note
The key distinction: higher regime → NÚKIB, lower regime → National CERT. Practical consequence: verify the correct channels and contacts for your regime in advance. When in doubt, report — under the Act a late report is riskier than one that eventually turns out to be moot.
§ 16
Procedure for reporting cybersecurity incidents
¶
Deadlines: early warning within 24 hours, notification within 72 hours (24 hours for trust services), progress report, final report within 30 days. Filings go primarily through the NÚKIB Portal.
CypherOn note
The deadlines apply in both regimes (only the addressee differs — see § 15). “From detection” means the moment the responsible person (typically the cybersecurity manager) has reasonable grounds for suspicion, not the moment of the attack. Have a template ready with the details pre-filled (company ID, contacts, sector) — in a crisis there is no time to hunt for them. For trust services (qualified eIDAS providers) the notification deadline is 24 hours instead of 72 — a significant shortening.
§ 17
Handling cybersecurity incidents
¶
NÚKIB or the CERT responds within 24 hours of the notification. Methodological and technical support from the authority. A general duty of cooperation.
CypherOn note
During an incident NÚKIB and the National CERT are on your side, within their means. Practical consequence: an early report can get you concrete advice, indicators of compromise seen at other entities, and recommendations on forensic steps. Cooperation pays off — withholding information or hesitating to report is what the authority takes badly.
§ 18
Special provisions on obligations in digital infrastructure
¶
A special regime for DNS, trust services, TLD registries, cloud computing, data centres, CDNs, online marketplaces, search engines, social networks and managed (security) services. The Commission implementing regulation applies directly. Split into essential and important entities under NIS2.
CypherOn note
For digital infrastructure the Commission implementing regulation (CIR 2024/2690) applies as lex specialis, with concrete technical requirements. If you provide cloud, DNS, a data centre, a CDN and the like, deal with that EU regulation alongside the Act and the decrees. The detail for the higher regime is in
Decree 409/2025, but the Commission implementing regulation refines it on several points.
Informing users about an incident with a significant impact and about significant threats. NÚKIB may impose a duty to inform by decision.
CypherOn note
Watch the overlap with Article 34 GDPR (informing data subjects) — the Act has its own duty to inform the users of the regulated service, GDPR a separate one towards data subjects. An incident involving personal data typically triggers both. Have a communication plan ready for three audiences: NÚKIB, clients and users, and the individuals affected (GDPR).
Defines three types of countermeasure: alert, warning and reactive countermeasure. General duty of cooperation.
CypherOn note
Three levels of escalation. An alert is public information about an incident or about a breach of the Act. A warning is information about a serious threat or vulnerability. A reactive countermeasure is a binding decision (typically a ban on a given activity, or disconnecting a component). Details in § 21–23.
NÚKIB may inform the public about a cybersecurity incident or about breaches of the Act. Alternatively it can order the provider to do so itself.
CypherOn note
An uncomfortable naming-and-shaming instrument. Practical consequence: good incident management (fast response, solid reporting, transparent cooperation) lowers the risk that the authority reaches for an alert. Prepare a communication scenario for the case where the authority names you publicly — usually one to work through with crisis PR.
NÚKIB issues a warning when it identifies a serious threat or vulnerability. It publishes it through the NÚKIB Portal and the official notice board.
CypherOn note
A warning is aimed at the community, not at one particular entity. In practice these are the NÚKIB bulletins on current threats (typically malware campaigns and critical vulnerabilities). We recommend following the
NÚKIB portal and the CSIRT.cz feeds, and folding them into your threat intelligence.
§ 23
Reactive countermeasure
¶
A binding decision (or a measure of a general nature) to resolve or prevent an incident. An appeal has no suspensive effect. The provider notifies once it has been carried out.
CypherOn note
The hardest instrument available. NÚKIB can order a specific action (disconnect a system, limit a service, add a further measure) and an appeal has no suspensive effect — the decision applies immediately. Actual use is rare but possible, typically with an acute threat of nationwide impact or where an entity fails repeatedly.
Part One · Chapter II · Divisions 3–6
Suppliers, strategically significant services, supply-chain screening
§ 24
Special rules on handing over information and data from a supplier
¶
NÚKIB may order a supplier to hand over data during an ongoing incident. Reimbursement of costs reasonably incurred. Data treated as movable property for enforcement purposes.
CypherOn note
A practical instrument against vendor lock-in in a crisis. When an incident hits and a key supplier hesitates to hand over logs or forensic data, the authority can impose the duty directly. Handle this contractually in advance (an incident response clause in the DPA), but § 24 is the backstop for when the contract fails.
§ 25
Definition of a strategically significant service
¶
A strategically significant service is a regulated service whose disruption could seriously affect the security of the Czech Republic. The government sets the list by regulation.
CypherOn note
Strategically significant status is a third layer of classification, alongside the higher and lower regimes. It brings special supply-chain screening (§ 27–32) and a requirement of availability from Czech territory (§ 33). If you fall into this category you will receive a decision saying so — do not classify yourself.
§ 26
Reporting changes relating to a strategically significant service
¶
Report within 60 days. If the strategic significance is lost, the procedure mirrors cancellation of the registration.
CypherOn note
A procedural rule. If you run a strategically significant service and you change your supplier structure or the way you deliver it, report it in time — a late report can lead to penalties under § 59.
§ 27
Screening risks associated with a supplier
¶
NÚKIB collects information about the suppliers of strategically significant services. Introduces the terms: critical part of the determined scope, security-significant supply, supplier of a security-significant supply, and indispensable function.
CypherOn note
This mechanism is new compared with the old Act. If you provide a strategically significant service, NÚKIB can screen your key suppliers and restrict their involvement (§ 29). It also reaches the “invisible” suppliers — the suppliers of software components inside cloud services, for instance.
§ 29
Restricting risks associated with a supplier
¶
A key section — a measure of a general nature imposing conditions on, or banning, what a supplier of a security-significant supply delivers. Requires a government resolution. Reviewed at least once every 4 years.
CypherOn note
This is the instrument by which the government can ban a given supplier for strategically significant services, typically on grounds of geopolitical risk. Under NIS2 elsewhere in the EU it has been applied to specific 5G suppliers, certain cloud platforms and equipment from risky jurisdictions. Do not assume it will never reach you — follow the updates to the list.
§ 31
Obligations tied to supply-chain security screening
¶
A provider of a strategically significant service must identify, record and report information about suppliers of security-significant supplies within 10 days.
CypherOn note
10 days is a very short deadline — in practice it calls for active vendor management with up-to-date records. If you are among strategically significant services, build this obligation into your procurement and change management processes.
§ 33
Ensuring the availability of a strategically significant service
¶
A duty to ensure the service is available from Czech territory to the necessary extent, timing and quality. Reviewed at least once every 2 years. The government sets the necessary extent by regulation. Exemption for the public-sector cloud.
CypherOn note
The “availability from Czech territory” requirement is central to the data sovereignty question — a strategically significant service cannot be fully outsourced to a foreign cloud if that would jeopardise continuity from the Czech Republic. In practice it means redundant infrastructure in the country, an EU-sovereign cloud, or a hybrid arrangement with a clear primary site in the Czech Republic.
Part One · Chapter III
Domains (DNS and TLD)
§ 34
Reporting of data by domain name registration service providers
¶
Report to NÚKIB within 30 days: name, addresses of establishments in the EU, contacts, the member states where the service is provided, and the range of public IP addresses. Updates within 90 days.
CypherOn note
This concerns domain registrars (CZ.NIC for .cz, among others). Ordinary companies will notice it only indirectly — when you change registrar, that registrar must hold a valid registration with NÚKIB.
§ 35
Collection of domain name registration data
¶
A duty to run a database of registrant data (name, e-mail, telephone, date of registration). Publication of non-personal data. Access to the data on request by a legitimate requester within 72 hours (WHOIS under NIS2).
CypherOn note
This is the technical transposition of the NIS2 requirements on WHOIS. For an ordinary company it means: if your domain is registered to a natural person, the data will be available to a certain extent to qualified requesters (authorities, investigators). For registrants who care about privacy, that can be a reason to move to a company registration.
Part One · Chapter IV
Further instruments for ensuring cybersecurity
§ 36
Exemption from the right to information
¶
Information that would endanger cybersecurity, and information from the registers under § 46, is not disclosed under the Free Access to Information Act or under the act on the right to environmental information.
CypherOn note
Practical impact: NÚKIB can legitimately refuse requests under Act 106/1999 Coll. for sensitive security information. For you as a provider it also protects the sensitive data you share with the authority (incidents, suppliers, technical detail).
§ 37
State of cyber emergency
¶
Sets out the grounds for declaring a state of cyber emergency.
CypherOn note
A state of cyber emergency is a milder form of crisis than a state of emergency under constitutional law. Once it is declared, both NÚKIB and regulated entities have extended powers and duties (§ 39).
§ 38
Declaring a state of cyber emergency
¶
Declared by NÚKIB for a maximum of 30 days (extendable, up to 60 days in total). After that it can ask the government to declare a state of emergency.
CypherOn note
It has not been declared so far (the Act is new). In future it can be expected during a massive ransomware attack on a key sector, or during geopolitical escalation. Put a “NÚKIB declares a state of cyber emergency” scenario into your business continuity plans and work out what it would mean for your organisation.
§ 39
Measures during a state of cyber emergency
¶
Broad powers for NÚKIB: ordering vulnerability scans or penetration tests, a duty to provide information, a ban on using certain assets, on-call duty, opening up non-public networks, and imposing obligations on the media.
CypherOn note
Very strong powers. Prepare an internal procedure: who has authority to decide on cooperation, how quickly you respond to a NÚKIB request, how you communicate inside the organisation. In a crisis there is no time to work this out.
Part One · Chapter V
Public administration and its oversight
§ 42
The Office (NÚKIB)
¶
NÚKIB as a central administrative authority (seat in Brno). The director is appointed by the government. A broad list of powers: registration, decrees, countermeasures, registers, contact point for the higher regime, certification, GOVSATCOM, Galileo, GNSS.
CypherOn note
NÚKIB is an independent central authority, not subordinate to a ministry. It has teams specialised by sector — if you want a working relationship, it is worth finding out who covers yours. The seat is in Brno, but communication runs mostly electronically through the NÚKIB Portal (§ 45).
Run by an operator under a public-law contract. Contact point for the lower regime. Conditions on the operator: seat in the Czech Republic, “Confidential” security clearance, 5 years of experience, international membership.
CypherOn note
The National CERT is currently operated by the CZ.NIC association (CSIRT.CZ). In the lower regime it is your main contact point for reporting incidents (§ 15). Follow
csirt.cz for warnings about current threats.
The mandatory electronic channel for most filings with NÚKIB. Anything outside the Portal is exceptional.
CypherOn note
Practical consequence: most of your dealings with NÚKIB run through the Office Portal (registration, reporting data, reporting incidents, submitting documents). Set up the account and access rights in advance — do not leave it until a crisis. Alternative channels (e-mail, data box) are reserved for specific situations, such as the portal being unavailable during the incident itself.
§ 46
Registers kept by the Office
¶
NÚKIB keeps registers of: regulated services, domain registrars, cybersecurity incidents / events / threats / vulnerabilities, suppliers of security-significant supplies, coordinated vulnerability disclosure, penetration tests and inspections. Staff are bound by confidentiality.
CypherOn note
Your data as a provider of a regulated service ends up in the NÚKIB registers. Part of it is open to the public (typically the list of regulated services), the sensitive part (incidents, vulnerabilities, suppliers) is protected. Practical consequence: the authority holds a structured picture of you, and it uses it in inspections (§ 55) and when assessing the supply chain (§ 27 and following).
§ 54
Cooperation with other member states
¶
Cooperation within the EU. Rules on the main establishment (DNS, cloud, social networks and so on) — inspections in another member state only at the request of the home state.
CypherOn note
Practical impact for multinational cloud / DNS / social networks: if your main establishment is in Ireland (the typical case for the large EU clouds), the primary regulator is the authority there and NÚKIB mostly acts through it. For purely Czech companies there is no practical impact.
Part One · Chapter VI
Inspections, remedial measures, offences and penalties
§ 55
Inspections carried out by the Office
¶
A general power for NÚKIB to inspect compliance with the Act at providers of regulated services.
CypherOn note
Inspections follow the Inspection Act (255/2012 Coll.). In the higher regime they are more regular (tied also to the audit under § 16 of Decree 409/2025); in the lower regime they are typically reactive, after an incident or a complaint. Keep an “inspection folder” ready — the set of key documents the authority routinely asks to see.
NÚKIB may order shortcomings to be remedied within a set deadline. An appeal has no suspensive effect.
CypherOn note
A remedial measure is the milder form of sanction — instead of a fine you get an obligation to put something right. In practice it is the first response when the authority finds shortcomings. If you do not act on it, it escalates into a fine (§ 59) or further steps.
§ 58
Temporary ban on serving as a member of the statutory body
¶
The option of a temporary ban on holding office (at least 6 months). Only for providers in the higher regime. Recorded in the commercial register.
CypherOn note
A very hard personal sanction — a member of the statutory body can be temporarily removed from office. It is an explicit NIS2 novelty carried into Czech law. Practical consequence: D&O insurance usually does not cover this type of regulatory sanction. If you are relying on a policy, check the scope with the insurer in advance.
§ 59
Offences by a provider of a regulated service
¶
Definitions of offences for the higher regime (15 items) and the lower regime (15 items), plus separate ones for strategically significant services (8 items). Fines up to CZK 250,000,000 or 2 % of worldwide turnover.
CypherOn note
The cap in Czech crowns (CZK 250 million, roughly EUR 10 million) matches NIS2. Reaching the maximum is rare in practice abroad, and decisions in the first Czech cases are not public yet. The main risk point is a late or missing incident report — it is the most easily testable obligation and, in NIS2 practice abroad, the most common reason for a penalty. Combined with GDPR (4 % of turnover), a single incident can generate two parallel fines, one from NÚKIB and one from the Czech data protection authority (ÚOOÚ).
§ 60
Offences by other persons in the field of cybersecurity
¶
9 general offences plus breach of confidentiality by a natural person, plus offences by domain registrars, TLD holders and applicants for registration in the Community. Fines up to CZK 250 million.
CypherOn note
Natural persons can be sanctioned too (confidentiality), not just providers of regulated services. For an ordinary company this matters if one of your people takes on the role of contact point or sits on an incident response committee — a breach of confidentiality means a personal fine.
Part Two
Common, transitional and final provisions
§ 67
Representative for the Czech Republic
¶
Non-European providers of DNS, cloud computing, CDNs, social networks and so on must appoint a representative in the Czech Republic. Otherwise they are deemed to be established here.
CypherOn note
This concerns foreign cloud and digital services that provide a regulated service in the Czech Republic. For an ordinary company it is relevant mostly indirectly — if you use a foreign SaaS for key processes, check whether the supplier meets § 67 (has a representative in the Czech Republic or the EU).
§ 70
Relationship to sectoral EU legislation
¶
Lex specialis: where another EU act sets comparable obligations, this Act does not apply (DORA for the financial sector, eIDAS for trust services, for example).
CypherOn note
Practical consequence for the financial sector: DORA (Regulation 2022/2554) takes precedence over this Act. Banks and credit institutions are primarily subject to DORA, not to this Act in full. Qualified eIDAS providers follow eIDAS. Map out which rules apply to you before you start planning compliance.
§ 71
Transitional provisions
¶
Entities regulated under the old Act (181/2014) meet their obligations on a transitional basis under the old act until the deadlines run out. Exception: incidents are already reported under the new Act.
CypherOn note
If you were an operator of critical information infrastructure or ran a significant information system under the old Act, you have a transitional period to put the new obligations in place. Incidents, however, are reported under the new Act from 1 November 2025 — watch the difference in addressee (NÚKIB or the National CERT) depending on your regime.
§ 72
Repealing provision
¶
Repeals 17 pieces of legislation: Act 181/2014, Decrees 317/2014, 437/2017, 82/2018, 315/2021, 190/2023 and all their amendments.
CypherOn note
Important for the references in your internal documentation — if your policies cite Decree 82/2018 (security measures for critical information infrastructure and significant information systems), update them to 409/2025 (higher regime) or 410/2025 (lower regime). We recommend a documentation review before the transitional period ends.
The Act takes effect on 1 November 2025.
CypherOn note
The key date. All the deadlines run from 1 November 2025 (60 days to notify a new service, 30 days to report data, 1 year to implement the measures). If you have not yet worked out where you stand, start now — our
calculator and
FAQ are a good entry point.