Resources · ZKB

CZECH CYBERSECURITY ACT

Act No. 264/2025 Coll. applies from 1 Nov 2025 and covers roughly 6,000 organisations per NÚKIB. Check whether yours is one of them and read the rules.

Step 1

Find out whether the act applies to you

Start with the calculator. If it turns out you are in scope, the readiness check shows how far you are from meeting the requirements.

Calculator · 30 seconds

Does the act apply to you?

Pick your sector and service, answer a few questions. The result tells you whether Act No. 264/2025 Coll. applies to your company and under which regime (lower / higher obligations). Covers all 15 sectors listed in Section 4 of the act.

Run the calculator →
Self-check · 5 min

Readiness check — lower obligations

A quick 13-question survey based on Act No. 264/2025 Coll. and decree No. 410/2025 Coll. in the lower-obligations regime. Find out how far your company is from full compliance — score, top 3 gaps, recommendations.

Run the check →
Self-check · 8 min

Readiness check — higher obligations

Eighteen questions based on decree No. 409/2025 Coll. for the higher-obligations regime — security roles, the cybersecurity management committee, audit, risk management, detection and testing. Same output: score, top 3 gaps, recommendations.

Run the check →
Builds on the tools

Gap analysis and implementation

The calculator and the readiness check tell you whether and how far you are in scope. This is where that turns into a concrete plan — what exactly is missing, in what order to fix it and how you will evidence it. For the lower and the higher regime alike.

Learn more →

Step 2

Get oriented in the obligations

What the act actually requires, by when, and what to do if you fall outside the regulation.

Guide · 10 min read

Guide to the Czech Cybersecurity Act

A plain-language guide to Act No. 264/2025 Coll. — who, what, when and how. Who it applies to, the two regimes, the obligations, notification of a service and registration, deadlines, penalties. Without the statutory wording.

Open the guide →
FAQ · common questions

FAQ on the new act

Answers to the usual questions — who the act applies to, how company size is counted, reporting deadlines, penalties, the cybersecurity manager role, higher vs. lower regime, overlap with GDPR.

Open the FAQ →
Outside the regulation · recommended minimum

The act does not apply to us — now what?

Even when the act does not reach you, cybersecurity still does. Ten minimum controls, plus pointers to the NÚKIB supporting materials and CIS Controls IG1.

Recommended minimum →

Step 3

Legal texts and summaries

The provisions with practical annotations, plus two-page cheatsheets for printing. The act is the Czech transposition of the NIS2 Directive (Directive (EU) 2022/2555), so anyone who knows NIS2 will recognise the structure of the obligations. Only the Czech wording published in the Collection of Laws is binding — the English texts here are an unofficial working translation. NIS2 in English is on EUR-Lex (CELEX 32022L2555), the Czech text of the act in the e-Sbírka at e-sbirka.gov.cz/sb/2025/264.

The act · interactive

Act No. 264/2025 Coll. — interactive

A structured walk through the sections of the cybersecurity act with annotations for practice. Search, a pinned table of contents, a note on every section. More readable than the PDF from the e-Sbírka.

Open the act →
Decree · higher · interactive

Decree 409/2025 — higher obligations

A structured walk through decree No. 409/2025 Coll. for the higher-obligations regime — 29 sections with their official headings and annotations by CypherOn. Part I (organisational measures, Sections 3–16) plus Part II (technical measures, Sections 17–27) and 6 annexes.

Open the decree →
Decree · lower · interactive

Decree 410/2025 — lower obligations

A structured walk through decree No. 410/2025 Coll. for the lower-obligations regime — 15 sections with their official headings and annotations by CypherOn. Merged measures on a single level plus 3 annexes. The reporting deadlines are the same as in the higher regime.

Open the decree →
Cheatsheet · 2 pages

Summary — higher obligations

A condensed 2-page overview of the obligations in the higher regime (essential entities). Ready to print as a PDF straight from the browser.

Open and download PDF →
Cheatsheet · 2 pages

Summary — lower obligations

A condensed 2-page overview of the obligations in the lower regime (important entities). Ready to print as a PDF straight from the browser.

Open and download PDF →

Need more than a tool?

The tools show the gaps.
We help you close them.

Gap analysis, an implementation plan and documentation you can stand behind, for the lower and the higher regime. Get in touch and we will go through where you stand and what is ahead.