Resources · ZKB
Act No. 264/2025 Coll. applies from 1 Nov 2025 and covers roughly 6,000 organisations per NÚKIB. Check whether yours is one of them and read the rules.
Step 1
Start with the calculator. If it turns out you are in scope, the readiness check shows how far you are from meeting the requirements.
Pick your sector and service, answer a few questions. The result tells you whether Act No. 264/2025 Coll. applies to your company and under which regime (lower / higher obligations). Covers all 15 sectors listed in Section 4 of the act.
Run the calculator → Self-check · 5 minA quick 13-question survey based on Act No. 264/2025 Coll. and decree No. 410/2025 Coll. in the lower-obligations regime. Find out how far your company is from full compliance — score, top 3 gaps, recommendations.
Run the check → Self-check · 8 minEighteen questions based on decree No. 409/2025 Coll. for the higher-obligations regime — security roles, the cybersecurity management committee, audit, risk management, detection and testing. Same output: score, top 3 gaps, recommendations.
Run the check → Builds on the toolsThe calculator and the readiness check tell you whether and how far you are in scope. This is where that turns into a concrete plan — what exactly is missing, in what order to fix it and how you will evidence it. For the lower and the higher regime alike.
Learn more →Step 2
What the act actually requires, by when, and what to do if you fall outside the regulation.
A plain-language guide to Act No. 264/2025 Coll. — who, what, when and how. Who it applies to, the two regimes, the obligations, notification of a service and registration, deadlines, penalties. Without the statutory wording.
Open the guide → FAQ · common questionsAnswers to the usual questions — who the act applies to, how company size is counted, reporting deadlines, penalties, the cybersecurity manager role, higher vs. lower regime, overlap with GDPR.
Open the FAQ → Outside the regulation · recommended minimumEven when the act does not reach you, cybersecurity still does. Ten minimum controls, plus pointers to the NÚKIB supporting materials and CIS Controls IG1.
Recommended minimum →Step 3
The provisions with practical annotations, plus two-page cheatsheets for printing. The act is the Czech transposition of the NIS2 Directive (Directive (EU) 2022/2555), so anyone who knows NIS2 will recognise the structure of the obligations. Only the Czech wording published in the Collection of Laws is binding — the English texts here are an unofficial working translation. NIS2 in English is on EUR-Lex (CELEX 32022L2555), the Czech text of the act in the e-Sbírka at e-sbirka.gov.cz/sb/2025/264.
A structured walk through the sections of the cybersecurity act with annotations for practice. Search, a pinned table of contents, a note on every section. More readable than the PDF from the e-Sbírka.
Open the act → Decree · higher · interactiveA structured walk through decree No. 409/2025 Coll. for the higher-obligations regime — 29 sections with their official headings and annotations by CypherOn. Part I (organisational measures, Sections 3–16) plus Part II (technical measures, Sections 17–27) and 6 annexes.
Open the decree → Decree · lower · interactiveA structured walk through decree No. 410/2025 Coll. for the lower-obligations regime — 15 sections with their official headings and annotations by CypherOn. Merged measures on a single level plus 3 annexes. The reporting deadlines are the same as in the higher regime.
Open the decree → Cheatsheet · 2 pagesA condensed 2-page overview of the obligations in the higher regime (essential entities). Ready to print as a PDF straight from the browser.
Open and download PDF → Cheatsheet · 2 pagesA condensed 2-page overview of the obligations in the lower regime (important entities). Ready to print as a PDF straight from the browser.
Open and download PDF →Need more than a tool?
Gap analysis, an implementation plan and documentation you can stand behind, for the lower and the higher regime. Get in touch and we will go through where you stand and what is ahead.