Registration
Assess whether the municipality or its organisations provide a regulated service, and report it to the Authority via the NÚKIB Portal within 60 days of meeting the conditions (Section 6(1)).
Act No. 264/2025 Coll. transposes the NIS2 directive into Czech law and also covers municipalities and subsidised organisations. Ten questions and two minutes will tell you whether it likely covers you too. Below is what the Act requires of municipalities, within which deadlines, and how to comply without an extra binder. The test itself is in Czech.
This is not just a job for the IT administrator. The Act wants management accountability, incident procedures, and records showing the municipality actually manages risk.
Assess whether the municipality or its organisations provide a regulated service, and report it to the Authority via the NÚKIB Portal within 60 days of meeting the conditions (Section 6(1)).
Within one year of delivery of the registration decision, put organisational and technical measures in place. Section 14 of the Act lists them; a decree sets out their content (Section 13(4)).
Cyber incidents are reported to the Authority within the time limits of Section 16: an early warning within 24 hours of detection, a notification within 72 hours of detection, and a final report within 30 days of the notification.
Management of the organisation is responsible for compliance, not just the IT administrator.
An initial assessment without access to municipal systems. The output is a score of 0 to 100 and a remediation plan with an owner and a deadline. Priced by scope, quoted on request.
From safe AI use to a programme for management. Practical training for clerks, IT administrators and leadership.
We help prioritise steps under Section 14, assign owners, and verify after implementation that the measures actually work.
The goal is not a folder of documents. The goal is concrete risks, a name behind every measure, and verification that the measures really work.
The municipality or its subsidised organisation takes a short NIS2 test to find out whether registering with NÚKIB makes sense.
CIAD checks publicly visible exposure, the website, email, basic AI rules and incident readiness.
The output is a prioritised list of steps with an owner, a deadline and an explanation municipal leadership can understand.
Training for the office and ongoing verification follow the fixes, so the changes last through staff and system changes.
What matters is the type of service provided, not the size of the office. Under Section 7(b), municipalities and their organisations are not considered an enterprise, so the size test does not apply to them. What decides is whether the municipality or its organisation provides a regulated service under Decree No. 408/2025 Coll. The test at /nis2-test/ gives an indicative answer; registration with NÚKIB is binding.
The Act is effective from 1 November 2025. A regulated service must be reported within 60 days of meeting the conditions, and the one-year period for putting measures in place runs from delivery of the registration decision. The sooner a municipality finds out whether it falls under the regulation, the calmer the schedule.
We quote on request. The scope of the Snapshot and of further steps depends on the size of the office, the number of organisations, and whether the municipality provides a regulated service.
Ten questions will show whether the municipality should deal with NÚKIB registration or whether basic cyber hygiene is enough for now. The test is in Czech. If you are unsure, write to office@ciad.cz.