NIS2 · CZECH REPUBLIC

The cyber act is in force. Deadlines already run.

Act No. 264/2025 Coll. transposes the NIS2 directive into Czech law and took effect on 1 November 2025. By 8 February 2026, 4,825 organisations had reported to the Office, against an estimate of about six thousand. Below are the scope conditions, deadlines and the incident reporting procedure, each figure with its section.

Act
264/2025 Coll.
In force
1 Nov 2025
Decree
408/2025 Coll.

Both conditions apply at once.

Scope rests on two conditions that must hold at the same time: a sector with a listed service, and the size of the organisation. Placement in a sector alone creates no duty.

Sector

The organisation operates in one of the fifteen sectors listed in Section 4(1)(a) and provides a listed service there under the decree.

Size

It is a medium or large enterprise under Commission Recommendation 2003/361/EC. Alternatively, significance for essential activities or state security suffices (Section 4(1)(b)).

Service list

The specific services and significance criteria are set in the annex to Decree No. 408/2025 Coll. on regulated services. The act itself does not list them (Section 4(2)).

Size-test exemption

State organisational units, territorial self-governing units and the Czech National Bank are not treated as enterprises (Section 7(b)). The size test therefore does not apply to them, which does not remove them from the scope of the act.

Fifteen sectors under Section 4(1)(a).

  • Public administration
  • Energy
  • Manufacturing
  • Food industry
  • Chemical industry
  • Water management
  • Waste management
  • Transport
  • Digital infrastructure and services
  • Financial market
  • Healthcare
  • Science, research and education
  • Postal and courier services
  • Defence industry
  • Space industry

Each deadline runs from something else.

The one-year period for putting measures in place runs only from delivery of the registration decision, not from the day of reporting. The sixty-day reporting period runs by law from the day the conditions are met.

60 days · Report a regulated service

The period runs from the day the organisation meets the conditions. Reports go to the Office via the NUKIB Portal. Section 6(1)

1 year · Put security measures in place

The period runs from delivery of the registration decision, only after reporting. Section 14 lists the measures; a decree sets their content. Section 13(4)

1 year · Start incident reporting

The same one-year run-up applies to the incident reporting duty. Until then the regime described below applies with no sanction impact under this provision. Section 15(4)

Incident reporting under Section 16.

For each step it matters what the period runs from and who receives the report. The Office files the notice of significant impact on state cyberspace; the provider files the rest. The final report counts from the notification, not from the moment of the incident.

DeadlineWhat is filedTo whomProvision
within 24 hours of detectionInitial reportProviderSection 16(1)
within 24 hours of the initial reportNotice of significant impact on state cyberspaceOfficeSection 16(2)
within 72 hours of detectionNotification: updates, initial assessment, impact, indicators of compromise. For trust services the deadline is 24 hours.ProviderSection 16(3)(a)
on request, no fixed deadlineInterim reportProviderSection 16(3)(b)
within 30 days of the notificationFinal report. The period runs from the notification, not from the moment of the incident.ProviderSection 16(3)(c)

Fines under Section 59.

Upper fine limits for providers of a regulated service. For the two highest rates, the higher of the two values applies. Which breach falls into which rate is set by the list of offences directly in Section 59; offences by other persons carry their own rates in Section 60.

CZK 250 million

or 2% of net worldwide annual turnover

CZK 175 million

or 1.4% of net worldwide annual turnover

CZK 100 million

CZK 50 million

CZK 35 million

First find the state. Then the measures.

CIAD Snapshot

An initial assessment with no access to your systems. The output is a 0 to 100 score and a remediation plan with an owner and a deadline. Pricing by scope, on request.

Training for management and teams

The management of the organisation answers for compliance with the act. We train both: the decision-making level and the people who actually operate the measures.

Measure planning and verification

We help sequence organisational and technical steps under Section 14, and after deployment we verify that the measures actually work.

Official sources.

Figures on this page come from the text of Act No. 264/2025 Coll. and NUKIB materials. The binding sources are always the wording of the regulation and the decisions of the Office.

Alongside legal sources we also measure practice: what Czech company websites actually look like is shown by our studies tracking before consent and law firm website security.

Frequent questions on registration and deadlines.

Since when does Act No. 264/2025 Coll. apply?

The act was adopted on 11 June 2025 and took effect on 1 November 2025. It replaced Act No. 181/2014 Coll.; the repeal of Decree No. 317/2014 Coll. on important information systems is set in Section 72.

How do I tell whether we fall under the regulation?

The act builds its scope on two conditions at once: a sector with a listed service (Section 4(1)(a)) and medium or large enterprise size (Section 4(1)(b)). The service list is in the annex to Decree No. 408/2025 Coll. Our two-minute test gives an indicative answer; reporting to the Office is binding.

By when must we report a regulated service?

Within 60 days of the day the organisation meets the conditions (Section 6(1)). Security measures then have one year from delivery of the registration decision (Section 13(4)).

By when is a cyber incident reported?

Initial report within 24 hours of detection, notification within 72 hours of detection, and final report within 30 days of the notification (Section 16). For trust services the notification deadline shrinks to 24 hours. The thirty-day period runs from the notification, not from the moment of the incident.

Does the act apply to municipalities?

Territorial self-governing units are not treated as enterprises under Section 7(b), so the size test does not apply to them. That does not remove them from scope. What matters is whether the municipality or its organisation provides a regulated service under the decree. Details for self-government are on the cybersecurity for municipalities page.

What fines apply?

The top rate under Section 59 is CZK 250 million or 2% of net worldwide annual turnover, whichever is higher. Then follow rates of CZK 175 million or 1.4% of turnover, plus CZK 100, 50 and 35 million. Offences by other persons carry their own rates in Section 60.

How many organisations have reported so far?

As of 8 February 2026, NUKIB recorded 4,825 reporting entities. The original estimate of organisations falling under the new act was about 6,000, so some obliged entities have not reported yet.

FIRST STEP

Find out whether the act covers you.

Ten questions and two minutes show whether reporting a regulated service is worth addressing. If you are unsure, write to office@ciad.cz.