Sector
The organisation operates in one of the fifteen sectors listed in Section 4(1)(a) and provides a listed service there under the decree.
Act No. 264/2025 Coll. transposes the NIS2 directive into Czech law and took effect on 1 November 2025. By 8 February 2026, 4,825 organisations had reported to the Office, against an estimate of about six thousand. Below are the scope conditions, deadlines and the incident reporting procedure, each figure with its section.
Scope rests on two conditions that must hold at the same time: a sector with a listed service, and the size of the organisation. Placement in a sector alone creates no duty.
The organisation operates in one of the fifteen sectors listed in Section 4(1)(a) and provides a listed service there under the decree.
It is a medium or large enterprise under Commission Recommendation 2003/361/EC. Alternatively, significance for essential activities or state security suffices (Section 4(1)(b)).
The specific services and significance criteria are set in the annex to Decree No. 408/2025 Coll. on regulated services. The act itself does not list them (Section 4(2)).
State organisational units, territorial self-governing units and the Czech National Bank are not treated as enterprises (Section 7(b)). The size test therefore does not apply to them, which does not remove them from the scope of the act.
The one-year period for putting measures in place runs only from delivery of the registration decision, not from the day of reporting. The sixty-day reporting period runs by law from the day the conditions are met.
The period runs from the day the organisation meets the conditions. Reports go to the Office via the NUKIB Portal. Section 6(1)
The period runs from delivery of the registration decision, only after reporting. Section 14 lists the measures; a decree sets their content. Section 13(4)
The same one-year run-up applies to the incident reporting duty. Until then the regime described below applies with no sanction impact under this provision. Section 15(4)
For each step it matters what the period runs from and who receives the report. The Office files the notice of significant impact on state cyberspace; the provider files the rest. The final report counts from the notification, not from the moment of the incident.
| Deadline | What is filed | To whom | Provision |
|---|---|---|---|
| within 24 hours of detection | Initial report | Provider | Section 16(1) |
| within 24 hours of the initial report | Notice of significant impact on state cyberspace | Office | Section 16(2) |
| within 72 hours of detection | Notification: updates, initial assessment, impact, indicators of compromise. For trust services the deadline is 24 hours. | Provider | Section 16(3)(a) |
| on request, no fixed deadline | Interim report | Provider | Section 16(3)(b) |
| within 30 days of the notification | Final report. The period runs from the notification, not from the moment of the incident. | Provider | Section 16(3)(c) |
Upper fine limits for providers of a regulated service. For the two highest rates, the higher of the two values applies. Which breach falls into which rate is set by the list of offences directly in Section 59; offences by other persons carry their own rates in Section 60.
or 2% of net worldwide annual turnover
or 1.4% of net worldwide annual turnover
An initial assessment with no access to your systems. The output is a 0 to 100 score and a remediation plan with an owner and a deadline. Pricing by scope, on request.
The management of the organisation answers for compliance with the act. We train both: the decision-making level and the people who actually operate the measures.
We help sequence organisational and technical steps under Section 14, and after deployment we verify that the measures actually work.
Figures on this page come from the text of Act No. 264/2025 Coll. and NUKIB materials. The binding sources are always the wording of the regulation and the decisions of the Office.
Alongside legal sources we also measure practice: what Czech company websites actually look like is shown by our studies tracking before consent and law firm website security.
The act was adopted on 11 June 2025 and took effect on 1 November 2025. It replaced Act No. 181/2014 Coll.; the repeal of Decree No. 317/2014 Coll. on important information systems is set in Section 72.
The act builds its scope on two conditions at once: a sector with a listed service (Section 4(1)(a)) and medium or large enterprise size (Section 4(1)(b)). The service list is in the annex to Decree No. 408/2025 Coll. Our two-minute test gives an indicative answer; reporting to the Office is binding.
Within 60 days of the day the organisation meets the conditions (Section 6(1)). Security measures then have one year from delivery of the registration decision (Section 13(4)).
Initial report within 24 hours of detection, notification within 72 hours of detection, and final report within 30 days of the notification (Section 16). For trust services the notification deadline shrinks to 24 hours. The thirty-day period runs from the notification, not from the moment of the incident.
Territorial self-governing units are not treated as enterprises under Section 7(b), so the size test does not apply to them. That does not remove them from scope. What matters is whether the municipality or its organisation provides a regulated service under the decree. Details for self-government are on the cybersecurity for municipalities page.
The top rate under Section 59 is CZK 250 million or 2% of net worldwide annual turnover, whichever is higher. Then follow rates of CZK 175 million or 1.4% of turnover, plus CZK 100, 50 and 35 million. Offences by other persons carry their own rates in Section 60.
As of 8 February 2026, NUKIB recorded 4,825 reporting entities. The original estimate of organisations falling under the new act was about 6,000, so some obliged entities have not reported yet.
Ten questions and two minutes show whether reporting a regulated service is worth addressing. If you are unsure, write to office@ciad.cz.