
The short answer: The European NIS2 Directive is implemented in Czechia by the new zákon o kybernetické bezpečnosti č. 264/2025 Sb., effective from 1 November 2025. It applies to companies that provide one of the services listed in the implementing decrees issued by NÚKIB and are at least medium-sized enterprises—roughly, those with 50 or more employees, or whose annual turnover and balance-sheet total both exceed EUR 10 million. For certain services, company size is irrelevant. The Act relies on self-identification: no one will send you a letter, so your company must determine its own status and register with NÚKIB. Most newly regulated companies will fall under the lower-obligation regime—but even that entails registration, security measures under the relevant decree, and incident reporting.
For two years, NIS2 was discussed in the conditional tense—„when it eventually arrives." It is now in force. Since 1 November 2025, zákon č. 264/2025 Sb., o kybernetické bezpečnosti has been effective, replacing zákon č. 181/2014 Sb. and expanding regulation from a few dozen critical-infrastructure entities to thousands of ordinary businesses: manufacturers, food producers, transport operators, chemical companies, IT providers, and hospitals.
Yet the question we hear most often from company directors remains the same: „Does this even apply to us?" This article will help you answer it—and, more importantly, explain what you need to do in practice during 2026.
From a European Directive to Czech Law
NIS2 is EU Directive 2022/2555 on measures for a high common level of cybersecurity. The Directive does not impose obligations on companies by itself—it must be implemented through national legislation. In Czechia, this is zákon č. 264/2025 Sb., together with a set of implementing decrees issued by NÚKIB that define regulated services and specify the required security measures.
The new Act introduces three major changes compared with the previous framework:
- A much broader scope. Regulation no longer focuses solely on the energy sector and government bodies; it now covers entire supply chains across the wider economy.
- Self-identification. Companies must assess for themselves whether they provide a regulated service and, if so, register with NÚKIB. Waiting „until they contact us" is a breach of the law, not a strategy.
- Two obligation regimes. Instead of imposing one stringent standard on everyone, the Act distinguishes between higher- and lower-obligation regimes based on the importance of the service.
Supervision is carried out by NÚKIB—Národní úřad pro kybernetickou a informační bezpečnost (the Czech National Cyber and Information Security Agency). It also operates the registration portal and a self-identification guide that companies can use to make an initial assessment.
How to Determine Whether You Provide a Regulated Service
Two conditions must be met at the same time: what you do and how large your company is.
1. Sector and Service
The implementing decree lists regulated services by sector. These are based on the annexes to the NIS2 Directive and broadly include:
- Sectors of higher criticality: energy, transport, banking and financial-market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, management of ICT services for other companies (MSPs/MSSPs), public administration, and the space sector.
- Other regulated sectors: postal and courier services, waste management, the chemical industry, food production and distribution, manufacturing—including electronics, machinery, motor vehicles, and medical devices—digital services such as online marketplaces, search engines, and social networks, and research.
Beware of one common pitfall: what matters is not the business activity listed in the Commercial Register, but what your company actually does. An engineering company that has added its own online store and logistics operation must be assessed based on all the activities it genuinely performs.
2. Company Size
As a rule, the Act applies to medium-sized and large enterprises. The threshold follows the European definition: broadly, 50 or more employees, or annual turnover and a balance-sheet total both exceeding EUR 10 million. Under the financial test, both criteria must be exceeded; high turnover alone is not enough if the balance-sheet total remains below the threshold. Linked and partner enterprises must also be included in the calculation—a subsidiary with twenty employees may therefore fall within the scope because of the size of the wider group. Certain services, including parts of digital infrastructure and public administration, are regulated regardless of company size.
If you meet both conditions, § 6 odst. 1 of the Act requires you to notify NÚKIB of the service within 60 days of the date on which the conditions were met, using its portal. For companies that already met the conditions when the Act took effect on 1 November 2025, the deadline expired on 31 December 2025. Anyone who missed it should register as soon as possible; waiting will only prolong the non-compliance. For each service, the decree also specifies whether it falls under the higher- or lower-obligation regime.
What the Lower-Obligation Regime Involves
Most newly regulated companies—typically those in manufacturing, food production, chemicals, waste management, and courier services—will fall under the lower-obligation regime. It has deliberately been designed to be manageable even for businesses without their own security department. However, it does not mean „we do not have to do anything." Specifically, it requires:
- Registration and maintenance of contact details with NÚKIB, including the reporting of any changes.
- Security measures under vyhláška č. 410/2025 Sb. (o bezpečnostních opatřeních poskytovatele regulované služby v režimu nižších povinností): access and identity management, backup and recovery, updates and vulnerability management, basic supplier management, incident handling, business continuity, and staff training.
- Reporting cybersecurity incidents. The deadlines are set out in § 16 of the Act: an initial report within 24 hours of detection; for an incident with a significant impact, a notification including an initial assessment within 72 hours; and a final resolution report within 30 days of that notification. Without a procedure prepared in advance, meeting these deadlines over a weekend is virtually impossible.
- Responding to NÚKIB measures—warnings, countermeasures, and, where applicable, corrective measures resulting from an inspection.
One important detail that company management often underestimates is that responsibility for cybersecurity rests with senior management and cannot be delegated entirely to IT staff or an external provider. Signing an outsourcing agreement does not remove that responsibility. It works in much the same way as BOZP obligations in offices and IT companies: a supplier may carry out the work, but the company’s governing body remains accountable.
And the penalties? The Czech Act states them in Czech koruna rather than the euros used in the Directive. Under § 59 of the Act, infringements in the higher-obligation regime may result in a fine of up to CZK 250,000,000 or up to 2% of the company’s net worldwide annual turnover, whichever is higher. In the lower-obligation regime, the maximum is CZK 175,000,000 or 1.4% of turnover. In practice, NÚKIB will almost certainly begin with corrective measures rather than maximum fines—but „nothing can happen to us" is no longer a credible argument.
A Cybersecurity Audit Is Not a Cabling Audit
The word „audit" now appears in almost every service proposal, so it is worth clarifying the terminology to ensure you do not buy something other than what you actually need.
An NIS2 compliance audit (gap analysis) compares the company’s current state against the requirements of the Act and its implementing decrees: risk management, policies, roles and responsibilities, supplier contracts, incident handling, backups, and training. The result is a list of gaps and a plan for closing them. Much of the work concerns processes and documentation, not hardware.
A computer network and cabling audit examines the physical and technical layer: network cabinets, switches, Wi-Fi, VLANs, firewalls, and network documentation. By itself, it cannot ensure NIS2 compliance—but without it, compliance is little more than a pretence, because you cannot protect a network you have not mapped. Guest Wi-Fi connected to the same network as the accounting system is a finding that no policy document can fix.
In practice, combining the two makes sense: first establish where the company genuinely stands, and only then prepare the documentation. That is exactly how we conduct our initial IT audit and gap analysis for businesses. We guide you through self-identification, the technical environment, and internal processes, producing a prioritised plan rather than a hundred-page report destined for a drawer. This means you do not have to diagnose your most serious NIS2 exposure in isolation.
What to Complete in 2026
The Act has been effective since 1 November 2025, and the deadlines are already running. A sensible plan for 2026 looks like this:
- Self-identification (immediately). Review the implementing decree and the NÚKIB self-identification guide. Document the result in writing even if you conclude that you are „not regulated"—it will be useful during an inspection or when responding to a customer’s enquiry.
- Registration (immediately—the deadline has already passed for many companies). If you provide a regulated service, register through the NÚKIB portal. Companies that already met the conditions on 1 November 2025 were required to submit the notification under § 6 odst. 1 by 31 December 2025. Delaying will not improve the situation; it will only reduce the time available for the next steps.
- Gap analysis (first half of 2026). Identify the difference between your current state and the requirements of the decree applicable to your regime. Under § 13 odst. 4, the security measures must be operational no later than one year after delivery of the registration decision. Companies registered around the turn of the year will therefore need to complete their measures during 2026.
- Quick wins before paperwork. Backups following the 3-2-1 rule with one copy stored off-site, multi-factor authentication, updates, and network segmentation. These measures start protecting you tomorrow—ransomware on a company NAS will not wait for you to finish writing a policy.
- An incident-reporting procedure. Define who identifies an incident, who reports it to NÚKIB, and who communicates with customers. Put it on a single printed A4 page—if your server has been encrypted, you will not be able to access the intranet.
- Get senior management involved. The company’s governing body must approve and understand security decisions. One hour a year spent evaluating risks is the bare minimum that will matter both during an inspection and when an incident occurs.
What If the Act Does Not Apply to You?
Even a company with fewer than 50 employees outside the regulated sectors will encounter NIS2 indirectly. Regulated entities must manage supply-chain security, so their requirements will flow downstream in the form of questionnaires, contractual clauses, requirements for MFA, or evidence of backups. Any company supplying a manufacturer, hospital, or bank is likely to receive a security questionnaire sooner than expected—and having a prepared response is a competitive advantage, not needless bureaucracy.
If you are unsure which category your company falls into, or if you want a gap analysis with a concrete plan instead of vague scare tactics, contact us. We will guide you through both self-identification and the technical side—from the network cabinet to the security policy.
Frequently Asked Questions
Does NIS2 Apply to a Company with Fewer Than 50 Employees?
As a rule, not directly, provided the company does not also exceed the financial thresholds and does not provide a service regulated regardless of size, such as certain digital-infrastructure services. However, remember that linked and partner enterprises within the group are counted together, and that regulated customers may impose security requirements indirectly.
How Can I Find Out Whether We Provide a Regulated Service?
Review the implementing decree for zákon č. 264/2025 Sb. and the self-identification guide available through the NÚKIB portal. Assess the activities you actually perform, not the entry in the Commercial Register. Document the outcome of the self-identification process; if the result is borderline, an independent gap analysis can help.
What Happens If We Do Not Register and „Wait and See"?
Registration is a statutory obligation with a short deadline, not an optional step. For companies regulated from the date the Act took effect, the deadline expired on 31 December 2025. Under § 59, zákon č. 264/2025 Sb. provides for fines of up to CZK 250 million or 2% of worldwide turnover—or, in the lower-obligation regime, up to CZK 175 million or 1.4%. The more realistic immediate risks are corrective measures imposed following a NÚKIB inspection and the loss of contracts with customers that require proof of compliance during procurement.
Is ISO 27001 Certification Enough?
It helps, but it does not establish compliance by itself. Registration, incident reporting, and the specific measures required by the Czech decree—vyhláška č. 410/2025 Sb. for the lower-obligation regime—also apply to certified companies. A properly implemented ISO system will, however, cover most of the requirements, so the gap analysis is usually brief: it maps the remaining differences instead of rebuilding everything from scratch.
When Must We Report an Incident?
The deadlines are set out in § 16 of zákon č. 264/2025 Sb.: an initial report must be submitted without undue delay and no later than 24 hours after detection; for an incident with a significant impact, a notification containing an initial assessment must follow within 72 hours, and a final resolution report within 30 days of that notification. In practice, this means deciding in advance who will assess the incident and who will submit the report, including cover for holidays and other absences.