Directive NIS2 European Union
Vyhláška č. 409/2025 Sb. (režim vyšších povinností) · in force since 1 November 2025

Bezpečnostní opatření podle zákona o kybernetické bezpečnosti

NIS2 says what you must achieve, never how you demonstrate it. Czechia answers with ZKB measures. If you operate there, this is what your regulator reads.

Published
Assurance levels
2
Controls at Režim vyšších povinností
25
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

This is binding law, not a voluntary scheme, and there is no certificate at the end of it. Meeting the decree is what compliance with the Czech Cybersecurity Act looks like; no third party certifies it for you, and NÚKIB inspects directly.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 maps closely onto the organisational measures and is the usual way Czech entities build the ISMS the decree requires, but the decree is the operative text and its § are what an inspection follows.

Assurance levels

2 tiers, cumulative


Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.

ZKB measures levels with the number of controls each adds and the cumulative total
Level Adds Cumulative Intended for
Režim nižších povinností Providers of regulated services in the lower-obligations regime
Režim vyšších povinností 25 Providers of regulated services in the higher-obligations regime
Režim nižších povinností

A lighter set, in its own decree (vyhláška č. 410/2025 Sb.). Which regime applies follows from the service you provide, not from your own choice.

Režim vyšších povinností

The full catalogue: an ISMS, named security roles (cybersecurity manager, architect, auditor, asset guarantor), and a cybersecurity audit obligation.

What it is built on

ZKB measures does not invent its own taxonomy. It sits on Zákon č. 264/2025 Sb., o kybernetické bezpečnosti.

Fourteen organisational measures (§ 3–16) and eleven technical ones (§ 17–27), each a numbered paragraph of the decree. The numbering is the identifier.

Mapping

How it covers article 21(2)


Basis

Paragraph-level mapping. Each article 21(2) measure is mapped to the § of vyhláška 409/2025 Sb. whose published heading delivers it. The § numbering is public and stable, so this mapping is as precise as the ISO one.

Limit of this mapping

The headings are unambiguous but the § themselves are detailed: a § match tells you which paragraph to read, not that its requirements are met. The lower-obligations regime has its own decree (410/2025 Sb.) with a lighter set — this mapping is of the higher regime.

Mapped at the level of
decree paragraph (§)
Units in the framework
25
Units carrying article 21(2)
25
Each of the ten risk-management measures of article 21(2), mapped to the decree paragraph (§) units of ZKB measures
Art. 21(2) Measure ZKB measures — decree paragraph (§)
(a) Risk analysis and security policies § 3 § 4 § 6 § 8
(b) Incident handling § 14 § 21 § 22 § 23
(c) Business continuity § 15 § 17 § 26
(d) Supply chain security § 9
(e) Security in acquisition, development and maintenance § 11 § 12 § 24 § 27
(f) Assessing the effectiveness of the measures § 3 § 16
(g) Basic cyber hygiene and cybersecurity training § 4 § 10
(h) Cryptography and encryption § 25
(i) Human resources security, access control and asset management § 5 § 7 § 10 § 13 § 20
(j) Multi-factor authentication and secured communications § 18 § 19
25 decree paragraph (§) units, in full
  • § 3 — Systém řízení bezpečnosti informací — information security management system
  • § 4 — Požadavky na vrcholné vedení — obligations of top management
  • § 5 — Stanovení bezpečnostních rolí — designation of security roles
  • § 6 — Řízení bezpečnostní politiky a dokumentace — security policy and documentation
  • § 7 — Řízení aktiv — asset management
  • § 8 — Řízení rizik — risk management
  • § 9 — Řízení dodavatelů — supplier management
  • § 10 — Bezpečnost lidských zdrojů — human resources security
  • § 11 — Řízení změn — change management
  • § 12 — Akvizice, vývoj a údržba — acquisition, development and maintenance
  • § 13 — Řízení přístupu — access management
  • § 14 — Zvládání kybernetických bezpečnostních událostí — incident handling
  • § 15 — Řízení kontinuity činností — business continuity management
  • § 16 — Provádění auditu kybernetické bezpečnosti — cybersecurity audit
  • § 17 — Fyzická bezpečnost — physical security
  • § 18 — Bezpečnost komunikačních sítí — communication network security
  • § 19 — Správa a ověřování identit — identity management and authentication
  • § 20 — Řízení přístupových práv a oprávnění — access rights and privileges
  • § 21 — Detekce kybernetických bezpečnostních událostí — event detection
  • § 22 — Zaznamenávání událostí — event logging
  • § 23 — Vyhodnocování kybernetických bezpečnostních událostí — event evaluation
  • § 24 — Aplikační bezpečnost — application security
  • § 25 — Kryptografické algoritmy — cryptographic algorithms
  • § 26 — Zajišťování dostupnosti regulované služby — availability of the regulated service
  • § 27 — Zabezpečení průmyslových aktiv — security of industrial assets (OT)
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. ZKB measures is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to ZKB measures and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) ZKB measures ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis § 3 § 4 § 6 § 8 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling § 14 § 21 § 22 § 23 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity § 15 § 17 § 26 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain § 9 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development § 11 § 12 § 24 § 27 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness § 3 § 16 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training § 4 § 10 5.37 6.3 8.7 AT SI CM
(h) Cryptography § 25 8.24 SC
(i) HR, access, assets § 5 § 7 § 10 § 13 § 20 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms § 18 § 19 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Sources

We are not affiliated with NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost. ZKB measures and related marks belong to their owners.

Cart 0