Bezpečnostní opatření podle zákona o kybernetické bezpečnosti
NIS2 says what you must achieve, never how you demonstrate it. Czechia answers with ZKB measures. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
This is binding law, not a voluntary scheme, and there is no certificate at the end of it. Meeting the decree is what compliance with the Czech Cybersecurity Act looks like; no third party certifies it for you, and NÚKIB inspects directly.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 maps closely onto the organisational measures and is the usual way Czech entities build the ISMS the decree requires, but the decree is the operative text and its § are what an inspection follows.
2 tiers, cumulative
Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.
| Level | Adds | Cumulative | Intended for |
|---|---|---|---|
| Režim nižších povinností | — | — | Providers of regulated services in the lower-obligations regime |
| Režim vyšších povinností | — | 25 | Providers of regulated services in the higher-obligations regime |
A lighter set, in its own decree (vyhláška č. 410/2025 Sb.). Which regime applies follows from the service you provide, not from your own choice.
The full catalogue: an ISMS, named security roles (cybersecurity manager, architect, auditor, asset guarantor), and a cybersecurity audit obligation.
What it is built on
ZKB measures does not invent its own taxonomy. It sits on Zákon č. 264/2025 Sb., o kybernetické bezpečnosti.
Fourteen organisational measures (§ 3–16) and eleven technical ones (§ 17–27), each a numbered paragraph of the decree. The numbering is the identifier.
How it covers article 21(2)
Paragraph-level mapping. Each article 21(2) measure is mapped to the § of vyhláška 409/2025 Sb. whose published heading delivers it. The § numbering is public and stable, so this mapping is as precise as the ISO one.
The headings are unambiguous but the § themselves are detailed: a § match tells you which paragraph to read, not that its requirements are met. The lower-obligations regime has its own decree (410/2025 Sb.) with a lighter set — this mapping is of the higher regime.
| Art. 21(2) | Measure | ZKB measures — decree paragraph (§) |
|---|---|---|
| (a) | Risk analysis and security policies | § 3 § 4 § 6 § 8 |
| (b) | Incident handling | § 14 § 21 § 22 § 23 |
| (c) | Business continuity | § 15 § 17 § 26 |
| (d) | Supply chain security | § 9 |
| (e) | Security in acquisition, development and maintenance | § 11 § 12 § 24 § 27 |
| (f) | Assessing the effectiveness of the measures | § 3 § 16 |
| (g) | Basic cyber hygiene and cybersecurity training | § 4 § 10 |
| (h) | Cryptography and encryption | § 25 |
| (i) | Human resources security, access control and asset management | § 5 § 7 § 10 § 13 § 20 |
| (j) | Multi-factor authentication and secured communications | § 18 § 19 |
25 decree paragraph (§) units, in full
- § 3 — Systém řízení bezpečnosti informací — information security management system
- § 4 — Požadavky na vrcholné vedení — obligations of top management
- § 5 — Stanovení bezpečnostních rolí — designation of security roles
- § 6 — Řízení bezpečnostní politiky a dokumentace — security policy and documentation
- § 7 — Řízení aktiv — asset management
- § 8 — Řízení rizik — risk management
- § 9 — Řízení dodavatelů — supplier management
- § 10 — Bezpečnost lidských zdrojů — human resources security
- § 11 — Řízení změn — change management
- § 12 — Akvizice, vývoj a údržba — acquisition, development and maintenance
- § 13 — Řízení přístupu — access management
- § 14 — Zvládání kybernetických bezpečnostních událostí — incident handling
- § 15 — Řízení kontinuity činností — business continuity management
- § 16 — Provádění auditu kybernetické bezpečnosti — cybersecurity audit
- § 17 — Fyzická bezpečnost — physical security
- § 18 — Bezpečnost komunikačních sítí — communication network security
- § 19 — Správa a ověřování identit — identity management and authentication
- § 20 — Řízení přístupových práv a oprávnění — access rights and privileges
- § 21 — Detekce kybernetických bezpečnostních událostí — event detection
- § 22 — Zaznamenávání událostí — event logging
- § 23 — Vyhodnocování kybernetických bezpečnostních událostí — event evaluation
- § 24 — Aplikační bezpečnost — application security
- § 25 — Kryptografické algoritmy — cryptographic algorithms
- § 26 — Zajišťování dostupnosti regulované služby — availability of the regulated service
- § 27 — Zabezpečení průmyslových aktiv — security of industrial assets (OT)
What you already have, for the same measure
Nobody in scope starts from nothing. ZKB measures is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | ZKB measures | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | § 3 § 4 § 6 § 8 | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | § 14 § 21 § 22 § 23 | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | § 15 § 17 § 26 | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | § 9 | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | § 11 § 12 § 24 § 27 | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | § 3 § 16 | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | § 4 § 10 | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | § 25 | 8.24 | SC |
| (i) HR, access, assets | § 5 § 7 § 10 § 13 § 20 | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | § 18 § 19 | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
- https://www.zakonyprolidi.cz/cs/2025-409
- https://portal.nukib.gov.cz/storage/uploads/2025/11/20/videoprenaska-nzkb_uid_691ee0e537a80.pdf
- https://nis2.nukib.gov.cz/
We are not affiliated with NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost. ZKB measures and related marks belong to their owners.