NIS2 in Czechia
What binds you in Czechia is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Zákon č. 264/2025 Sb., o kybernetické bezpečnosti
The act replaced the 2014 Cybersecurity Act outright rather than amending it, and it works through implementing decrees: 408/2025 Sb. (regulated services), 409/2025 Sb. (security measures, higher-obligations regime), 410/2025 Sb. (security measures, lower regime) and 334/2025 Sb. (the NÚKIB portal). The act alone will not tell you what to implement.
This is not the article you read in the directive
Which regime applies follows from the service you provide, not from your size or your own preference. Self-identification is the first task, and the deadline for implementing the measures runs one year from registration.
Bezpečnostní opatření podle zákona o kybernetické bezpečnosti — Vyhláška č. 409/2025 Sb. (režim vyšších povinností)
in force since 1 November 2025, published by NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost. Built on Zákon č. 264/2025 Sb., o kybernetické bezpečnosti.
Czechia has the most usable national catalogue after CyFun: 25 numbered paragraphs of vyhláška 409/2025 Sb., fourteen organisational and eleven technical. It is binding law with no certificate at the end — NÚKIB inspects directly. Read the decree, not a summary of the act.
A label is not compliance
This is binding law, not a voluntary scheme, and there is no certificate at the end of it. Meeting the decree is what compliance with the Czech Cybersecurity Act looks like; no third party certifies it for you, and NÚKIB inspects directly.
ZKB measures in full — levels, controls and what it does not cover →
Who supervises you
NÚKIB is the competent authority designated by Czechia. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to GovCERT.CZ, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Czechia legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.