Checked on September 27, 2026
NIS2 in Czechia
How Czechia applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- In force
- National law
- Cybersecurity Act · Zákon č. 264/2025 Sb., o kybernetické bezpečnosti · from November 1, 2025
- Competent authority
- National Cyber and Information Security Agency (NUKIB) (Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB))
- National CSIRT
- NÚKIB (governmental CERT) and national CSIRT (CSIRT.CZ)
- Registration
- Required · Portal · deadline December 31, 2025
Self-identification (higher/lower obligation regime); report provision of a regulated service via the NÚKIB portal within 60 days of 2025-11-01.
- Incident reporting
- Significant incidents to NÚKIB: initial notification within 24h, full report within 72h (24h for trust services), final report per Directive.
- National specifics
- Two regimes: higher obligations (essential) and lower obligations (important); security measures due within 1 year of effect.
- Fines up to CZK 250m or 2% of turnover (higher regime), CZK 175m or 1.4% (lower regime).
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.