Czech Republic - Cybersecurity Act (264/2025)
Act on Cybersecurity
Zákon o kybernetické bezpečnosti
Czech Republic
RAI-CZ-NA-CZOKBXX-2025Act No. 264/2025 Sb. modernises Czech cybersecurity law by transposing the EU NIS2 Directive into national law. It expands the scope of regulated entities across critical sectors, establishes a self‑identification and registration regime through NÚKIB, imposes risk‑management and incident‑reporting obligations, and creates enforcement measures including administrative fines and coercive penalties.
Summary
Read full text ↗Plain English
Overview
The Act on Cybersecurity (Act No. 264/2025 Sb.) establishes a modern, NIS2‑aligned Czech regulatory framework for the protection of the national cyber‑space and the resilience of services critical to society and the economy. Adopted on 11 June 2025 and published in the Collection of Laws on 4 August 2025, it entered into force on 1 November 2025. The Act expands sectoral coverage, introduces a self‑identification and registration model via the official NÚKIB portal and differentiates obligations by significance and size through a two‑tier regime. The Act gives the National Cyber and Information Security Office (NÚKIB) broad supervisory, investigative and enforcement powers and coordinates reporting with the national CERT and sectoral regulators. For the official consolidated text see Zákon č. 264/2025 Sb. (zakonyprolidi) and for regulator guidance and operational details see the NÚKIB regulation and portal pages at NÚKIB - Regulation and Control.
Definitions
The Act defines key terms that structure scope and obligations, including "regulated service" (services meeting statutory criteria in listed sectors), "provider of a regulated service", "regime of higher obligations" (entities of strategic, essential significance) and "regime of lower obligations" (entities of important significance), "cybersecurity incident" (events with cyber origin causing or likely to cause operational, financial or integrity harm), "critical information infrastructure" and "national CERT". Definitions align closely with NIS2 language to ensure interoperability with EU reporting and certification instruments. The detailed statutory definitions are set out in the opening sections and in implementing regulations and are essential for applying thresholds and reporting duties.
Governance and Institutional Framework
The Act assigns central supervisory responsibility to the National Cyber and Information Security Office (NÚKIB) which manages registration, oversight, incident evaluation and enforcement. NÚKIB operates in coordination with the National CERT (GovCERT/Národní CERT) for incident intake, technical support and international exchange. Sectoral regulators (e.g., the Czech National Bank in finance, health ministry in healthcare, Energy Regulatory Office in energy) retain parallel powers for sector‑specific supervision and can cooperate with NÚKIB under memoranda and statutory provisions. The Act authorises NÚKIB to maintain public registers, issue binding reactivemeasures and general measures, require supplier risk mitigation, order audits, demand documentation and to apply administrative sanctions. The law also frames interagency cooperation and data‑sharing protocols to ensure confidential information is protected while enabling effective oversight; see NÚKIB guidance at NÚKIB - Regulation and Control and practical portal instructions at the NÚKIB Portal portal.nukib.gov.cz.
Key Focus Areas
The Act concentrates on (1) scope and registration: organisations operating in 15 broad sectors must self‑identify and, if criteria are met, register regulated services through the NÚKIB portal within statutory deadlines; (2) risk management: providers must implement governance, asset and vulnerability management, supplier and supply‑chain risk management, cryptography and patch management, backup and continuity planning; (3) incident reporting and response: the Act stipulates initial notification timelines (without undue delay; initial reporting for many incidents expected within 24 hours) and follow‑up reporting, plus cooperation with NÚKIB and CERTs for mitigation and coordinated disclosure; (4) accountability and corporate governance: statutory responsibility sits with management and boards, including obligations to ensure resources, training and management oversight; (5) supervision and enforcement: NÚKIB can issue orders, impose fines and coercive measures and require remediation plans; (6) transparency: certain reporting, evidence retention and possible public disclosure of systemic weaknesses or sanctions are foreseen; and (7) international cooperation and alignment with EU cyber certification frameworks. Extensive implementing measures and sectoral rules clarify thresholds and technical details.
Implementation Framework
The Act sets an implementation architecture combining primary law with secondary instruments: NÚKIB implementing decrees, technical standards and operational guidelines, plus sectoral regulations and cooperation agreements. Entities that meet statutory thresholds must self‑identify (samoidentifikace) and register regulated services via the NÚKIB portal; NÚKIB classifies services into higher or lower obligation regimes, issues registration certificates and publishes certain registry data internally for supervisory use. Providers are obliged to maintain documented information security management systems (ISMS), keep audit trails of decisions and incidents, perform periodic audits and penetration tests, engage in supplier due diligence and provide contact and operational information to NÚKIB. Transitional and grandfathering rules allow previously regulated entities to map existing duties into the new two‑tier system; see the transitional provisions in §71 and related articles. The practical operational steps and templates for registration, notification and coordination are published by NÚKIB on the portal; see NÚKIB Portal and NÚKIB’s "Regulation and Control" page at NÚKIB.
Monitoring and Evaluation
NÚKIB is charged with monitoring compliance through self‑reporting, mandatory notifications, targeted inspections and evidence required during audits. The Act requires NÚKIB to maintain registers and an evidence database for incidents, vulnerabilities and enforcement actions. Periodic review cycles, reporting obligations and evaluation clauses are built into the law to align national measures with EU monitoring and to permit NÚKIB to revise technical guidance and thresholds. The law also obliges providers to keep records of security measures, incident handling and supplier assessments for supervisory review. The Act foresees cooperation with sectoral regulators who may conduct parallel checks and share findings with NÚKIB under confidentiality safeguards.
Penalties, Liability, and Appeals
The Act defines administrative sanctions and misdemeanor (administrative offence) regimes for non‑compliance. The statutory scheme sets maximum fines for individual administrative offences (for example, fines up to CZK 50,000,000 for the most severe breaches in specified categories, reduced ceilings for lesser offences and specific caps for procedural failures) and allows NÚKIB to impose coercive fines (donucovací pokuty) and enforcement measures up to CZK 10,000,000 or an amount tied to turnover in some cases. The Act also empowers NÚKIB to suspend or restrict operations, require remedial measures and in extreme cases to take action affecting corporate statutory bodies when management repeatedly or seriously fails to meet obligations. Decisions of NÚKIB are subject to administrative appeal and judicial review under Czech administrative law; the Act specifies special procedural rules for enforcement proceedings and temporary measures (see the Act's provisions on penalties, coercive fines and administrative procedure). For detailed statutory fines and articles see the consolidated text at Zákon č. 264/2025 Sb..
Relationship to Other Instruments
The Act operates alongside and amends a range of existing Czech laws (including sectoral statutes) so that responsibilities for cyber‑security are coherent across banking, energy, healthcare and communications law. It transposes Directive (EU) 2022/2555 (NIS2) into national law and references EU cyber certification regulation (Regulation (EU) 2019/881). The Act modifies and integrates previous domestic cybersecurity duties and creates cross‑references that require updates to other statutes (many of which were amended by implementing acts such as Act No. 265/2025 Sb.). Sectoral regulators maintain parallel powers where sector law demands it; the Act specifies cooperation mechanisms and data‑sharing rules to avoid conflicting supervision.
International Alignment
The Act intentionally aligns Czech obligations with NIS2 and relevant EU instruments to enable interoperability within the EU incident reporting, information sharing and certification frameworks. It establishes provisions for sharing incident and vulnerability data with international partners and ENISA where appropriate, while safeguarding confidentiality under Czech law. The Act also contemplates alignment with EU cyber certification schemes and allows NÚKIB to participate in EU‑level certification and coordination activities. Cross‑border notification rules reflect NIS2 requirements regarding incidents with potential or actual cross‑border impact.
Implementation Timeline
| Event | Date | Notes |
|---|---|---|
| Adoption by Parliament | 2025-06-11 | Act text adopted by Parliament (date on Act). |
| Promulgation (Collection of Laws) | 2025-08-04 | Published as No. 264/2025 Sb. |
| Entry into force | 2025-11-01 | Main effective date for the Act. |
| Initial self-identification window | 2025-11-01 to 2025-12-31 | 60‑day registration window for entities in scope at the moment of effect; subsequent events trigger 60‑day deadlines. |
| Registration reporting of contacts | Within 30 days after registration | Providers must report authorised contact persons and technical data after registration. |
| Incident reporting initial timeframe | Immediate; initial report normally within 24 hours | See §16 and §17 for procedures and follow-up timelines. |
| Deadline to start reporting after registration | Within 1 year of registration decision | Providers begin fulfilling incident reporting duties for each registered service no later than one year after registration decision. |
Compliance Checklist
| Requirement | Action | Evidence |
|---|---|---|
| Self-identify regulated services | Assess service portfolio; submit registration via NÚKIB portal | Portal receipt; registration certificate |
| Appoint responsible persons | Designate cybersecurity contact(s) and record contacts in portal | Written appointment, contact details filed with NÚKIB |
| Implement risk management | Adopt ISMS, asset inventory, supply‑chain assessments | Risk register; audits; policies |
| Incident reporting | Establish detection, triage and reporting workflows | Incident logs; notification records; timestamps |
| Vulnerability and disclosure procedures | Adopt coordinated disclosure policy and reporting path | Policy documents; disclosure logs |
| Documentation & retention | Maintain audit‑grade records and evidence for supervisory checks | Retention logs; exportable evidence packs |
Sources and References
| Source | Type |
|---|---|
| Zákon č. 264/2025 Sb., Act on Cybersecurity (consolidated text) | Primary Source |
| NÁRODNÍ ÚŘAD PRO KYBERNETICKOU A INFORMAČNÍ BEZPEČNOST (NÚKIB) - Regulation and Control | Primary Source (Regulator Guidance) |
| CSIRT.cz - Guidance on changes under the new Act | Primary/Operational Guidance |
The Czech Act on Cybersecurity, effective November 1, 2025, significantly expands and modernises national cybersecurity requirements, primarily targeting organizations providing critical services across 15 key sectors.
This new law implements the European Union's NIS2 Directive, placing obligations on a broad range of entities, from energy and transport to healthcare and digital infrastructure. If your organization provides a "regulated service" within these sectors and meets certain criteria, you are likely in scope. The law differentiates between "higher obligations" for strategically essential entities and "lower obligations" for those of important significance, tailoring the compliance burden.
Key requirements include: - **Self-identification and Registration:** You must proactively assess if your services fall under the Act and register them with the National Cyber and Information Security Office (NÚKIB) via their portal. The initial registration window runs from November 1 to December 31, 2025. - **Robust Risk Management:** Implement comprehensive cybersecurity measures covering governance, asset and vulnerability management, supply chain security, cryptography, and business continuity planning. - **Incident Reporting:** Establish procedures to detect and report cybersecurity incidents to NÚKIB and the national CERT without undue delay, with initial reports often expected within 24 hours. - **Accountability:** Senior management and boards are explicitly responsible for ensuring adequate resources, training, and oversight for cybersecurity.
The Act became effective on November 1, 2025, with the initial self-identification period closing at the end of the year. NÚKIB holds extensive supervisory and enforcement powers. Non-compliance can lead to substantial administrative fines, potentially up to CZK 50,000,000 for severe breaches, or amounts tied to turnover. NÚKIB can also impose coercive fines, suspend operations, or require remedial actions.
A crucial point for businesses is the *self-identification* requirement. Unlike some regulations where authorities identify you, here, the onus is on your organization to determine if it's in scope and to register proactively. Failing to do so can lead to penalties even before NÚKIB has formally engaged.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
Related Regulations
Commission Cybersecurity Resilience and Capabilities Package 2026
European Union89% similar
National Cybersecurity Strategy 2021–2025
Slovakia87% similar
Cyber Security Act 2024
Malaysia87% similar
Ley N° 21.663 — Ley Marco de Ciberseguridad (Framework Law on Cybersecurity and Critical Information Infrastructure)
Chile87% similar
“Kiberxavfsizlik to‘g‘risida”gi O‘zbekiston Respublikasi Qonuni
Uzbekistan86% similar
© Regulations.AI — created on 13-Jun-2026