NIS2 · National implementation
NIS2 in Czechia
Czechia transposed NIS2 through Act No 264/2025 Coll. on Cybersecurity, a full replacement of the 2014 act, in force since 1 November 2025.
- National law
- Zákon č. 264/2025 Sb. o kybernetické bezpečnosti
- Act No 264/2025 Coll. on Cybersecurity
- Status
- In force
- In force
- 1 November 2025
- Authority
- NÚKIB
Supervision
NÚKIB (Národní úřad pro kybernetickou a informační bezpečnost) is the single authority and runs a dedicated NIS2 portal with a scope self-check. Entities register via the portal within the statutory window from qualifying.
What is specific to Czechia
The Czech act splits obligations into two regimes: a lower regime (basic duties for important-type entities) and a higher regime (fuller obligations for essential-type entities), with detail in NÚKIB decrees. It also carries a supply-chain security mechanism allowing scrutiny of high-risk suppliers for critical infrastructure. NÚKIB's guidance culture is strong — its portal materials are the operative compliance manual.
Official sources
Primary references: the national statute book at www.e-sbirka.cz and the national cybersecurity authority at nukib.gov.cz.
NIS2 in Czechia: frequently asked questions
Last reviewed:
Related reading
Definitions
