NIS2 · National implementation

NIS2 in Czechia

Czechia transposed NIS2 through Act No 264/2025 Coll. on Cybersecurity, a full replacement of the 2014 act, in force since 1 November 2025.

National law
Zákon č. 264/2025 Sb. o kybernetické bezpečnosti
Act No 264/2025 Coll. on Cybersecurity
Status
In force
In force
1 November 2025
Authority
NÚKIB

Supervision

NÚKIB (Národní úřad pro kybernetickou a informační bezpečnost) is the single authority and runs a dedicated NIS2 portal with a scope self-check. Entities register via the portal within the statutory window from qualifying.

What is specific to Czechia

The Czech act splits obligations into two regimes: a lower regime (basic duties for important-type entities) and a higher regime (fuller obligations for essential-type entities), with detail in NÚKIB decrees. It also carries a supply-chain security mechanism allowing scrutiny of high-risk suppliers for critical infrastructure. NÚKIB's guidance culture is strong — its portal materials are the operative compliance manual.

Official sources

Primary references: the national statute book at www.e-sbirka.cz and the national cybersecurity authority at nukib.gov.cz.

NIS2 in Czechia: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states