What is NIS2 and Act No. 264/2025 Coll.?
Published: 16. 10. 2025 | Author: Ing. Vít Vomáčko | NIS2OK.cz
NIS2 - Network and Information Security Directive 2 - is a European directive (EU 2022/2555) that significantly expands cybersecurity obligations for thousands of organisations across the European Union. In the Czech Republic, it has been implemented. Act No. 264/2025 Coll. On Cybersecuritywhich came into force on 17 October 2025.
If your company operates in a critical sector and is of medium or larger size, Act No. 264/2025 Coll. Will almost certainly apply to you. Failure to comply may result in fines of up to 250 million Kč or 2% of global turnover, as well as personal liability for management.
From NIS1 to NIS2: what has changed?
The original NIS Directive (EU 2016/1148) from 2016 applied only to a narrow circle of so-called operators of essential services, energy, transport, finance, healthcare and digital infrastructure, and only to major players. Practice has shown that cyber threats respect far fewer boundaries and the medium-sized enterprise sector remained entirely unregulated.
NIS2 fundamentally changes this situation. The number of regulated entities in the Czech Republic has risen from around 300 to an estimated 6,000 to 9,000 organisations. The expansion covers both the number of sectors (adding food production, waste management, critical product manufacturing and the space industry) and the size threshold, medium-sized enterprises with 50 or more employees are now included.
A major new feature is also direct liability of statutory bodies. The company's management cannot delegate cybersecurity "to IT" and thereby absolve itself of responsibility. Management must approve cybersecurity measures, supervise them and undergo regular training.
Act 264/2025 Coll., Czech implementation of NIS2 OK
The Cybersecurity Act No. 264/2025 Coll. Replaced the original Act No. 181/2014 Coll. And transposed NIS2 into the Czech legal system. The Act defines two types of regulated entities:
- ✓Essential Entities - larger organisations in highly critical sectors (energy, transport, healthcare, digital infrastructure, banking). They are subject to stricter supervision and higher penalties.
- ✓Important entities - medium-sized enterprises in other regulated sectors or smaller entities in highly critical sectors. Supervision is more reactive, sanctions are lower, but obligations are almost identical.
Supervision of compliance with the Act is carried out by NÚKIB (National Cyber and Information Security Authority), which is authorised to conduct audits, issue binding instructions and impose sanctions.
Who does Act No. 264/2025 Coll. Concern?
The basic criterion is a combination business sector and organisation size. The law applies to entities meeting both conditions simultaneously.
Size criteria
| Category | Employees | Turnover or balance sheet total |
|---|---|---|
| Medium-sized enterprise | 50 - 249 | 10 - 50 million EUR |
| Large enterprise | 250 and more | over 50 mil. EUR |
The exception is the so-called critical infrastructure - size is irrelevant. If you operate backbone internet infrastructure, a critical domain registry or a similar service, NIS2 OK applies to you regardless of the number of employees.
Regulated sectors
NIS2 distinguishes highly critical sectors (Annex I) and other critical sectors (Annex II):
Highly critical (Annex I)
- • Energy sector (electricity, gas, oil, district heating)
- • Transport (air, rail, water, road)
- • Banking and financial infrastructure
- • Healthcare and pharmaceutical manufacturing
- • Drinking water and wastewater
- • Digital infrastructure (ISP, DNS, data centres)
- • Public administration
- • Space industry
Other critical (Annex II)
- • Postal and courier services
- • Waste handling
- • Manufacturing (chemicals, foodstuffs, medical devices, electronics, engineering)
- • Digital providers (e-commerce, search engines, social networks)
- • Research
- • Food industry
What must regulated organisations comply with?
Act No. 264/2025 Coll. Does not specify particular technical solutions but requires systematic approach to cybersecurity management to a level commensurate with the risk. In practice, this means:
1. Appointment of a cybersecurity manager
Every regulated entity must appoint a responsible person. cybersecurity manager (CSM). This person need not be an internal employee; the role can also be fulfilled externally via outsourcing. The KB Manager must possess appropriate professional competence and have direct access to the organisation's management. If you do not have an internal candidate, a solution could be, for example, nis2manager.cz - a platform for outsourcing the CISO role.
2. Risk management and security policies
The organisation must carry out a formal risk analysis for their information and communication systems, document it and update it regularly. Based on the analysis, it is necessary to introduce and maintain security policies covering:
- •Access control and authentication (MFA, privileged account management)
- •Backup and recovery after an incident (BCM/DRP)
- •Securing the supply chain and third parties
- •Data encryption and protection
- •Physical security
- •Vulnerability and patch management
3. Reporting security incidents
The Act introduces strict deadlines for reporting cyber incidents. Within 24 hours From the detection of a serious incident, it is necessary to send NÚKIB so-called early warning. Within 72 hours followed by a detailed incident report with available information on impact and causes. The final report is submitted to one month.
4. Registration with NÚKIB
Regulated entities must register with NÚKIB via the gov.nukib.cz portal. Registration includes identification of the entity, contact person and description of services provided. The registration deadline was set at three months from the date the Act enters into force, or from the moment the entity begins to meet the criteria.
5. Training and awareness raising
The law explicitly requires regular staff training in the field of cybersecurity and ensuring professional training for management. The organisation's leadership must actively oversee the state of cybersecurity. It is not enough simply to "know that IT is handling it".
Timeline: key dates
16. 1. 2023
Entry into force of the NIS2 Directive at EU level
17. 10. 2024
EU deadline for transposing NIS2 into national law (the Czech Republic missed this deadline)
17. 10. 2025
Act 264/2025 Coll. Has entered into force in the Czech Republic.
January 2026
Deadline for registering existing entities with NÚKIB has passed.
From 2026
NÚKIB launches active supervision, inspections and penalty proceedings
How to start preparing?
The most common question we receive is: Where to start? The answer is simple, first determine whether the law applies to your organisation at all, and if it does, assess the current compliance status (gap analysis).
Preparation for NIS2 is not a one-off event but a continuous process. A typical path for a regulated entity looks like this: registration → gap analysis → appointment of the CISO → risk analysis → implementation of measures → internal audit → ongoing training and monitoring.
The entire process may take from 3 to 18 months depending on the size of the organisation and its initial security status. The sooner you start, the better, active cooperation with NÚKIB is viewed positively even if the organisation has not yet achieved full compliance.
Find out if NIS2 applies to you
Our free online audit will tell you within 5 minutes whether you fall under Act No. 264/2025 Coll. And what you must comply with. No registration required, immediate results.
Start a free audit