NIS2 in the Czech Republic: A Guide for Foreign-Owned Companies
Published: 19 July 2026 | Author: Vít Vomáčko | NIS2OK.cz
If your organisation has a subsidiary, branch, or operating entity in the Czech Republic, there's a good chance NIS2 already applies to it - regardless of where your parent company is headquartered or where group-level security decisions get made. This guide sets out, in plain English, what actually changed, who enforces it, and why the Czech entity cannot simply wait for instructions from head office.
What NIS2 actually is
NIS2 is shorthand for the EU's second Network and Information Security Directive, formally Directive (EU) 2022/2555. Like any EU directive, it doesn't apply directly to companies - it obliges each member state to transpose it into national law. That's the part that matters operationally: your Czech entity isn't regulated by "NIS2" in the abstract. It's regulated by whatever law the Czech Republic wrote to implement it.
The Czech implementation: Act 264/2025 Sb.
The Czech Republic's transposition is a new Act on Cybersecurity, published as Act No. 264/2025 Sb., which entered into effect on 1 November 2025. It replaced the country's previous cybersecurity law and significantly widened the circle of organisations it covers. The Act is enforced by NÚKIB, the Czech national cyber security agency - the body your Czech entity will deal with directly for registration, oversight, and incident reporting.
This is a genuinely Czech law with a Czech regulator. It sits alongside - not instead of - equivalent NIS2 transpositions your group may already be managing in other EU member states, and each one is enforced locally.
Ownership doesn't exempt you
A common assumption inside international groups is that NIS2 obligations attach to the ultimate parent, or that a foreign HQ's existing security programme automatically covers a Czech subsidiary. It doesn't work that way. Act 264/2025 Sb. applies to the entity registered and operating in the Czech Republic, assessed on its own sector, activities, and size. If your Czech branch or subsidiary meets the criteria, it carries the obligations directly - NÚKIB looks to that entity, not to a security team sitting in another country.
Two regimes, not one
The Act doesn't treat every regulated organisation identically. It sets up two broad regimes - one carrying comparatively higher obligations and tighter oversight, the other comparatively lower obligations - depending on the sector and how critical the service is considered. Both regimes carry real compliance duties; the practical difference is mainly in the intensity of oversight and how proactively NÚKIB engages. Working out which regime your entity falls into is one of the first things worth establishing, since it shapes how much process you'll need to build around registration and ongoing compliance.
The registration duty is on you
One detail that regularly catches foreign-owned entities off guard: registering with NÚKIB is a self-identification duty. Nobody notifies you that you're in scope. The Act expects organisations to assess their own situation against the sector and size criteria and register themselves accordingly. For a group used to a regulator making first contact, this is a real change in posture - it's an obligation to act, not a notice to wait for.
What non-compliance risks
The Act gives NÚKIB real enforcement powers, including the ability to impose significant fines on organisations that fail to register or fail to meet their obligations. We're deliberately not quoting a specific figure here unless we can point you to the exact clause - treat "significant" as an accurate description, not a euphemism.
Related reading
Find out where your Czech entity stands
Our free online NIS2 check takes about 10 minutes and tells you whether Act 264/2025 Sb. applies, and which regime is likely relevant.
Start the free check →The check is currently in Czech - contact us for a guided English-language walkthrough.