NIS2 deadlines and dates 2026:
what you need to get done

Published: 29. 1. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz

Act No. 264/2025 Coll. On Cybersecurity has entered into force. 17 October 2025, but the implementation deadlines allow for the gradual fulfilment of obligations. You do not have to meet everything at once. It depends on when you became aware of your status as a regulated entity and what type of obligation is involved.

We provide an overview of key deadlines so you know what needs to be completed and by when.

Overview of key terms

17 October 2025 - COMPLETED

The Act comes into force

Act No. 264/2025 Coll. Is in force. From this date, all implementation deadlines are running. If you are a regulated entity, you are obliged to begin compliance.

Until 17 January 2026: COMPLETED (for entities aware of their status)

Registration with NÚKIB

Entities that were aware of their status by the effective date had 3 months to register via the NÚKIB portal. If you are still unregistered, contact NÚKIB as soon as possible, late registration is an offence.

Until 17 July 2026: APPROACHING

Appointment of a Cybersecurity Manager

The law requires the appointment of a person responsible for cybersecurity (Cybersecurity Manager). This individual must meet the qualification requirements under Decree 409/2025 Coll. Or engage an external Cybersecurity Manager with certification. Deadline: 9 months from entry into force.

Until 17 October 2026

Implementation of basic security measures

Within 12 months of entry into force, all mandatory technical and organisational security measures under Sections 15-17 of the Act must be implemented. These include risk management, security policy, backups, cryptography, access rights, patch management and staff training.

Until 17 October 2026

Incident Response Plan and BCM

Business Continuity Management (BCM), Disaster Recovery Plan (DRP) and a formalised incident response plan must be documented, tested and implemented.

Continuously: from the date of entry into force

Reporting of cyber incidents

The obligation to report serious incidents to NÚKIB applies. effective immediately from 17 October 2025. Deadline: early warning within 24 hours of detection, formal notification within 72 hours, final report within 1 month.

Until 17 October 2027 (basic entities)

Security audit and certification

Basic entities must undergo a conformity audit within 24 months and repeat it regularly. Important entities are audited upon request by the NÚKIB.

Warning: deadlines vary depending on when you discovered your status.

The Act covers situations where an entity discovers its regulated status only after it has come into force, for example, because it expanded its business into a regulated sector or exceeded size thresholds. In such cases, individual deadlines begin to run. from the day on which the entity became certain of its statusor from notification by NÚKIB.

Most common mistakes when meeting NIS2 deadlines

How to meet deadlines? A realistic plan

The entire NIS2 implementation for a medium-sized company realistically takes 3-6 months with sufficient effort. If you start today, you still have time to meet the October deadline. The key is proper prioritisation:

  1. 1.GAP analysis: current status versus required status (2-4 weeks)
  2. 2.Appointment or procurement of a Key Person Manager (immediately)
  3. 3.Registration with NÚKIB (within 30 days)
  4. 4.Implementation of technical measures according to priorities from the GAP analysis
  5. 5.Documentation, training, setting up incident reporting

Do you need help with implementation? Certified Cybersecurity Manager takes over coordination of the entire process and ensures all deadlines are met.

Find out your NIS2 status in 10 minutes

Free online audit: no registration required.

Start a free audit →