NIS2 deadlines and dates 2026:
what you need to get done
Published: 29. 1. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz
Act No. 264/2025 Coll. On Cybersecurity has entered into force. 17 October 2025, but the implementation deadlines allow for the gradual fulfilment of obligations. You do not have to meet everything at once. It depends on when you became aware of your status as a regulated entity and what type of obligation is involved.
We provide an overview of key deadlines so you know what needs to be completed and by when.
Overview of key terms
17 October 2025 - COMPLETED
The Act comes into force
Act No. 264/2025 Coll. Is in force. From this date, all implementation deadlines are running. If you are a regulated entity, you are obliged to begin compliance.
Until 17 January 2026: COMPLETED (for entities aware of their status)
Registration with NÚKIB
Entities that were aware of their status by the effective date had 3 months to register via the NÚKIB portal. If you are still unregistered, contact NÚKIB as soon as possible, late registration is an offence.
Until 17 July 2026: APPROACHING
Appointment of a Cybersecurity Manager
The law requires the appointment of a person responsible for cybersecurity (Cybersecurity Manager). This individual must meet the qualification requirements under Decree 409/2025 Coll. Or engage an external Cybersecurity Manager with certification. Deadline: 9 months from entry into force.
Until 17 October 2026
Implementation of basic security measures
Within 12 months of entry into force, all mandatory technical and organisational security measures under Sections 15-17 of the Act must be implemented. These include risk management, security policy, backups, cryptography, access rights, patch management and staff training.
Until 17 October 2026
Incident Response Plan and BCM
Business Continuity Management (BCM), Disaster Recovery Plan (DRP) and a formalised incident response plan must be documented, tested and implemented.
Continuously: from the date of entry into force
Reporting of cyber incidents
The obligation to report serious incidents to NÚKIB applies. effective immediately from 17 October 2025. Deadline: early warning within 24 hours of detection, formal notification within 72 hours, final report within 1 month.
Until 17 October 2027 (basic entities)
Security audit and certification
Basic entities must undergo a conformity audit within 24 months and repeat it regularly. Important entities are audited upon request by the NÚKIB.
Warning: deadlines vary depending on when you discovered your status.
The Act covers situations where an entity discovers its regulated status only after it has come into force, for example, because it expanded its business into a regulated sector or exceeded size thresholds. In such cases, individual deadlines begin to run. from the day on which the entity became certain of its statusor from notification by NÚKIB.
Most common mistakes when meeting NIS2 deadlines
- ✗ Waiting for NÚKIB to "get in touch with me - The law does not require NÚKIB to actively seek out entities. The obligation to register lies with you.
- ✗ Confusion over deadlines for different obligations - Incident reporting is effective immediately; implementation of measures has a deadline of 12 months.
- ✗ Underestimating the KB manager - Appointing a formal person without actual qualifications is insufficient. NÚKIB will verify competence.
- ✗ Neglect of the supply chain - You must also impose security requirements on your key IT service suppliers.
How to meet deadlines? A realistic plan
The entire NIS2 implementation for a medium-sized company realistically takes 3-6 months with sufficient effort. If you start today, you still have time to meet the October deadline. The key is proper prioritisation:
- 1.GAP analysis: current status versus required status (2-4 weeks)
- 2.Appointment or procurement of a Key Person Manager (immediately)
- 3.Registration with NÚKIB (within 30 days)
- 4.Implementation of technical measures according to priorities from the GAP analysis
- 5.Documentation, training, setting up incident reporting
Do you need help with implementation? Certified Cybersecurity Manager takes over coordination of the entire process and ensures all deadlines are met.
Related articles
Find out your NIS2 status in 10 minutes
Free online audit: no registration required.
Start a free audit →