NIS2 for small businesses: do I need to comply with Act No. 264/2025 Coll.?

Published: 16. 2. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz

Act No. 264/2025 Coll. On Cybersecurity (the Czech implementation of the NIS2 Directive) applies to thousands of organisations, but not all. If you run a small or medium-sized business, you are likely interested in one question: Am I required to comply with NIS2 OK, or am I exempt as a small business?

Short answer: it depends on the sector and size. But beware. There are exceptions that bring even small companies under the regulation.

Basic rule: a medium-sized enterprise as a minimum.

Act No. 264/2025 Coll. Is based on the NIS2 Directive and defines two categories of regulated entities - basic and important. The same size criteria apply to both:

Size criteria according to the law

Category Employees Turnover or balance sheet total
Micro-enterprise < 10 ≤ 2 million EUR - usually exempted
Small business 10-49 ≤ 10 million EUR - usually exempted
Medium-sized enterprise 50-249 ≤ 50 mil. EUR - regulated
Large enterprise 250+ > 50 mil. EUR - regulated

Note: When assessing, a combination of employee and financial thresholds is used. Exceeding one is sufficient.

If you are a small or micro-enterprise in in a typical sector, Act No. 264/2025 Coll. Probably does not concern you. But the word "probably" is key here. There are important exceptions.

When the law affects a small business anyway

Act No. 264/2025 Coll. (and previously the NÚKIB decree) stipulates that small and micro enterprises may be regulated if:

⚠️ Critical infrastructure regardless of size

If your organisation operates critical infrastructure (as defined by Act No. 181/2014 Coll.), NIS2 OK obligations apply regardless of the number of employees. This typically covers energy, water supply, healthcare or critical digital services.

⚠️ Providers of digital services

Domain registrars, DNS resolvers, CDN networks, cloud services, data centres and electronic trading platforms may be regulated even at smaller sizes if they exceed specific thresholds for customers or transactions.

⚠️ Subcontractors of regulated entities

The law requires regulated entities to manage their cyber risks. suppliers (supply chain security). This means that a small IT company or cloud service provider may receive contractual requirements for NIS2 compliance from its customer, even if the law does not directly regulate it.

⚡ Voluntary registration

Entities not covered by the Act may register voluntarily with NÚKIB and thereby gain access to information on threats and certification. For IT companies selling to the public sector, this can be a competitive advantage.

How to correctly determine whether you are a regulated entity

The National Cyber and Information Security Bureau (NÚKIB) has published the list of sectors affected by the law. Procedure for small businesses:

  1. 1 Find your NACE code - Does your main business area fall within a regulated sector? Key sectors include energy, transport, healthcare, banking, digital infrastructure, water supply or public administration.
  2. 2 Assess the size criteria - do you have at least 50 employees or turnover exceeding 10 million EUR? If not and you are not in critical infrastructure, you probably do not fall under NIS2.
  3. 3 Check your supply chain relationships - Do you provide IT services or software for a regulated entity? If so, verify the contractual requirements.
  4. 4 Use the online audit - on check.nis2ok.cz We will carry out a free preliminary analysis in 10 minutes.

What to do if you are not subject to NIS2

If you are a small business outside regulated sectors, Act No. 264/2025 Coll. Does not impose direct obligations on you. Nevertheless, we recommend:

What to do if you fall under NIS2 (as a small company)

If you are a small business in a regulated sector or operate critical infrastructure, you have the same obligations as large enterprises, with the difference that you have fewer resources. In such cases, the most effective route is NIS2 OK at nis2ok.cz. external cybersecurity manager, which handles everything turnkey without the need to build an internal team.

A certified KB manager will prepare the GAP analysis, documentation and technical measures, and assist with registration at NÚKIB. The entire NIS2 implementation process for a small company in a regulated sector typically takes 2-4 months.

Find out in 10 minutes whether you fall under NIS2.

Free online audit without registration: a concrete result for your company.

Start a free audit →