NIS2 sanctions and fines: up to 250 million Kč
Published: 25. 2. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz
Act No. 264/2025 Coll. On Cybersecurity introduces a sanctioning system without precedent in Czech law within the IT sector. Fines may reach up to 250 million Kč or 2% of global annual turnover. - depending on which value is higher. On top of that, the law establishes personal liability for statutory bodies, making the situation a direct existential threat to top management.
This article summarises who can be penalised, for what, the amount of the fine, and how enforcement is carried out by NÚKIB.
Fine amounts by entity type
NIS2 OK and Act No. 264/2025 Coll. Distinguish between two categories of regulated entities with different penalties:
| Type of entity | Maximum fine | Alternative (% of turnover) |
|---|---|---|
| Essential Entity | 250 000 000 Kč | 2% of global turnover |
| Important Entity | 100 000 000 Kč | 1.7% of global turnover |
The higher of the two values always applies. For multinational groups, therefore, the turnover of the entire group is used, not just that of the Czech subsidiary. A large software vendor with a group turnover in the billions could face fines amounting to hundreds of millions of Kč even for seemingly minor breaches.
Personal responsibility of management
This is the most significant change compared to the original regulation. Act No. 264/2025 Coll. Establishes the direct personal liability of statutory bodies. (directors, board members) for failure to comply with cybersecurity obligations.
In practice, this means that NÚKIB can impose sanctions not only on the organisation as such but also on the natural person managing it. Individuals face a fine of up to 5 000 000 Kč. Additionally, a temporary ban on performing management functions is possible, effectively a prohibition on acting as a director or board member.
Arguments such as "I didn't know, IT handles this" or "we have a specialist for that" are insufficient. The law explicitly requires the organisation's management to address cybersecurity measures. approved, supervised and completed regular training sessionsA passive approach by management is itself a breach of the law.
What specific sanctions are at stake?
The law defines a range of specific offences. The most common and serious violations for which sanctions can be expected are:
-
!
Failure to register with NÚKIB - Even a single overlooked administrative step can lead to sanctions, as NÚKIB then lacks an overview of the entity and cannot fulfil its supervisory function.
-
!
Failure to report or late reporting of an incident - expiry of the 24-hour deadline for early warning or the 72-hour deadline for incident reporting.
-
!
Lack of risk management - missing or outdated risk analysis, absence of security policies and procedures.
-
!
Inadequate supply chain security - third-party access to critical systems without appropriate contractual and technical safeguards.
-
!
Failure to ensure operational continuity - lack of recovery plans, regular backup testing or failure scenario testing.
-
!
Non-cooperation during NÚKIB inspection - refusal of access to the auditor, failure to provide documentation or intentional provision of false information.
How does enforcement proceed on the part of NÚKIB?
From October 2025, NÚKIB will have full supervisory powers. Enforcement may be initiated in three ways:
Proactive audit
NÚKIB may initiate an inspection based on its own supervision plan. For essential entities, audits are conducted regularly; for important entities, they are more reactive.
Response to the Incident
Following the reporting (or non-reporting) of a significant incident, NÚKIB will investigate whether the organisation fulfilled its obligations prior to the incident and during its resolution.
Third-party incentive
A customer, partner or employee may submit a report. The competitive environment increases the risk that non-compliance will be reported.
Administrative proceedings initiated by NÚKIB typically proceed in several phases: notification of the commencement of proceedings, a call for remediation (in less serious cases), followed by a decision on sanctions with the possibility of appeal. In urgent situations involving threats to critical infrastructure, NÚKIB may also impose... preliminary measure - for example, temporary restrictions on system operation or the obligation to immediately implement specific measures.
How to protect yourself against sanctions?
The most effective defence is, of course, actual compliance with the law. However, even with the best intentions, 100% compliance cannot be guaranteed from day one. Key factors that NÚKIB considers when imposing sanctions:
- ✓Demonstrable effort to achieve compliance - existing documentation, initiated projects, appointed key manager. NÚKIB assesses the process, not just the outcome.
- ✓Proactive communication with NÚKIB - registration, incident reporting, transparency during inspections. Cooperating entities receive lower penalties.
- ✓Quick repair - if a non-compliance is identified, rapid implementation of corrective measures reduces the amount of the sanction.
- ✓Documentation of safety measures - what is not documented is deemed non-existent. Records of training, audits and risk analyses are essential.
Do not forget that sanctions are not limited to fines. NÚKIB may also publish information about a breach of the law including the name of the organisation and the nature of the breach, reputational damage can be more fatal than the fine itself in many sectors.
Comparison with GDPR: which is worse?
Many companies are familiar with the sanction logic of GDPR (up to 20 million EUR or 4% of turnover). In reality, NIS2 brings lower maximum percentage rates (2% vs 4%), but the key difference lies in the personal liability of management, GDPR enshrines this more weakly. On top of that, NIS2 covers operational cybersecurity as a whole, whereas GDPR focuses on the protection of personal data. Both regulations overlap in the area of data breach incidents: a security breach can lead to sanctions from two laws at once.
Check your compliance status for free
Before the NÚKIB finds you, find yourself first. Our free online audit will identify the most critical gaps and propose priority remedial steps. It takes 5 minutes.
Start a free audit