NIS2 sanctions and fines: up to 250 million Kč

Published: 25. 2. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz

Act No. 264/2025 Coll. On Cybersecurity introduces a sanctioning system without precedent in Czech law within the IT sector. Fines may reach up to 250 million Kč or 2% of global annual turnover. - depending on which value is higher. On top of that, the law establishes personal liability for statutory bodies, making the situation a direct existential threat to top management.

This article summarises who can be penalised, for what, the amount of the fine, and how enforcement is carried out by NÚKIB.

Fine amounts by entity type

NIS2 OK and Act No. 264/2025 Coll. Distinguish between two categories of regulated entities with different penalties:

Type of entity Maximum fine Alternative (% of turnover)
Essential Entity 250 000 000 Kč 2% of global turnover
Important Entity 100 000 000 Kč 1.7% of global turnover

The higher of the two values always applies. For multinational groups, therefore, the turnover of the entire group is used, not just that of the Czech subsidiary. A large software vendor with a group turnover in the billions could face fines amounting to hundreds of millions of Kč even for seemingly minor breaches.

Personal responsibility of management

This is the most significant change compared to the original regulation. Act No. 264/2025 Coll. Establishes the direct personal liability of statutory bodies. (directors, board members) for failure to comply with cybersecurity obligations.

In practice, this means that NÚKIB can impose sanctions not only on the organisation as such but also on the natural person managing it. Individuals face a fine of up to 5 000 000 Kč. Additionally, a temporary ban on performing management functions is possible, effectively a prohibition on acting as a director or board member.

Arguments such as "I didn't know, IT handles this" or "we have a specialist for that" are insufficient. The law explicitly requires the organisation's management to address cybersecurity measures. approved, supervised and completed regular training sessionsA passive approach by management is itself a breach of the law.

What specific sanctions are at stake?

The law defines a range of specific offences. The most common and serious violations for which sanctions can be expected are:

How does enforcement proceed on the part of NÚKIB?

From October 2025, NÚKIB will have full supervisory powers. Enforcement may be initiated in three ways:

Proactive audit

NÚKIB may initiate an inspection based on its own supervision plan. For essential entities, audits are conducted regularly; for important entities, they are more reactive.

Response to the Incident

Following the reporting (or non-reporting) of a significant incident, NÚKIB will investigate whether the organisation fulfilled its obligations prior to the incident and during its resolution.

Third-party incentive

A customer, partner or employee may submit a report. The competitive environment increases the risk that non-compliance will be reported.

Administrative proceedings initiated by NÚKIB typically proceed in several phases: notification of the commencement of proceedings, a call for remediation (in less serious cases), followed by a decision on sanctions with the possibility of appeal. In urgent situations involving threats to critical infrastructure, NÚKIB may also impose... preliminary measure - for example, temporary restrictions on system operation or the obligation to immediately implement specific measures.

How to protect yourself against sanctions?

The most effective defence is, of course, actual compliance with the law. However, even with the best intentions, 100% compliance cannot be guaranteed from day one. Key factors that NÚKIB considers when imposing sanctions:

Do not forget that sanctions are not limited to fines. NÚKIB may also publish information about a breach of the law including the name of the organisation and the nature of the breach, reputational damage can be more fatal than the fine itself in many sectors.

Comparison with GDPR: which is worse?

Many companies are familiar with the sanction logic of GDPR (up to 20 million EUR or 4% of turnover). In reality, NIS2 brings lower maximum percentage rates (2% vs 4%), but the key difference lies in the personal liability of management, GDPR enshrines this more weakly. On top of that, NIS2 covers operational cybersecurity as a whole, whereas GDPR focuses on the protection of personal data. Both regulations overlap in the area of data breach incidents: a security breach can lead to sanctions from two laws at once.

Check your compliance status for free

Before the NÚKIB finds you, find yourself first. Our free online audit will identify the most critical gaps and propose priority remedial steps. It takes 5 minutes.

Start a free audit