Do I fall under NIS2? How to find out if Act No. 264/2025 Coll. Applies to me.
Published: 4. 12. 2025 | Author: Ing. Vít Vomáčko | NIS2OK.cz
Do I fall under NIS2? - this is the most common question we receive from companies and organisations since October 2025. The quickest answer comes from our Free test: in 10 minutes you will know if the law applies to you.The answer depends on two factors: the sector in which you operate and the size of your organisation. This guide will walk you through a step-by-step self-assessment.
Warning: the responsibility for determining whether an organisation falls under the Act lies with the organisation itself: not with NÚKIB. If you are unsure and the Act applies to you but you fail to register, penalties for non-registration may be imposed.
Step 1: Check the size of the organisation
Act 264/2025 Coll. Generally applies to medium and large enterprises. Micro-organisations and small enterprises are mostly exempt, but with important exceptions (see below).
| Business category | Employees | Annual turnover | Balance sum |
|---|---|---|---|
| Micro-enterprise | < 10 | < 2 million EUR | < 2 million EUR |
| Small business | 10 - 49 | 2 - 10 million EUR | 2 - 10 million EUR |
| Medium-sized enterprise | 50 - 249 | 10 - 50 million EUR | 10 - 43 million EUR |
| Large enterprise | 250 and more | > 50 million EUR | > 43 mil. EUR |
For size classification, average data from the last two financial years are used. If an organisation exceeds at least one of the numerical indicators, it falls into that category. Medium and large enterprises in regulated sectors have obligations under Act No. 264/2025 Coll.
The size is assessed for the entire economic group; regulation cannot be evaded by artificially splitting an organisation into multiple smaller entities.
Step 2: Verify whether you operate in a regulated sector
The Act distinguishes between highly critical sectors (Annex I) and other critical sectors (Annex II). Entities from Annex I are classified as essential and are subject to stricter supervision.
| Sector | Annex | Examples of entities | Min. Size |
|---|---|---|---|
| Energy efficiency | And | Production, transmission and distribution of electricity, gas, oil and district heating. | Medium |
| Delivery | And | Air transport, railways, river and sea transport, operators of road infrastructure | Medium |
| Banking and finance | And | Banks, financial market infrastructure operators, payment institutions | Medium |
| Healthcare | And | Hospitals, pharmaceutical and medical device manufacturing, laboratories | Medium |
| Drinking water | And | Drinking water distribution, wastewater treatment plants | Medium |
| Digital infrastructure | And | ISP, DNS providers, data centres, cloud providers, IXP, TLD registry | Without exception |
| Public administration | And | Central state administration authorities and regional offices | Without exception |
| Space industry | And | Ground infrastructure for space programmes | Medium |
| Postal and courier services | II | Operators of postal and delivery services | Medium |
| Waste management | II | Operators handling waste | Medium |
| Manufacturing | II | Manufacture of medical devices, electronics, machinery, motor vehicles and chemicals. | Medium |
| Food industry | II | Production, processing and distribution of foodstuffs | Medium |
| Digital providers | II | Online marketplaces, search engines, social media platforms | Medium |
| Research | II | Research institutions (especially those connected to critical infrastructure) | Medium |
Exceptions that may come as a surprise
There are situations where the law applies even to organisations that do not meet the standard size criteria:
- !Critical infrastructure - entities included in the National Plan for the Protection of Critical Infrastructure are regulated regardless of size.
- !Single or dominant provider - if you are the sole provider of a critical service in the Czech Republic or its region, the law also applies to small organisations.
- !Digital infrastructure without exception - ISPs, DNS providers, IXPs and TLD registries have no exemption for small businesses.
- !Public administration - state and regional authorities fall under the law without any size condition.
Step 3: Result: what does this imply?
I do not fall under this category.
A small business outside the regulated sector. Act 264/2025 Coll. Does not impose direct obligations on you, but cybersecurity pays off even without regulation.
I may be falling behind.
You are at the threshold (close to 50 employees or €10M turnover, or you are unsure of your sector classification). Have it verified by an expert on NIS2 OK. NIS2Manager.cz.
I fall under
A medium or large enterprise in a regulated sector. You must register with the National Nuclear Safety Authority and comply with legal obligations.
Step 4: Registration with NÚKIB
If you have concluded that Act No. 264/2025 Coll. Applies to you, the first step is registration with NÚKIBThe deadline for registering existing entities expired in January 2026, if you have not yet registered, do so as soon as possible.
Registration is carried out electronically via the gov.nukib.cz portal using a data box or a qualified electronic signature. When registering, you must provide:
- •Organisation identification (IČO, name, registered office)
- •The contact person responsible for cybersecurity
- •Description of services provided and their sector classification
- •Information on critical infrastructure (if applicable)
- •Contact details for reporting incidents (available 24/7)
After registration, NÚKIB will include the entity in the register of regulated entities and assign it the appropriate category (essential or important entity). This classification determines the intensity of supervision and the level of potential sanctions.
What to do first upon discovering that you fall under NIS2 OK?
Chronologically, we recommend this procedure:
Registration with NÚKIB
Immediately, if not yet completed. This fulfills your basic obligation and initiates communication with the regulator.
Appointment of a Cybersecurity Manager
Internal or external. Must have appropriate competence and direct access to management.
Gap analysis / compliance audit
Find out what obligations the law imposes and where you have gaps. Start with our free online audit or use SecureOn.cz for a detailed B2B security audit.
Risk analysis and security policies
Basic documentation without which compliance cannot be demonstrated during a NÚKIB inspection.
Setting up the incident response process
Who reports incidents to NÚKIB, how and within what deadlines. This procedure must operate 24/7 from day one.
Find out your status in 5 minutes
Our free online audit on check.nis2ok.cz will answer you precisely:
- ✓ Whether you fall under Act No. 264/2025 Coll.
- ✓ Whether you are a critical or important entity
- ✓ What gaps do you have in fulfilling your obligations?
- ✓ What steps to take as a priority
No registration. No credit card. Results immediately.