We help you get ready for NIS2 in Czechia
Czechia transposed NIS2 as Act 264/2025 Sb., supervised by NUKIB.
Audit41 Readiness assesses you against the Czech requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.
Check your Czechia NIS2 scope- 1
Registration
31 December 2025
- 2
Measures
1 year from the registration decision, per entity
- 3
Audit
Decree 409/2025 Sb. section 16(4), at least once every 2 years, higher obligations regime
Every 2 years
Which tier are you?
The regime of higher obligations. Providers of regulated services of essential or strategic significance, and larger organisations by the size thresholds in the law. This regime carries the full obligation set, including the mandatory cybersecurity audit.
Penalties
Up to 250 million CZK or 2 percent of worldwide annual turnover, whichever is higher. NUKIB can also temporarily bar a member of the statutory body for repeated failure to remedy deficiencies.
The regime of lower obligations. Providers of regulated services of important significance that do not meet the higher threshold. A lighter obligation set, without the mandatory audit.
Penalties
Up to the statutory maximum, with supervision triggered by indication of non-compliance.
Your obligations under Act 264/2025 Sb.
Self-identify as a provider of a regulated service and register with NUKIB within the statutory window after you meet the criteria.
Determine your regime, higher or lower obligations, since your full obligation set follows from it.
Establish and run an information security management system as the framework for your security measures.
Implement the security measures Decree 409/2025 Sb. requires for your regime.
Appoint the required security roles, cybersecurity manager, architect, auditor, and asset guarantor, with the role separation the decree requires.
Higher obligations regime: complete a cybersecurity audit under section 16, by an independent auditor, on the recurring cycle the decree sets.
Evaluate the effectiveness of your security management system at least once a year.
Report significant incidents to NUKIB through its portal under the statutory timelines.
The Czech Act does not mandate a specific international standard. An ISO 27001 certification and its Annex A controls map usefully onto the required security management system and give you a recognised structure, but certification does not replace the statutory measures under Decree 409/2025 Sb. or the mandatory audit for the higher obligations regime.
Sectors in scope
Two regimes, not two labels
Czechia frames scope as a regime of higher obligations and a regime of lower obligations, rather than the essential and important labels used elsewhere. The higher regime carries the mandatory audit and the fuller measure set, so determining your regime is the first thing that sets your workload.
A defence industry sector, beyond the EU list
Czechia regulates a defence industry sector in addition to the standard NIS2 sectors. If you supply the defence sector, check your scope carefully.
Size is not the only trigger
Beyond the medium and large size thresholds, the Act can pull you into scope regardless of size under section 5 criteria, including a monopoly position or a disruption that would affect the lives of more than 125,000 people. Small organisations are not automatically out of scope.
Strategically important services carry more
A sub-group of the higher regime, providers of strategically important services, face additional duties including Czech-territory service availability and supply chain verification, where NUKIB can restrict specific suppliers.
From gap report to audit-ready
Between registering with NUKIB and passing the section 16 audit, most higher-regime organisations reach for a consultant. Audit41 Readiness assesses you against the controls Decree 409/2025 Sb. requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Know where you stand on NIS2 in Czechia
The free self-check applies the Czech rules, tells you your regime, and recommends the right assessment.
Check your Czechia NIS2 scopeThis self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.