Skip to content

NIS 2 IN CZECHIA

Návrh zákona o kybernetické bezpečnosti (nový zákon nahrazující zákon č. 181/2014 Sb.) — the national act transposing Directive (EU) 2022/2555 in Czechia. Supervised by Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB).

DRAFT PUBLISHED

Key facts

In force
Not yet in force
National law
Návrh zákona o kybernetické bezpečnosti (nový zákon nahrazující zákon č. 181/2014 Sb.)
Primary supervisor
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities will register through the NÚKIB portal; transitional provisions carry over registrations from the prior Act 181/2014 where applicable.

Scope and national nuance

Czechia is replacing its 2014 Cybersecurity Act with a new act explicitly transposing NIS 2. NÚKIB remains the central authority and operates the national CERT (GovCERT.CZ) and CSIRT.CZ in coordination with CZ.NIC.

Sector supervisors

SectorAuthorityAcronym
Electronic communicationsČeský telekomunikační úřadČTÚ
Financial servicesČeská národní bankaČNB

What is specific to Czechia

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to NÚKIB’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →