NIS 2 — Czechia
NIS 2 IN CZECHIA
Návrh zákona o kybernetické bezpečnosti (nový zákon nahrazující zákon č. 181/2014 Sb.) — the national act transposing Directive (EU) 2022/2555 in Czechia. Supervised by Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB).
DRAFT PUBLISHED
Key facts
In force
Not yet in force
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities will register through the NÚKIB portal; transitional provisions carry over registrations from the prior Act 181/2014 where applicable.
Scope and national nuance
Czechia is replacing its 2014 Cybersecurity Act with a new act explicitly transposing NIS 2. NÚKIB remains the central authority and operates the national CERT (GovCERT.CZ) and CSIRT.CZ in coordination with CZ.NIC.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Electronic communications | Český telekomunikační úřad | ČTÚ |
| Financial services | Česká národní banka | ČNB |
What is specific to Czechia
- Czechia is fully replacing its 2014 cybersecurity act rather than amending it — covered entities under the old regime should expect a fresh registration and classification cycle.
- NÚKIB combines the policy supervisor, national CSIRT (GovCERT.CZ) and certification authority roles in a single body — one of the most consolidated supervisory models in the EU.
- The new act introduces a regime adjustment based on the directive's two-tier essential/important entity model but preserves a Czech-specific notion of services of critical importance for state operations.
- NÚKIB's strategic-supplier assessment regime (Ruling on 5G suppliers and on cloud) sits alongside the NIS 2 supply-chain obligations and applies cumulatively.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to NÚKIB’s supervisory expectations.