Skip to main content
NIS2 · CZECHIA

NIS2 in Czechia — Act 264/2025, obligations per service, and every incident reportable.

Czechia's Act No. 264/2025 Sb. entered into force on 1 November 2025, giving covered entities 60 days to self-identify — a window that closed on 31 December 2025. The regime now runs on its implementation clock: twelve months to put the security measures in place, running to 1 November 2026, with NÚKIB's portal as the registration surface and unusually detailed public guidance defining what compliance looks like.

Two Czech particularities bite. First, the higher/lower classification — the Czech essential/important split — attaches per regulated service, not per entity: a company can be essential for one service and important for another. Second, Czechia requires reporting of all incidents, not only significant ones — a materially broader reporting duty than the directive baseline.

Who it applies to

Providers of regulated services across the NIS2 sectors, classified higher or lower per service — one entity can hold both classifications for different services. Self-identification ran through the NÚKIB portal to 31 December 2025; entities crossing thresholds later identify within the statutory window. Security measures are due by 1 November 2026, and every incident — significant or not — is reportable.

The clock

Competent authority: NÚKIB (National Cyber and Information Security Agency). Transposition: Act No. 264/2025 Sb..

NIS2 in Czechia · timeline
WhenWhat happens
1 Nov 2025Act 264/2025 Sb. enters into force
31 Dec 202560-day self-identification window closes · NÚKIB portal
1 Nov 2026Security-measures implementation due (12 months)
OngoingAll incidents reportable · early warning within 24 h for significant incidents

Per-service classification, every incident reportable

Czechia's transposition sharpens two edges most member states left dull. The essential/important classification attaches to the regulated service, not the entity — so the same organization can operate under the heavier regime for one service and the lighter for another, and the evidence has to be separable along the same lines. And the reporting duty covers all incidents, not only significant ones: the volume a team must handle as routine reporting is far higher, which makes templated, clocked, pre-built incident records the difference between a reportable process and a drowned one. NÚKIB's guidance is among the most detailed published anywhere — TruSecure maps controls to that national guidance, not just the directive text.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Czechia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Czechia requirements · how TruSecure answers them
What the law asksWhere it is answered
Self-identify per regulated serviceApplicability engine · per-service higher/lower classification, not per-entity
Implement security measures by 1 November 2026Control library · continuously evidenced, gap list dated
Report all incidents — not only significant onesIncident workflow · every incident templated and clocked
Map controls to NÚKIB's national guidanceControl library · NÚKIB specifics layered over the EU baseline
Show management-body oversight and trainingGovernance workspace · approvals and training records, dated

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Czechia NIS2 readiness file · excerptSample data
NÚKIB registration
filed · 14 Dec 2025, two services classified
Per-service classification
energy · higher (essential) · data centre · lower (important)
Measures deadline
1 Nov 2026 · 112/128 evidenced, 16 open with owners
Incident volume
all-incidents regime · 41 filed this year, clocks met
Export
sealed · sha256:5c3e...9a2f

Where teams usually start

With a demo walked through by TruSecure — your services classified per the Czech model, controls mapped to NÚKIB's guidance against the November 2026 deadline, and the all-incidents reporting flow shown end to end. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Czechia by NÚKIB (National Cyber and Information Security Agency). TruSecure determines applicability against Czechia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

What has NÚKIB published on NIS2 so far?
NÚKIB has published unusually detailed public guidance on scope and controls, among the most complete of any national transposition — TruSecure maps directly to it rather than only the EU baseline text.