NIS2 in Czechia — Act 264/2025, obligations per service, and every incident reportable.
Czechia's Act No. 264/2025 Sb. entered into force on 1 November 2025, giving covered entities 60 days to self-identify — a window that closed on 31 December 2025. The regime now runs on its implementation clock: twelve months to put the security measures in place, running to 1 November 2026, with NÚKIB's portal as the registration surface and unusually detailed public guidance defining what compliance looks like.
Two Czech particularities bite. First, the higher/lower classification — the Czech essential/important split — attaches per regulated service, not per entity: a company can be essential for one service and important for another. Second, Czechia requires reporting of all incidents, not only significant ones — a materially broader reporting duty than the directive baseline.
Who it applies to
Providers of regulated services across the NIS2 sectors, classified higher or lower per service — one entity can hold both classifications for different services. Self-identification ran through the NÚKIB portal to 31 December 2025; entities crossing thresholds later identify within the statutory window. Security measures are due by 1 November 2026, and every incident — significant or not — is reportable.
The clock
Competent authority: NÚKIB (National Cyber and Information Security Agency). Transposition: Act No. 264/2025 Sb..
| When | What happens |
|---|---|
| 1 Nov 2025 | Act 264/2025 Sb. enters into force |
| 31 Dec 2025 | 60-day self-identification window closes · NÚKIB portal |
| 1 Nov 2026 | Security-measures implementation due (12 months) |
| Ongoing | All incidents reportable · early warning within 24 h for significant incidents |
Per-service classification, every incident reportable
Czechia's transposition sharpens two edges most member states left dull. The essential/important classification attaches to the regulated service, not the entity — so the same organization can operate under the heavier regime for one service and the lighter for another, and the evidence has to be separable along the same lines. And the reporting duty covers all incidents, not only significant ones: the volume a team must handle as routine reporting is far higher, which makes templated, clocked, pre-built incident records the difference between a reportable process and a drowned one. NÚKIB's guidance is among the most detailed published anywhere — TruSecure maps controls to that national guidance, not just the directive text.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Czechia transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Self-identify per regulated service | Applicability engine · per-service higher/lower classification, not per-entity |
| Implement security measures by 1 November 2026 | Control library · continuously evidenced, gap list dated |
| Report all incidents — not only significant ones | Incident workflow · every incident templated and clocked |
| Map controls to NÚKIB's national guidance | Control library · NÚKIB specifics layered over the EU baseline |
| Show management-body oversight and training | Governance workspace · approvals and training records, dated |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- NÚKIB registration
- filed · 14 Dec 2025, two services classified
- Per-service classification
- energy · higher (essential) · data centre · lower (important)
- Measures deadline
- 1 Nov 2026 · 112/128 evidenced, 16 open with owners
- Incident volume
- all-incidents regime · 41 filed this year, clocks met
- Export
- sealed · sha256:5c3e...9a2f
Where teams usually start
With a demo walked through by TruSecure — your services classified per the Czech model, controls mapped to NÚKIB's guidance against the November 2026 deadline, and the all-incidents reporting flow shown end to end. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Czechia by NÚKIB (National Cyber and Information Security Agency). TruSecure determines applicability against Czechia's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.