Skip to main content
EN

Czech Republic Cybersecurity Act 2025

The National Cyber and Information Security Agency (NÚKIB) of the Czech Republic has published official information on the adoption of a new Cybersecurity Act to transpose the NIS2 Directive into Czech law.

From the Current Act to the New Legal Framework

Until now, cybersecurity regulation in the Czech Republic was governed by the Act No. 181/2014 Coll. on Cybersecurity. The new Act marks a significant update: it is explicitly designed to implement NIS2 requirements, thereby widening the range of entities subject to cybersecurity obligations.

The NIS2 Directive itself entered into force at the EU level in December 2022, with Member States obliged to incorporate its measures into national law.

Scope and Key Features

The new Czech Cybersecurity Act expands the scope of regulated entities beyond the previous critical-infrastructure model. According to professional analysis, the Act will apply to sectors such as energy, transport, healthcare, digital services and infrastructure, and will introduce differentiated regimes depending on an entity’s size and function.

Key features in the new law include:

  • A defined obligation to implement risk-management frameworks, including governance, oversight and training of management.
  • Incident-reporting requirements, with a distinction between “essential” and “important” entities and their reporting obligations.
  • Enhanced powers for supply-chain controls and vendor restrictions where risk to national security is deemed high.

Legislative Status and Timeline

As of April 25, 2025, the Czech Republic’s lower house approved the new Cybersecurity Act as part of its transposition of NIS2. The publication in the official Collection of Laws remains a forthcoming step.

Under the Act, the effective date will be the first day of the third calendar month following its official publication in the Collection of Laws. While some sources estimate it may take effect in late 2025, the precise date is subject to publication scheduling.

Role of the NÚKIB Portal

The NÚKIB has also introduced a digital platform, the NÚKIB Portal, which will support compliance with the new Act by providing regulated entities with access to guidance, tools and secure communication channels.

The Portal features a public section, offering information about the law and cyber-security obligations, and a non-public section, accessible to registered regulated entities, allowing them to submit reports and share information with the regulator.

What This Means

For organizations operating in the Czech Republic, preparation is key. The expansion of the legal regime means that many entities not previously subject to specific cybersecurity obligations may now fall under the new Act’s remit. The combination of governance, incident-reporting and supply-chain rules indicates that cyber-security is becoming a regulated area akin to data protection.

In summary, the Czech Republic’s new Cybersecurity Act aligns its national legal framework with the EU’s NIS2 Directive, enhances regulator powers through NÚKIB and creates a digital infrastructure for compliance via the NÚKIB Portal. Entities affected should monitor the publication process and plan their compliance strategy accordingly.

Ai image.

Call Now Button