World Watch/Czechia/Cybersecurity

Cybersecurity · Czechia

Cybersecurity regulation in Czechia (2026)

Comprehensive lawAct No. 264/2025 Coll. on Cybersecurity (Zákon o kybernetické bezpečnosti), in force 1 November 2025, transposing EU NIS2 Directive (2022/2555); supervised by NÚKIB (National Cyber and Information Security Agency)Country index 84 · A

Czechia shaded by its cybersecurity status

Czechia enacted a new, standalone Cybersecurity Act (No. 264/2025 Coll.) that entered into force on 1 November 2025, replacing the prior cybersecurity regime and fully transposing the EU NIS2 Directive. The law significantly expands the scope of regulated entities across 15 sectors, establishes a two-tier classification (essential / important entities), and imposes risk-management, incident-reporting, and supply-chain obligations enforced by NÚKIB. Some secondary implementing regulations (e.g., on essential functions and strategically significant services) remained pending into 2026.

Key points

NIS2 Transposition — Act No. 264/2025

The Chamber of Deputies passed the act on 25 April 2025; it was signed by the President on 26 June 2025, published in the Collection of Laws on 4 August 2025, and entered into force on 1 November 2025, missing the EU's 17 October 2024 deadline. It replaces the earlier cybersecurity act entirely.

Scope — Essential vs. Important Entities

The act covers entities with ≥50 employees or annual turnover/balance sheet >€10 million operating in 15 sectors (energy, healthcare, transport, finance, digital infrastructure, food, manufacturing, etc.), classified as either 'essential entities' (higher obligations) or 'important entities' (lower obligations). Entities had 60 days from 1 November 2025 to self-assess and register with NÚKIB.

Incident Reporting Obligations

Essential entities must report to NÚKIB all cybersecurity incidents affecting their regulated service that originate in cyberspace and where intentional conduct cannot be excluded; important entities must report incidents with a significant impact on service provision, with reports directed to the national CSIRT. The act goes beyond the NIS2 minimum by requiring reporting of all (not only significant) incidents for essential entities.

Risk Management & Governance Duties

Regulated entities must implement technical and organisational cybersecurity measures, ensure top-level management oversight and cybersecurity training, conduct supply chain risk assessments, and maintain business continuity plans for serious cyber incidents. NÚKIB may request extensive supply-chain information and prohibit or restrict use of specific suppliers deemed security risks.

Penalties

Essential entities face fines of up to CZK 250 million or 2% of global annual turnover (whichever is higher); important entities face up to CZK 175 million or 1.4% of global annual turnover. NÚKIB may also impose coercive fines up to CZK 10 million, suspend operations, require remediation, and in cases of repeated serious management failures, take action affecting corporate bodies.

Pending Secondary Legislation & 2026 Outlook

As of early 2026, several Government regulations implementing the act — particularly on essential functions and strategically significant services with enhanced supply-chain resilience requirements — remained pending. NÚKIB was processing entity registrations submitted by the December 2025 deadline; once confirmed, a one-year transitional compliance period begins before full enforcement of all security controls and reporting obligations.

Timeline - major decisions & events

Sep 3, 2025guidanceofficial
NÚKIB Formal High-Risk Warning: Chinese Technology Transfers and Remote Administration

NÚKIB issued a formal high-risk warning (probability 'likely to very likely') advising critical-infrastructure operators against products and services that send data to or allow remote management from the People's Republic of China — covering IP cameras, PV inverters, smart meters, connected vehicles, cloud storage, and LLMs. Entities regulated under the Cybersecurity Act must integrate this risk into mandatory risk analyses and apply commensurate controls.

NÚKIB
Aug 4, 2025lawofficial
New Cybersecurity Act No. 264/2025 Enacted — Full NIS2 Transposition (Effective 1 Nov 2025)

The Czech Parliament enacted Act No. 264/2025 Coll. on Cybersecurity, published in the Official Gazette on 4 August 2025 and entering into force 1 November 2025. It replaces Act No. 181/2014, expands regulated entities from roughly 400 to an estimated 6,000–15,000 across 18 sectors, introduces essential/important entity tiers, mandatory supply chain risk management, executive accountability, 24-hour incident reporting, and fines up to CZK 250 million or 2% of global annual turnover.

NÚKIB
May 28, 2025incidentofficial
Czech Government Publicly Attributes APT31 (China/MSS) Espionage Campaign Against Ministry of Foreign Affairs

The Czech Government formally attributed a cyber-espionage campaign active since at least 2022 to APT31, assessed with high certainty to be operated by China's Ministry of State Security, which had persistently targeted the unclassified network of the Czech Ministry of Foreign Affairs — designated critical infrastructure. The attribution was concluded jointly by all four Czech intelligence and security agencies.

NÚKIB
May 3, 2024incidentofficial
Czechia Publicly Attributes APT28 (Russia/GRU) Attacks on Political Institutions; Joins EU–NATO Condemnation

The Czech MFA, alongside Germany, the EU, and NATO, formally attributed to Russia's GRU-linked APT28 a campaign exploiting a Microsoft Outlook zero-day (CVE-2023-23397) to target Czech political entities and government institutions. The EU Council issued a parallel statement condemning Russia's 'continuous pattern of irresponsible behaviour in cyberspace.'

Czech Ministry of Foreign Affairs
Jan 1, 2020guidanceofficial
National Cybersecurity Strategy of the Czech Republic 2021–2025 Adopted

The Czech Government adopted its second National Cybersecurity Strategy, covering 2021–2025 with an accompanying Action Plan. Built with input from dozens of public and private organisations, it established binding goals across three pillars: confidence in cyberspace, strong international alliances, and a resilient digital society — and set the institutional agenda for NÚKIB's regulatory expansion.

NÚKIB
May 3, 2019guidanceofficial
Prague 5G Security Conference — 'Prague Proposals' Published

Hosted by the Czech Government and NÚKIB, the conference brought together representatives from 30+ countries, the EU, and NATO to address 5G supply-chain risks. The resulting 'Prague Proposals' became an internationally influential framework recommending vendor evaluation based on rule-of-law, transparency, and security — effectively providing the geopolitical and technical rationale for restricting high-risk vendors such as Huawei in critical networks.

Czech Government
Dec 17, 2018guidanceofficial
NÚKIB Issues First National Security Warning Against Huawei and ZTE Products

NÚKIB issued a formal warning declaring that hardware and software of Huawei Technologies and ZTE Corporation posed a threat to national security, citing Chinese law's compelled-cooperation provisions for private companies. The warning directed critical-infrastructure operators to treat these vendors as high-risk and pre-dated similar actions by most EU partners, establishing Czechia as an early mover in the Western 5G vendor debate.

NÚKIB
Aug 1, 2017lawofficial
NÚKIB Established as Standalone National Cybersecurity Authority

Act No. 205/2017 Coll. amended the 2014 Cybersecurity Act to separate cybersecurity functions from the National Security Authority and create the National Cyber and Information Security Agency (NÚKIB) as the dedicated central administrative body. NÚKIB assumed responsibility for regulation and audit of critical entities, national CERT/CSIRT coordination, and international cyber diplomacy — also transposing core NIS Directive obligations into Czech law.

NÚKIB
Jul 23, 2014lawofficial
Czech Cybersecurity Act No. 181/2014 Enacted — First Dedicated Cybersecurity Law in Central Europe

The Czech Parliament enacted Act No. 181/2014 Coll. on Cyber Security, establishing the country's first comprehensive cybersecurity legal framework. It imposed mandatory security measures and incident-reporting obligations on operators of critical information infrastructure and important information systems, and created the National Security Authority as the supervising body — one of the earliest such laws in the EU, predating the EU NIS Directive by two years.

NÚKIB

Czechia - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →