Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Back to the NIS2 overview
NIS2 · Czech Republic

NIS2 in Czech Republic — transposition status and what’s changed

Czech Republic transposed NIS2 via Act No. 264/2025 Coll. on Cybersecurity, which was signed in June 2025, published in the Collection of Laws on 4 August 2025, and entered into force on 1 November 2025. The new act replaces the previous Zákon o kybernetické bezpečnosti rather than amending it. Czechia was on the European Commission’s 7 May 2025 reasoned-opinion list for missing the original 17 October 2024 deadline; the November 2025 act closed that out. The supervisory authority is NÚKIB — Národní úřad pro kybernetickou a informační bezpečnost. Czech transposition includes its own national register and notification cadence rules that diverge slightly from the directive’s defaults.

National competent authority
NÚKIB

Authoritative source for Czech Republic-specific NIS2 guidance, registration, and incident reporting.

1.0 / What Czech entities face under NIS2

The Czech industrial base — heavy manufacturing, automotive supply (notably the Škoda / VW Group ecosystem), energy, regional banking, and a deep managed-services layer — places thousands of Annex I and Annex II entities into NIS2 scope. The Czech Republic also hosts a disproportionate concentration of digital-infrastructure providers (data centres, regional cloud, MSPs serving German-speaking markets), which means many Czech entities are simultaneously regulated under Annex I and act as suppliers to other regulated entities elsewhere in the EU.

Mid-market Czech entities are now expected to hold the same shape of supplier-assurance evidence that multinational regulated buyers ask for, on a tighter notification cadence than most have ever operated. The work cluster is real and the timeline is now.

2.0 / Act 264/2025 and what NÚKIB is asking for

Act No. 264/2025 Coll. on Cybersecurity replaced the previous statutory regime in November 2025, aligning Czech law with NIS2 and replacing the old system-based categories with providers of "regulated services" (regulovaná služba), sorted into a higher-obligations and a lower-obligations regime, with self-identification and registration via the NÚKIB portal. NÚKIB publishes extensive Czech-language support materials — methodologies, manuals, regime-specific step-by-step guides — and the implementing decree catalogue is more prescriptive than the EU baseline.

Notification cadence is broadly directive-aligned (24-hour early warning, 72-hour incident notification), with Czech templates and registration in the NÚKIB portal. NÚKIB’s regime-specific manuals are particularly relevant for MSPs serving Czech regulated buyers.

3.0 / Supplier-risk patterns particular to Czech Republic

Czech regulated entities sit inside cross-border supply chains tied tightly to German manufacturing — particularly the VW Group ecosystem via Škoda — which means supplier inheritance flows both ways across the border. A Czech automotive supplier increasingly inherits German NIS2 obligations from its OEM buyers AND must satisfy its own Czech NÚKIB obligations as an Annex II important entity.

The high concentration of MSPs serving the Czech mid-market is a distinctive pattern: many of these providers are themselves Annex I digital-infrastructure entities under NIS2, and they are increasingly central to the supplier-assurance conversation as both buyer and supplier. Contractual incident-notification SLAs from suppliers — particularly ICT services suppliers — are a natural negotiation point as Czech buyers work through how to inherit-up to their own 72-hour notification windows.

4.0 / How Vittnor fits the Czech market

Czech-language UI is on the roadmap — after Slovak in the language sequence. NÚKIB-aligned evidence templates are planned against the regulator’s published methodologies — particularly the prescriptive measure catalogue of the higher-obligations regime. Designed so one supplier file supports both the inherited German NIS2 obligations and the native Czech ones in Czech-German and Czech-Slovak supply chains — cross-buyer routing is planned for later versions.

The MSP / MSSP partner channel is particularly relevant for the Czech market — co-delivery economics work well where a Czech MSP is itself regulated and serves multiple regulated mid-market buyers. The partner page covers the channel mechanics; the supplier-side surface of Vittnor — Supply Chain Assurance for the mid-market — keeps your questionnaire answers and evidence in one library, so the next request starts from what you already proved — cross-buyer reuse is planned for later versions.

5.0 / Next step

Where are you with NIS2 supplier work in Czech Republic?

Two ways to find out fast — a five-minute readiness check, or a practitioner-walked exposure picture in two to three weeks.