What it is about
European Union Directive 2022/2555, known as NIS2, establishes a common framework for cybersecurity for EU Member States. The Czech Republic has transposed it into national law through Act No. 264/2025 Coll. On Cybersecurity, which has been in force since 1 November 2025. Supervision of compliance in the Czech Republic is carried out by the National Office for Cyber and Information Security, abbreviated as NÚKIB.
The Act replaces the previous regulation and expands the scope of entities subject to security obligations. It no longer applies only to operators of critical information systems, but to a broader range of companies and institutions across sectors.
Two modes of obligation
The law distinguishes between two regimes based on the significance of the service provided and the size of the organisation: the higher obligations regime and the lower obligations regime.
- To higher obligations regime This typically applies to larger or more significant providers of regulated services, where the impact of a potential incident on sector operations or users is highest.
- Reduced obligations regime specifies a narrower set of obligations representing basic organisational and technical safety measures.
One regulated person always falls under only one regime, if even one of their services meets the conditions for a higher regime, the higher regime applies to the entire person. The division into regimes is established by NÚKIB through an implementing regulation. Whether the obligation concerns a specific company and in which regime must always be verified individually: the field of activity and company size alone do not automatically provide the answer.
What the law typically requires
Regulated entities must implement risk management and appropriate organisational and technical security measures. In practice, this includes, among other things, protecting networks and information systems, access control, managing supply chain risks, having an incident response plan, and the ability to record, assess, and report incidents to NÚKIB within legally prescribed deadlines.
The scope of specific measures varies depending on the regime: the higher regime requires a broader and more extensive set of measures than the lower one. What both regimes have in common is that this is an ongoing obligation, not a one-off task, measures must be maintained, updated, and their operation must be demonstrable, not just introduced once and then left alone.
Why this also concerns companies that previously did not know about NIS2
The previous legal framework for cybersecurity in the Czech Republic applied only to a narrower group of operators of critical and important information systems. The new law expands the scope of regulated entities across sectors, today, companies that previously believed they were not subject to statutory cybersecurity obligations are also asking questions: smaller manufacturing enterprises, providers of services for public administration, or firms in the supply chain of larger regulated entities. Even where a company has no statutory obligation, implementing network security solutions makes practical sense on its own; regulation merely names what is already reasonable to have in place.
Where a firewall fits in
Firewall covers the technical part of perimeter and internal network protection requirements, operational segmentation according to data sensitivity, intrusion control and prevention (see our article on UTM functions), secure remote access via VPN and network activity logs, which are also useful for demonstrating compliance with required measures.
This is not the only measure required by law. It also includes access control, backups, supplier management and incident response plans. However, it is one of the tangible technical foundations on which the rest can be built. A company that has so far relied solely on a router from its provider (see difference between a router and a firewall), which usually addresses the basic gap first.
How to determine whether the law applies to you
Classification under NIS2 and assignment to a specific regime is a legal matter that should be verified individually, ideally with a lawyer or directly with the National Cyber and Information Security Bureau (NÚKIB). As an initial step for guidance, we offer a free test on check.nis2ok.cz, a sister project focused specifically on navigating this area.
The technical aspects, firewall, network segmentation and network security, are handled by us. The legal classification and formal requirements with NÚKIB need to be discussed with a specialist in that field.