Does your company meet the Czech Cybersecurity Act?
The Act asks companies for eleven things. These are eleven questions that tell you where you stand — without legalese and without a consultant.
NIS2 checklist
11 questions, one per measure the Act requires. You answer yes, no, or don't know. It takes five minutes, no registration.
You'll see the result instantly on screen: an overall score, an eleven-area traffic light, and three steps you can start tomorrow morning. Your answers stay in your browser.
What you get
Instantly on screen, free
- ✓an overall score and a ten-area traffic light — where it's green, red or “we don't know”,
- ✓three steps you can start tomorrow morning.
The report by e-mail — also free
- ✓an action plan for each of the eleven areas — what to do and in what order,
- ✓the proof to ask for in each area — exactly what an inspection wants to see,
- ✓optionally: a 90-day reminder of how far along the measures are.
Where the questions come from
Each question maps to one measure of Decree No. 410/2025 Coll. (lower obligations regime), § 3 to § 13. These are not generic tips from the internet — it is the law translated into plain language.
The context — deadlines, regimes and penalties — is on our NIS2 hub.
Why tell us, of all people
Out of 262 companies that ran our free online audit, 151 had at least one serious security finding. Continuity plays a bigger role in that than you'd expect — accounts left behind by former employees are among the most common findings.
Microsoft Solutions Partner · Cloudflare Partner · Managing IT since 2004
Roman & Lenka
owners of ICT-GROUP
We've been managing IT hands-on since 2004. We built this check the way we'd want to receive it ourselves — completely free, no strings attached.
Want the outside view too?
The Continuity Check shows what your IT looks like from the inside. The free online security audit looks at it from the outside — 13 checks, 5 minutes, no meeting. Each complements the other.
One hour of IT support, free
Complete the Continuity Check and save your result to the client zone — then an hour of online IT support is yours, free. It isn't a sales call, it's an hour of work. We'll take whatever your result flagged: set up backups to the 3-2-1 rule, create an emergency account, work out who actually owns your domains.
The check takes 5 minutes. You then pick your hour in our calendar — no account and nothing to install.
Frequently asked questions
We have an external IT company — does this apply to us?
Yes — and possibly more than companies with an in-house admin. CloudNordic and Kaseya are both cases where the failure originated at the supplier and its customers paid for it. The same applies to you, just substitute “supplier” for “IT admin”: keep your own copy of the backups, your own access, and an exit agreed in the contract.
Isn't this a sign of distrust towards our IT admin?
The opposite — it protects them most of all. As long as everything lives in their head, they can't take a calm holiday, let alone proper sick leave. A good admin welcomes the sealed envelope and a second emergency account.
Is this the same as your online audit?
No. The audit is a passive scan from the outside — 13 checks of what's publicly visible from your domain. The Continuity Check asks inward: who owns what, who knows what, and when you last tested it. Each complements the other.