The Act has been in force since 1 November 2025 and the NÚKIB registration wave is over. What runs now is the part that matters: roughly a one-year deadline to actually implement the security measures. This page is not about “what is NIS2” — it is about HOW to meet the requirements in practice, and how to find out where your company is not compliant. No legalese, plain IT language.
“We won't sell you hardware you don't need, and we won't bill you for every phone call. That's something we can put our names to with a clear conscience.”
The “does NIS2 apply to us?” phase is over — those affected have registered (and a newly qualifying company must register within 60 days). From the registration decision, every company has roughly one year to implement the security measures defined by the implementing decree. That is the part you cannot solve with paperwork: the measures must actually work on your network, your devices and your Microsoft 365 — and NÚKIB can come and check.
The second change: accountability moved from the IT department to company management. The statutory body approves the measures and oversees them — “our IT guys handle that” is no longer an acceptable answer.
The implementation deadline runs roughly one year from the registration decision — for companies registered around the turn of 2025/26 that means late 2026. Rolling out MFA, backups, logging and access control across a company does not take a week.
Missed the registration? The obligation has not gone away — register via the NÚKIB portal as soon as possible and start implementing the measures in parallel; the deadlines run from the registration decision.
The Act sorts companies into two regimes by how significant their service is. Both share the same core — the difference is the scope of measures, the strictness of supervision and the size of the fines.
Which regime you fall into was determined by your NÚKIB registration. The specific measures are set by the implementing decrees — and that is exactly what the mapping below translates into Microsoft 365 terms.
Lawyers tell you WHAT the law wants. Here is WHERE it actually gets configured if your company runs on Microsoft 365 — by the areas of Article 21 of NIS2 as transposed by the Czech Act. Our paid audit measures roughly 50 specific controls across these areas.
MFA enforced for all users and admins via Conditional Access (no app exclusions), SMS disabled, phishing-resistant methods, every account “MFA capable”. Entra ID.
Admin-account hygiene, least privilege on Windows, LAPS, guest restrictions and external-sharing limits (SharePoint, Teams, calendars). Entra ID + M365.
Unified audit log on, no mailbox outside auditing, security events on Windows endpoints, time sync for log correlation. Purview + Intune.
Defender policies enforced, Attack Surface Reduction rules, Safe Links / Safe Attachments, anti-phishing with quarantine, Gatekeeper on macOS. Intune + Defender for O365.
Disk encryption (BitLocker/FileVault) with recovery-key escrow, DLP policies, data classification via sensitivity labels. Intune + Purview.
SPF and DMARC on all domains, legacy authentication blocked, SMTP AUTH off, SMB v1 and other legacy protocols disabled. Exchange + Intune.
Intune baseline re-applied regularly (Config Refresh), OS updates enforced including macOS, security-patch rollback blocked. Intune.
Who may create apps, groups and join devices; admin consent workflow; third-party cloud storage restrictions. Entra ID.
Under the hood: CIS Microsoft 365 Foundations v7, CIS Intune (Windows 11 + macOS) and CIS Defender benchmarks — each control tied to a specific NIS2 article.
The internet is full of “does NIS2 apply to me?” calculators. What nobody offers: looking into your company's actual environment and telling you which requirements you already meet and which you don't. We have two tools for that.
Enter your company domain and see what is visible from the outside: e-mail security (SPF/DMARC — network security under NIS2), certificates and encryption, passwords leaked to the dark web, Microsoft 365 gaps. 13 checks, report to your inbox, no salesperson calls.
An inside check against the full matrix above: ~50 controls across Entra, Intune, Defender, Exchange and Purview. Read-only access (Global Reader), results within 2 business days, report + a 90-minute consultation. Ordered online, no meeting.
Supervision belongs to NÚKIB: it can request evidence, run inspections and impose corrective measures as well as fines. Under the higher-obligations regime a fine can reach up to CZK 250 million (alternatively calculated as a percentage of worldwide turnover); the lower regime carries smaller but still painful rates. On top of the fines there is personal accountability of management — the statutory body approves and oversees the measures, not the IT department.
In practice: a binder of policies will not survive an inspection. What gets checked is whether the measures actually run — whether every account has MFA, backups get restore-tested, logs are collected and incidents reported within 24 hours. Exactly the things our audit measures.
Organisations in 18 regulated sectors — from energy, healthcare and transport to manufacturing, waste management and IT services — with 50 or more employees, or annual turnover above €10 million. An estimated 6,000–8,000 companies in Czechia. It works by self-identification: each company must determine its own obligation.
Act No. 264/2025 has been in force since 1 Nov 2025. The main NÚKIB registration wave ended 31 Dec 2025 (a newly qualifying company registers within 60 days). From the registration decision, roughly one year runs for implementing the security measures — for most companies a deadline around the end of 2026. Significant incidents are reported via the NÚKIB portal, the initial report typically within 24 hours.
Under the higher-obligations regime up to CZK 250 million, alternatively capped as a percentage of worldwide annual turnover. The lower regime carries smaller rates. On top of that, the Act introduces personal accountability of company management for approving and overseeing the measures.
The obligation has not disappeared — register via the NÚKIB portal as soon as possible and start implementing the measures in parallel. The implementation deadline runs from the registration decision, so delay only makes the problem bigger.
Most of the Act's requirements — MFA, access control, logging, encryption, e-mail protection — are configured, for companies running on Microsoft 365, exactly there: in Entra ID, Intune, Defender and Purview. The mapping of legal areas to specific M365 controls is on this page above; our audit measures them with roughly 50 checks.
Find out where you stand: the free outside-in scan takes 5 minutes, the full Microsoft 365 check against NIS2 takes 2 business days. The findings become a concrete to-do list — ordered by risk, not by paragraphs.
Don't start with a binder. Start by finding out where your company actually stands — the rest is craft we can do for you or help you with.
No pressure, no commitment. We only get in touch when something changes for the worse.