NIS2 · Czech Act No. 264/2025

NIS2 and the new Czech Cybersecurity Act: what you must get done by the end of 2026

The Act has been in force since 1 November 2025 and the NÚKIB registration wave is over. What runs now is the part that matters: roughly a one-year deadline to actually implement the security measures. This page is not about “what is NIS2” — it is about HOW to meet the requirements in practice, and how to find out where your company is not compliant. No legalese, plain IT language.

6–8k companies
newly regulated in Czechia
18 sectors
from energy to manufacturing and IT
up to CZK 250M
fine under the higher-obligations regime
Lenka and Roman Krutina, owners of ICT-GROUP
Lenka & Roman Krutina
Our personal guarantee

“We won't sell you hardware you don't need, and we won't bill you for every phone call. That's something we can put our names to with a clear conscience.”

Roman & Lenka Krutina
Owners, ICT-GROUP
Where we are

Status 2026: registration is done. What gets checked now is what you actually implemented

The “does NIS2 apply to us?” phase is over — those affected have registered (and a newly qualifying company must register within 60 days). From the registration decision, every company has roughly one year to implement the security measures defined by the implementing decree. That is the part you cannot solve with paperwork: the measures must actually work on your network, your devices and your Microsoft 365 — and NÚKIB can come and check.

The second change: accountability moved from the IT department to company management. The statutory body approves the measures and oversees them — “our IT guys handle that” is no longer an acceptable answer.

Time remaining
days until the end of 2026

The implementation deadline runs roughly one year from the registration decision — for companies registered around the turn of 2025/26 that means late 2026. Rolling out MFA, backups, logging and access control across a company does not take a week.

  • 1 Nov 2025 — Act No. 264/2025 in force
  • 31 Dec 2025 — main NÚKIB registration wave
  • now — implementing the measures (≈ 12 months from the decision)

Missed the registration? The obligation has not gone away — register via the NÚKIB portal as soon as possible and start implementing the measures in parallel; the deadlines run from the registration decision.

Obligations in IT language

Lower vs. higher obligations: what it means in practice

The Act sorts companies into two regimes by how significant their service is. Both share the same core — the difference is the scope of measures, the strictness of supervision and the size of the fines.

Lower-obligations regime
Most companies with 50+ employees in the 18 sectors
  • The base set of security measures per the decree (access control, MFA, backups, updates, logging)
  • Reporting significant incidents via the NÚKIB portal — initial report typically within 24 hours of detection
  • Management accountability for approving and overseeing the measures
Higher-obligations regime
Providers of more significant regulated services
  • Everything from the lower regime — plus a broader, stricter set of measures (risk management, supply chain, cryptography, detection)
  • Stricter NÚKIB supervision including on-site inspections
  • Fines up to CZK 250 million, or a percentage of worldwide turnover

Which regime you fall into was determined by your NÚKIB registration. The specific measures are set by the implementing decrees — and that is exactly what the mapping below translates into Microsoft 365 terms.

The differentiator

NIS2 → Microsoft 365 mapping: where exactly the legal requirements get configured

Lawyers tell you WHAT the law wants. Here is WHERE it actually gets configured if your company runs on Microsoft 365 — by the areas of Article 21 of NIS2 as transposed by the Czech Act. Our paid audit measures roughly 50 specific controls across these areas.

Multi-factor authentication & passwords

MFA enforced for all users and admins via Conditional Access (no app exclusions), SMS disabled, phishing-resistant methods, every account “MFA capable”. Entra ID.

Access control & privileged accounts

Admin-account hygiene, least privilege on Windows, LAPS, guest restrictions and external-sharing limits (SharePoint, Teams, calendars). Entra ID + M365.

Monitoring & logging

Unified audit log on, no mailbox outside auditing, security events on Windows endpoints, time sync for log correlation. Purview + Intune.

Protection against malware

Defender policies enforced, Attack Surface Reduction rules, Safe Links / Safe Attachments, anti-phishing with quarantine, Gatekeeper on macOS. Intune + Defender for O365.

Cryptography & data protection

Disk encryption (BitLocker/FileVault) with recovery-key escrow, DLP policies, data classification via sensitivity labels. Intune + Purview.

Network & e-mail security

SPF and DMARC on all domains, legacy authentication blocked, SMTP AUTH off, SMB v1 and other legacy protocols disabled. Exchange + Intune.

Configuration management & updates

Intune baseline re-applied regularly (Config Refresh), OS updates enforced including macOS, security-patch rollback blocked. Intune.

Roles, responsibilities & suppliers

Who may create apps, groups and join devices; admin consent workflow; third-party cloud storage restrictions. Entra ID.

Under the hood: CIS Microsoft 365 Foundations v7, CIS Intune (Windows 11 + macOS) and CIS Defender benchmarks — each control tied to a specific NIS2 article.

Where am I not compliant?

Find out before NÚKIB does — or an attacker

The internet is full of “does NIS2 apply to me?” calculators. What nobody offers: looking into your company's actual environment and telling you which requirements you already meet and which you don't. We have two tools for that.

Step 1 · free
Free outside-in scan — 5 minutes

Enter your company domain and see what is visible from the outside: e-mail security (SPF/DMARC — network security under NIS2), certificates and encryption, passwords leaked to the dark web, Microsoft 365 gaps. 13 checks, report to your inbox, no salesperson calls.

Step 2 · the full check
NIS2 audit of Microsoft 365 — CZK 14,900

An inside check against the full matrix above: ~50 controls across Entra, Intune, Defender, Exchange and Purview. Read-only access (Global Reader), results within 2 business days, report + a 90-minute consultation. Ordered online, no meeting.

Penalties & supervision

What NÚKIB inspects — and what you risk without the measures

Supervision belongs to NÚKIB: it can request evidence, run inspections and impose corrective measures as well as fines. Under the higher-obligations regime a fine can reach up to CZK 250 million (alternatively calculated as a percentage of worldwide turnover); the lower regime carries smaller but still painful rates. On top of the fines there is personal accountability of management — the statutory body approves and oversees the measures, not the IT department.

In practice: a binder of policies will not survive an inspection. What gets checked is whether the measures actually run — whether every account has MFA, backups get restore-tested, logs are collected and incidents reported within 24 hours. Exactly the things our audit measures.

FAQ

NIS2 and the new Czech Act: what companies ask

Who does NIS2 apply to in Czechia?+

Organisations in 18 regulated sectors — from energy, healthcare and transport to manufacturing, waste management and IT services — with 50 or more employees, or annual turnover above €10 million. An estimated 6,000–8,000 companies in Czechia. It works by self-identification: each company must determine its own obligation.

What deadlines are running now?+

Act No. 264/2025 has been in force since 1 Nov 2025. The main NÚKIB registration wave ended 31 Dec 2025 (a newly qualifying company registers within 60 days). From the registration decision, roughly one year runs for implementing the security measures — for most companies a deadline around the end of 2026. Significant incidents are reported via the NÚKIB portal, the initial report typically within 24 hours.

What are the fines?+

Under the higher-obligations regime up to CZK 250 million, alternatively capped as a percentage of worldwide annual turnover. The lower regime carries smaller rates. On top of that, the Act introduces personal accountability of company management for approving and overseeing the measures.

We missed the NÚKIB registration. What now?+

The obligation has not disappeared — register via the NÚKIB portal as soon as possible and start implementing the measures in parallel. The implementation deadline runs from the registration decision, so delay only makes the problem bigger.

How does NIS2 relate to Microsoft 365?+

Most of the Act's requirements — MFA, access control, logging, encryption, e-mail protection — are configured, for companies running on Microsoft 365, exactly there: in Entra ID, Intune, Defender and Purview. The mapping of legal areas to specific M365 controls is on this page above; our audit measures them with roughly 50 checks.

Where should we start?+

Find out where you stand: the free outside-in scan takes 5 minutes, the full Microsoft 365 check against NIS2 takes 2 business days. The findings become a concrete to-do list — ordered by risk, not by paragraphs.

A year to implement the measures goes by fast

Don't start with a binder. Start by finding out where your company actually stands — the rest is craft we can do for you or help you with.

No pressure, no commitment. We only get in touch when something changes for the worse.