The Czech Republic's NIS2 transposition is enacted and in force. Act No. 264/2025 Coll., the Cybersecurity Act (zákon o kybernetické bezpečnosti), was published in the Collection of Laws on 4 August 2025 and, under its own Section 73, entered into force on the first day of the third calendar month following publication, 1 November 2025.
Section 72 repeals the prior Act No. 181/2014 Coll. on cybersecurity outright, along with several of its implementing decrees, so the 2014 regime does not remain in force alongside the new Act.
Sections 3 to 5 bind a poskytovatel regulované služby (provider of a regulated service) drawn from 15 named sectors, including public administration, energy, manufacturing, digital infrastructure and services, financial markets, healthcare, and defence, where the provider is a medium or large enterprise under Commission Recommendation 2003/361/EC or is otherwise significant for essential social, economic or security functions regardless of size.
Section 8 splits providers into a vyšší povinnosti (higher-obligations) regime, matching NIS2's essential-entity class, and a nižší povinnosti (lower-obligations) regime, matching its important-entity class.
Section 18 names an online marketplace, an internet search engine and a social-networking-platform provider, alongside DNS resolution, top-level-domain registry, cloud computing, data-centre, content-delivery-network and trust-service providers, among the regulated services of the digital-infrastructure-and-services sector.
Section 13 requires a regulated-service provider to adopt organisational and technical security measures, listed at Section 14, transposing NIS2 Article 21, and Sections 15 and 16 set a graduated incident-notification clock (an initial report within 24 hours, a follow-up within 72 hours, and a final report within 30 days of the 72-hour report, or a progress report if the incident is still ongoing at that point) transposing NIS2 Article 23.
The Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB, the National Cyber and Information Security Agency), seated in Brno, is the central administrative authority for cybersecurity and receives reports from a higher-obligations provider directly; a lower-obligations provider reports instead to the Národní CERT, the national coordination team NÚKIB may contract out under Section 53.
No instrument reviewed here imposes an independent product-security or market-placement duty on a manufacturer: that rests on the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847), which is documented at the European Union level and is not restated here.
The Czech Republic's own Cyber Resilience Act (CRA) adaptation act, naming the Czech Trade Inspection Authority (Česká obchodní inspekce) as market-surveillance authority for most product categories and NÚKIB as the national single reporting point, was submitted by the Ministry of Industry and Trade for interministerial comment in July 2026 and was heading to the Chamber of Deputies as of this review, without having been enacted and without affecting the Cyber Resilience Act's own direct applicability.
The Czech Republic has no free-standing reasonable-security or information-security-programme statute reaching a business with no sector gate; personal-data breach notification to the Úřad pro ochranu osobních údajů and to the affected person is separate law, General Data Protection Regulation (GDPR) Articles 33 and 34, which sits in the privacy topic rather than here, as does GDPR Article 32's security-of-processing obligation.