New Czech Cybersecurity Act is effective

Contacts

vojtech chloupek module
Vojtěch Chloupek

Partner
Czech Republic

I enjoy working with innovative, creative and technology-rich businesses. Having joined our firm in 2009, I head up our Intellectual Property and Tech & Comms Groups in the Czech Republic and Slovakia.

jan kuklinca Module
Ján Kuklinca

Partner
Czech Republic

I am a partner in the Czech Tech & Comms sector group.

tomas kolouch Module
Tomáš Kolouch

Associate
Czech Republic

I am a junior associate based in our Prague office, focusing on Privacy and Data Protection and Intellectual Property Law.

On November 1, 2025, a new Cybersecurity Act (the "Cybersecurity Act") has come into effect. The Cybersecurity Act implements the Directive (EU) 2022/2555 (the "NIS2 Directive"). The Cybersecurity Act significantly expands the number of regulated sectors and services. Experts anticipate that the Cybersecurity Act will affect 10 to 20 thousand private and public entities.

What to do?

By December 31, 2025, organizations need to

  • self-assess whether the Cybersecurity Act applies to them and

  • notify their regulated services to the National Cyber and Information Security Agency ("NÚKIB").

Considering the complexity of the self-assessment and the end-year rush, we recommend that all entities involved in the regulated sectors start preparing as soon as possible to comply with the new requirements.

Read more in English

Read more in Czech

Latest insights

More Insights
featured image

EU Digital Omnibus package: Major Changes to the Data Act Proposed

8 minutes Nov 19 2025

Read More
featured image

CMA Launches Major Consumer Enforcement Drive Focused On Online Pricing Practices

6 minutes Nov 19 2025

Read More
featured image

Guide to EU and UK Pharmaceutical Regulatory Law (Ninth Edition), 2025, Edited by Sally Shorthose and Pieter Erasmus

3 minutes Nov 19 2025

Read More