Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures
Act No. 264/2025 Coll., Cybersecurity Act, Sections 13-14
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 10 months, effective 1 November 2025.
A sector security regimes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds a poskytovatel regulované služby (provider of a regulated service) under Sections 3 to 5, drawn from 15 named sectors, where you are a medium or large enterprise under Commission Recommendation 2003/361/EC or are otherwise significant for essential social, economic or security functions regardless of size; Section 18 names an online marketplace, an internet search engine and a social-networking-platform provider among the digital-infrastructure-and-services sector's regulated services. The wider sector classes this binds (public administration, energy, manufacturing, food, chemicals, water, waste, transport, financial markets, healthcare, science and education, postal and courier services, defence, and space) are a sector designation no activity in this vocabulary expresses, so they are not separately flagged here.
- Adopt and implement organisational and technical security measures adequate and proportionate to securing the regulated service's proper provision and the cybersecurity of the assets you use to provide it, within a scope you determine and must regularly review.
- If you are in the higher-obligations regime, cover at least: an information security management system, top-management requirements, security roles, security-policy and documentation management, asset management, risk management, supplier management, human-resources security, change management, acquisition and development security, access management, handling of cybersecurity events and incidents, business-continuity management and cybersecurity auditing, plus physical security, communications-network security, identity administration and access-rights management, detection, logging and evaluation of cybersecurity events, application security, cryptographic algorithms, availability assurance, and, where applicable, security of industrial, control or similarly specific technical assets.
- If you are in the lower-obligations regime, a reduced set applies: a minimum cybersecurity assurance system, top-management requirements, asset management, risk management, human-resources security, business-continuity management, access management, identity and authorisation management, detection and logging of cybersecurity events, incident handling, communications-network security, application security, and cryptographic algorithms.
- Where a supplier implements a security measure on your behalf, select that supplier consistent with the measure's requirements and write those requirements into your contract with the supplier.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
A Section 13 or Section 18(1) infringement is an administrative offence (přestupek) under Section 59, not a criminal offence.
Penalty structure
Section 59(4)(a) sets the fine for a higher-obligations (essential-entity) provider's Section 59(1)(f) infringement (failing to establish or carry out a security measure under Section 13(2) or Section 18(1)) at up to CZK 250,000,000 or up to 2 percent of the offender's group worldwide net annual turnover for the preceding accounting period, whichever is higher, mirroring NIS2 Article 34(4). Section 59(4)(b) sets the same infringement by a lower-obligations (important-entity) provider under Section 59(2)(f) at up to CZK 175,000,000 or up to 1.4 percent of that turnover, whichever is higher, mirroring NIS2 Article 34(5).
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- CZK
- Fixed cap
- 250,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB, the National Cyber and Information Security Agency), the central administrative authority for cybersecurity under Section 42.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://portal.nukib.gov.cz/pruvodce-novym-zakonem-o-kyberneticke-bezpecnosti
- Guidance body
- Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB)
- Open questions
- Which classification and technical-measures vyhlášky (implementing decrees) has NÚKIB issued under Sections 8(2) and 14 since the Act's 1 November 2025 effective date, and do any of them narrow the Section 14 measures list as it applies specifically to an online marketplace, internet search engine or social-networking-platform provider?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 13 requires a provider of a regulated service, within the scope it determines for its own assets, to adopt and implement organisational and technical security measures adequate to secure the regulated service's proper provision and the cybersecurity of its assets.
Section 14(1) sets at least 14 organisational measure categories for a provider in the higher-obligations (essential-entity) regime, including an information security management system, top-management requirements, security roles, security-policy and documentation management, asset, risk, supplier and change management, human-resources security, acquisition and development security, access management, incident handling, business-continuity management and cybersecurity auditing, plus at least 11 technical measure categories including physical security, communications-network security, identity and access-rights administration, event detection, logging and evaluation, application security, cryptographic algorithms, availability assurance, and security of industrial or control-system assets.
Section 14(2) sets a reduced 13-category combined list for a provider in the lower-obligations (important-entity) regime. Section 18 extends this duty expressly to a provider of DNS resolution, trust, top-level-domain registry, cloud computing, data-centre, content-delivery-network, online-marketplace, internet-search-engine, social-networking-platform, managed-service or managed-security-service offerings, transposing NIS2 Article 21.
When LexLint raises it
operates_social_platform
Read the law
Act No. 264/2025 Coll., consolidated text, zakonyprolidi.cz, Sections 13-14 and 18