Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification
Act No. 264/2025 Coll., Cybersecurity Act, Sections 15-16
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 10 months, effective 1 November 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds a poskytovatel regulované služby under Sections 3 to 5, which Section 18 extends by name to an online marketplace, an internet search engine and a social-networking-platform provider among other digital-infrastructure-and-services roles; the wider sector classes this also binds are not separately flagged here, for the reason given on this jurisdiction's companion security-measures row.
- If you are in the higher-obligations regime, notify NÚKIB no later than 24 hours after detecting a qualifying cybersecurity incident, with an initial report giving your identifying details, basic incident data, and whether you believe the incident was caused by an unlawful intervention or could have a cross-border impact.
- If you are in the lower-obligations regime, notify the Národní CERT on the same 24-hour clock instead, for a qualifying incident with significant impact on your service's provision.
- For an incident with significant impact, follow with a report no later than 72 hours after detection that updates your initial assessment and gives the incident's impact and, where available, indicators of compromise.
- Submit an interim report on request, and a final report no later than 30 days after the 72-hour report, or, if the incident is still ongoing at that point, a progress report followed by a final report within 30 days of resolution.
- Report through NÚKIB's Portál Úřadu where you can; otherwise a higher-obligations provider emails NÚKIB or uses its data-box address, and a lower-obligations provider does the same with the Národní CERT.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
A Section 16 reporting infringement is an administrative offence (přestupek) under Section 59, not a criminal offence.
Penalty structure
The same Section 59(4)(a) and (b) tiers that govern a Section 13/18 infringement govern a Section 59(1)(h) or 59(2)(h) infringement (failing to submit the initial incident report under Section 16(1), failing to complete required incident data under Section 16(3), or failing to report an incident under Section 18(2)): up to CZK 250,000,000 or 2 percent of worldwide turnover for a higher-obligations provider, and up to CZK 175,000,000 or 1.4 percent for a lower-obligations provider, whichever amount is higher in each case.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- CZK
- Fixed cap
- 250,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB), directly for a higher-obligations provider and, for a lower-obligations provider, through the Národní CERT it may contract to operate under Section 53.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://portal.nukib.gov.cz/pruvodce-novym-zakonem-o-kyberneticke-bezpecnosti
- Guidance body
- Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB)
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 15 requires a provider in the higher-obligations regime to report a qualifying cybersecurity incident directly to NÚKIB, and a provider in the lower-obligations regime to report to the Národní CERT. Section 16 sets a graduated notification clock, transposing NIS2 Article 23.
An initial report is due no later than 24 hours after detecting the incident, giving the provider's identifying details, basic incident data, and whether the provider believes the incident was caused by an unlawful intervention or could have a cross-border impact.
For an incident with significant impact, a follow-up report is due no later than 72 hours after detection, updating that assessment and giving an initial evaluation of the incident's impact and, where available, indicators of compromise.
An interim report is due on NÚKIB's or the Národní CERT's request, and a final report is due no later than 30 days after the 72-hour report; if the incident is still ongoing at that point, a progress report is due instead, followed by a final report within 30 days of resolution. A provider reports through NÚKIB's Portál Úřadu where possible; a higher-obligations provider otherwise emails NÚKIB or uses its data-box address, and a lower-obligations provider does the same with the Národní CERT.
When LexLint raises it
operates_social_platform
Read the law
Act No. 264/2025 Coll., consolidated text, zakonyprolidi.cz, Sections 15-16