Law / Czech Republic

Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification

Act No. 264/2025 Coll., Cybersecurity Act, Sections 15-16

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 10 months, effective 1 November 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds a poskytovatel regulované služby under Sections 3 to 5, which Section 18 extends by name to an online marketplace, an internet search engine and a social-networking-platform provider among other digital-infrastructure-and-services roles; the wider sector classes this also binds are not separately flagged here, for the reason given on this jurisdiction's companion security-measures row.
  • If you are in the higher-obligations regime, notify NÚKIB no later than 24 hours after detecting a qualifying cybersecurity incident, with an initial report giving your identifying details, basic incident data, and whether you believe the incident was caused by an unlawful intervention or could have a cross-border impact.
  • If you are in the lower-obligations regime, notify the Národní CERT on the same 24-hour clock instead, for a qualifying incident with significant impact on your service's provision.
  • For an incident with significant impact, follow with a report no later than 72 hours after detection that updates your initial assessment and gives the incident's impact and, where available, indicators of compromise.
  • Submit an interim report on request, and a final report no later than 30 days after the 72-hour report, or, if the incident is still ongoing at that point, a progress report followed by a final report within 30 days of resolution.
  • Report through NÚKIB's Portál Úřadu where you can; otherwise a higher-obligations provider emails NÚKIB or uses its data-box address, and a lower-obligations provider does the same with the Národní CERT.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

A Section 16 reporting infringement is an administrative offence (přestupek) under Section 59, not a criminal offence.

Penalty structure

The same Section 59(4)(a) and (b) tiers that govern a Section 13/18 infringement govern a Section 59(1)(h) or 59(2)(h) infringement (failing to submit the initial incident report under Section 16(1), failing to complete required incident data under Section 16(3), or failing to report an incident under Section 18(2)): up to CZK 250,000,000 or 2 percent of worldwide turnover for a higher-obligations provider, and up to CZK 175,000,000 or 1.4 percent for a lower-obligations provider, whichever amount is higher in each case.

Rule
Higher of
As of
14 September 2026
Currency
CZK
Fixed cap
250,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB), directly for a higher-obligations provider and, for a lower-obligations provider, through the Národní CERT it may contract to operate under Section 53.

Settledness

As of
14 September 2026
Guidance link
https://portal.nukib.gov.cz/pruvodce-novym-zakonem-o-kyberneticke-bezpecnosti
Guidance body
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB)

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 15 requires a provider in the higher-obligations regime to report a qualifying cybersecurity incident directly to NÚKIB, and a provider in the lower-obligations regime to report to the Národní CERT. Section 16 sets a graduated notification clock, transposing NIS2 Article 23.

An initial report is due no later than 24 hours after detecting the incident, giving the provider's identifying details, basic incident data, and whether the provider believes the incident was caused by an unlawful intervention or could have a cross-border impact.

For an incident with significant impact, a follow-up report is due no later than 72 hours after detection, updating that assessment and giving an initial evaluation of the incident's impact and, where available, indicators of compromise.

An interim report is due on NÚKIB's or the Národní CERT's request, and a final report is due no later than 30 days after the 72-hour report; if the incident is still ongoing at that point, a progress report is due instead, followed by a final report within 30 days of resolution. A provider reports through NÚKIB's Portál Úřadu where possible; a higher-obligations provider otherwise emails NÚKIB or uses its data-box address, and a lower-obligations provider does the same with the Národní CERT.

When LexLint raises it

  • operates_social_platform

Read the law

Act No. 264/2025 Coll., consolidated text, zakonyprolidi.cz, Sections 15-16

Back to the example  ·  Lint your app