Free quick checkFree check
NIS2 · Directive (EU) 2022/2555 · CZ Act No. 264/2025 Coll. · SK Act No. 69/2018 Coll.

NIS2 in the Czech Republic and Slovakia.
Does it apply to you?

The cybersecurity rules also reach selected manufacturers and food businesses – in the Czech Republic usually from 50 employees, in Slovakia from the size of a medium-sized enterprise in a regulated sector – with a duty to notify the authority, put security measures in place and report incidents. We check what exactly applies to you.

up to CZK 250 million – or 2% of turnover in the higher regime – Czech Republic · for failing to notify the service the highest rate applies even to a company in the lower regime; Slovakia: up to €10,000,000 or 2% of turnover for a critical essential service (Section 31)

Free and without obligation · a few questions · no registration

You answer a few questions and within 2 working days you receive your Pravano Kompas: which obligations apply to you in the Czech Republic and in Slovakia. We communicate in English, in writing.

NIS2 in a nutshell

What it is, who it concerns and since when it applies.

What is NIS2 and since when does it apply?

NIS2 is Directive (EU) 2022/2555 on cybersecurity. In the Czech Republic companies are bound by the Czech act that transposes it: the new Cybersecurity Act No. 264/2025 Coll., in force since 1 November 2025. In Slovakia the directive is transposed by amendment No. 366/2024 Coll. to Act No. 69/2018 Coll. on cybersecurity, in force since 1 January 2025.

Who is in scope?

Czech Republic: according to the estimate of the National Cyber and Information Security Agency (NÚKIB), about 6,000 organisations – medium-sized and large enterprises (usually from 50 employees, or with both turnover and balance sheet total above €10 million) in fifteen sectors, including selected manufacturing (electronics, electrical equipment, machinery, vehicles and other transport equipment), food and chemicals. Size is counted for the whole group. Slovakia: in simplified terms, companies that reach at least the size of a medium-sized enterprise and operate in one of the sectors listed in Annex 1 or Annex 2 (Section 17(1)(e)). Some providers – electronic communications, trust services, DNS, TLD – are regulated regardless of size.

Czech Republic: regimes and deadlines

Obligations are split into a higher and a lower regime; most manufacturers fall into the lower one, but every company in scope must notify. It is not just about IT: the company itself must notify its service to NÚKIB within 60 days of meeting the criteria. Security measures and incident reporting (24 h / 72 h / 30 days) take effect within one year of delivery of the registration decision – for the first wave around the turn of 2026 and 2027.

Slovakia: one regime and deadlines

Slovak law does not have two regimes like the Czech one – it uses a single term, “operator of an essential service”, with a stricter regime for a critical essential service. You notify the start of the regulated activity to the Slovak National Security Authority (NBÚ) within 60 days (Section 17(2)). You put security measures in place within 12 months of registration (Section 19(1)). A significant incident is reported in three steps: 24 hours / 72 hours / final report within one month (Section 24).

What is at stake?

Czech Republic: fines of up to CZK 250 million or 2% of turnover in the higher regime; for failing to notify the service the highest rate applies even to a company in the lower regime. The lower regime has a cap of CZK 175 million or 1.4% of turnover. Slovakia (Section 31): for failing to notify the start of activity €300 – €500,000; for failing to adopt measures or to report an incident €300 – €7,000,000 or 1.4% of worldwide turnover; for a critical essential service up to €10,000,000 or 2%.

What can go wrong

  • Czech Republic: as at 8 February 2026, according to NÚKIB, 4,825 of an estimated approximately 6,000 affected organisations had notified – anyone who is in scope and has not notified risks the highest rate of fine.
  • Czech Republic: in the higher regime, a member of the statutory body may be temporarily banned from holding office, with an entry in the Commercial Register, for a repeated or serious breach that frustrated a remedial decision of the authority.
  • Customers from regulated sectors will start enforcing the requirements by contract sooner than the state.
  • Slovakia: failing to register – anyone who carries out a regulated activity must notify NBÚ within 60 days of starting it (Section 17(2)).
  • Slovakia: missing security measures after 12 months from registration (Section 19(1), scope under Section 20).

What we do for you

  • We show whether, based on your answers, you are likely in scope and under which regime – in the Czech Republic the higher or lower regime, in Slovakia whether you reach the size of a medium-sized enterprise and operate in a regulated sector (Annex 1 or Annex 2).
  • Czech Republic: we build a map of gaps against the decree, rank the measures by risk and cost, and prepare documents for the notification and a plan for meeting the one-year deadline after registration.
  • Slovakia: we go through the notification to NBÚ (60 days), the deadline for security measures (12 months) and their scope under Section 20(2).
  • Slovakia: we set up incident reporting 24 h / 72 h / 1 month (Section 24) and – if you were already regulated before 2025 – the use of the transitional period until 31 December 2026.
Scope of the check

What exactly we go through.

Czech Republic

  • Scope: sector under the decree, size counted for the group, exemptions for separate assets
  • Regime of obligations: higher or lower, including the exceptions in manufacturing and chemicals
  • Notification of the service and deadlines after delivery of the registration decision
  • Security measures: asset and risk management, access, backups, detection, continuity
  • Role and responsibility of management, including demonstrable training
  • Contractual requirements for suppliers and your position in someone else’s supply chain

Slovakia

  • Size of a medium-sized enterprise + sector under Annex 1 or Annex 2 (Section 17(1)(e))
  • Entities regulated regardless of size – electronic communications, trust services, DNS, TLD (Section 17(1)(c))
  • Notification to NBÚ within 60 days of starting the activity (Section 17(2))
  • Security measures within 12 months of registration, scope under Section 20(2)
  • Contract with the supplier when network operation is outsourced (Section 19(2))
  • Incident reporting: 24 h early warning / 72 h notification / final report within 1 month (Section 24)
  • Transitional period until 31 December 2026 for entities regulated up to 31 December 2024 (Section 34b)
  • Critical essential service vs. others (Section 18) – a stricter regime and stricter sanctions

The scope is based on verified facts – every point is linked to a specific provision of the EU act or of the Czech or Slovak law in its current wording. The binding texts are the legislation itself; our English outputs explain it and cite the provisions.

Packages and prices

A fixed price in advance. No hourly billing.

The check is free. A fixed price for the result, not for time. Prices in euros, excluding VAT.

Map

€890

For a company that does not know whether and under which regime NIS2 applies to it

  • Assessment of whether and under which regime you are in scope
  • Overview of the main obligations
  • Recommended first steps
  • 3 months of Watch free

Delivery usually within 10 working days of confirming the scope and receiving your documents.

Order Map
✓ Money-back guarantee
Recommended

Guide

€2,190

For a company that knows it is in scope and wants to know what it is missing

Everything in Map, plus:

  • Gap analysis against NIS2 requirements
  • Prioritised remediation roadmap
  • Input for registration with NÚKIB (CZ) or notification to NBÚ (SK)
  • Split: what to do in-house / with a partner

Delivery usually 3 to 5 weeks after confirming the scope and receiving your documents.

Order Guide

Ongoing Support

from €3,390

For a company implementing measures with a cybersecurity partner

Everything in Guide, plus:

  • Management of remediation
  • Support during implementation with a cybersecurity partner
  • Preparation for an inspection by NÚKIB (CZ) or NBÚ (SK)
  • 6 months of Watch free (instead of 3)

Delivery according to the scope agreed in the confirmation, usually 6 to 10 weeks.

Order Ongoing Support

What each package includes

MapGuideOngoing Support
Scope whole companywhole companywhole company, with full support
Map of obligations for your role (with citations of the law) ✓✓✓
Recommended next steps ✓prioritised remediation roadmapprioritised remediation roadmap
Ready-made documents —gap analysis, input for registration with NÚKIB (CZ) / notification to NBÚ (SK)gap analysis, input for registration with NÚKIB (CZ) / notification to NBÚ (SK)
Implementation, support and tailored consultations ——remediation management, implementation, preparation for an inspection
Indicative delivery time usually within 10 working daysusually 3–5 weeksusually 6–10 weeks
Watch free 3 mo.3 mo.6 mo.
Money-back guarantee ✓——
Price credited on upgrade within 60 days towards Guide——

NIS2 Watch €129 per month keeps track of rule changes in this area for you: a report every Monday, cancel any time with effect from the end of the month. Order the Watch →

Prices excluding VAT · fixed price for the result · paid by bank transfer against an invoice in EUR due in 14 days (we may ask for payment in advance for Guide and Ongoing Support, and for any package from companies established outside the EU – Terms Art. 4.2). By ordering you agree to the terms and conditions (English translation; the Czech version prevails).

FAQ

What you ask most often.

We are a manufacturer, not an IT company – does this apply to us at all?
In the Czech Republic it depends on your sector. Under Decree No. 408/2025 Coll., the manufacturing sector covers only CZ-NACE divisions 26–30: computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment; other manufacturing on its own is not enough, but a company may be in scope through another service, e.g. food or chemicals. Size counted for the group also matters: manufacturers on the list are regulated as a medium-sized or large enterprise and usually fall only into the lower regime – but they must notify.
We are a medium-sized company in industry or IT. Does NIS2 apply to us in Slovakia?
Probably yes, if you reach at least the size of a medium-sized enterprise and operate in one of the sectors in Annex 1 or Annex 2 (Section 17(1)(e)). Some providers (electronic communications, trust services, DNS, TLD) are regulated regardless of size.
We heard that manufacturers in the Czech Republic always only have the lower regime. Is that true?
Almost always, but not entirely. Two exceptions point higher: a series manufacturer of passenger cars and an operator of a group B establishment under the Czech Major Accident Prevention Act. That is exactly why we start with an assessment of scope and regime.
By when must we notify and have everything in place?
Czech Republic: you file the notification within 60 days of meeting the conditions. Security measures and incident reporting then take effect within one year of delivery of the registration decision – for the first wave this falls around the turn of 2026 and 2027. Anyone already regulated under the old act reports incidents the new way from delivery of the decision. Slovakia: you must notify the start of the regulated activity to NBÚ within 60 days (Section 17(2)). Rights and obligations arise on the day stated in the notice of registration, at the earliest on the 30th day after registration. You then put security measures in place within 12 months of registration (Section 19(1)).
What deadlines apply to a cyber incident?
Czech Republic: incidents are reported within 24 h / 72 h / 30 days. Slovakia: a significant incident is reported through the single cybersecurity information system in three steps – early warning within 24 hours, notification within 72 hours and a final report within one month (Section 24(3)).
We were already regulated under the old Slovak act. Do we have to change everything at once?
Not at once. Entities regulated under the wording in force until 31 December 2024 may, until 31 December 2026, comply with measures under the previous rules (Section 34b(5)) and, in categories I and II, replace the audit for 2025 and 2026 with a self-assessment (Section 34b(8)).
We are not in scope. Can we relax?
Only partly. In the Czech Republic regulated companies must pass the requirements on into their contracts with suppliers, so they will reach you through business channels. The check shows what your customers will ask of you and what is sensible to have ready in advance.
Is the Map or the Guide the same as an audit with a guarantee of compliance?
No. It is an informative assessment of readiness and support with documentation – not a legal service or an official audit. We help you get ready; final responsibility and the legal interpretation remain with you.
Quick check

3 minutes to fill in. Within 2 working days you know what applies to you.

We will send you the Pravano Kompas: an overview of obligations for your company, deadlines and recommended steps. Free and without obligation.

1 · NIS2 – a few questions

We only ask for facts about your company. What follows from them is our job – under the rules of the market you sell to.

2 · Five more things

The specific service decides whether you are covered – in the Czech Republic under the decree on regulated services, in Slovakia under Act No. 69/2018 Coll. on cybersecurity.

Under NIS2 size is assessed for the whole group – add partner and linked enterprises (parent and subsidiary companies) to your own figures. Besides headcount, annual turnover and balance sheet total also matter.

Some obligations depend on whether a company is established in the EU – that is why we ask.

On top of the EU rules we apply the national layer of the market you sell to: local acts, authorities and deadlines.

3 · Where should we send the Pravano Kompas?

By sending the form you acknowledge that the Pravano Kompas is free indicative information, not a legal service, and that we process your data under our Privacy Policy. We prepare the Pravano Kompas with the help of AI and a person approves it. We send marketing messages only with your separate consent. We communicate in English in writing.

Done.

Thank you! We will send you the Pravano Kompas within 2 working days. A confirmation has just been sent to your e-mail – if it does not arrive, please also check your spam or promotions folder.

What happens next: we assess your answers against the full text of the rules, a person checks and approves the result, and the Pravano Kompas comes to you by e-mail within 2 working days.

Meanwhile you can look at the pricing – from the Map of your obligations to complete documentation.

  • Data protected under the GDPR, analytics cookies only with consent
  • No spam – marketing only with your explicit consent
  • Pravano Kompas within 2 working days – prepared with the help of AI, checked and approved by a person
  • Protected (Cloudflare Turnstile)

Prefer to write? info@pravano.cz – a person reads it and replies in English.