NIS2 in the Czech Republic and Slovakia.
Does it apply to you?
The cybersecurity rules also reach selected manufacturers and food businesses – in the Czech Republic usually from 50 employees, in Slovakia from the size of a medium-sized enterprise in a regulated sector – with a duty to notify the authority, put security measures in place and report incidents. We check what exactly applies to you.
up to CZK 250 million – or 2% of turnover in the higher regime – Czech Republic · for failing to notify the service the highest rate applies even to a company in the lower regime; Slovakia: up to €10,000,000 or 2% of turnover for a critical essential service (Section 31)
Free and without obligation · a few questions · no registration
You answer a few questions and within 2 working days you receive your Pravano Kompas: which obligations apply to you in the Czech Republic and in Slovakia. We communicate in English, in writing.
What it is, who it concerns and since when it applies.
What is NIS2 and since when does it apply?
NIS2 is Directive (EU) 2022/2555 on cybersecurity. In the Czech Republic companies are bound by the Czech act that transposes it: the new Cybersecurity Act No. 264/2025 Coll., in force since 1 November 2025. In Slovakia the directive is transposed by amendment No. 366/2024 Coll. to Act No. 69/2018 Coll. on cybersecurity, in force since 1 January 2025.
Who is in scope?
Czech Republic: according to the estimate of the National Cyber and Information Security Agency (NÚKIB), about 6,000 organisations – medium-sized and large enterprises (usually from 50 employees, or with both turnover and balance sheet total above €10 million) in fifteen sectors, including selected manufacturing (electronics, electrical equipment, machinery, vehicles and other transport equipment), food and chemicals. Size is counted for the whole group. Slovakia: in simplified terms, companies that reach at least the size of a medium-sized enterprise and operate in one of the sectors listed in Annex 1 or Annex 2 (Section 17(1)(e)). Some providers – electronic communications, trust services, DNS, TLD – are regulated regardless of size.
Czech Republic: regimes and deadlines
Obligations are split into a higher and a lower regime; most manufacturers fall into the lower one, but every company in scope must notify. It is not just about IT: the company itself must notify its service to NÚKIB within 60 days of meeting the criteria. Security measures and incident reporting (24 h / 72 h / 30 days) take effect within one year of delivery of the registration decision – for the first wave around the turn of 2026 and 2027.
Slovakia: one regime and deadlines
Slovak law does not have two regimes like the Czech one – it uses a single term, “operator of an essential service”, with a stricter regime for a critical essential service. You notify the start of the regulated activity to the Slovak National Security Authority (NBÚ) within 60 days (Section 17(2)). You put security measures in place within 12 months of registration (Section 19(1)). A significant incident is reported in three steps: 24 hours / 72 hours / final report within one month (Section 24).
What is at stake?
Czech Republic: fines of up to CZK 250 million or 2% of turnover in the higher regime; for failing to notify the service the highest rate applies even to a company in the lower regime. The lower regime has a cap of CZK 175 million or 1.4% of turnover. Slovakia (Section 31): for failing to notify the start of activity €300 – €500,000; for failing to adopt measures or to report an incident €300 – €7,000,000 or 1.4% of worldwide turnover; for a critical essential service up to €10,000,000 or 2%.
What can go wrong
- Czech Republic: as at 8 February 2026, according to NÚKIB, 4,825 of an estimated approximately 6,000 affected organisations had notified – anyone who is in scope and has not notified risks the highest rate of fine.
- Czech Republic: in the higher regime, a member of the statutory body may be temporarily banned from holding office, with an entry in the Commercial Register, for a repeated or serious breach that frustrated a remedial decision of the authority.
- Customers from regulated sectors will start enforcing the requirements by contract sooner than the state.
- Slovakia: failing to register – anyone who carries out a regulated activity must notify NBÚ within 60 days of starting it (Section 17(2)).
- Slovakia: missing security measures after 12 months from registration (Section 19(1), scope under Section 20).
What we do for you
- We show whether, based on your answers, you are likely in scope and under which regime – in the Czech Republic the higher or lower regime, in Slovakia whether you reach the size of a medium-sized enterprise and operate in a regulated sector (Annex 1 or Annex 2).
- Czech Republic: we build a map of gaps against the decree, rank the measures by risk and cost, and prepare documents for the notification and a plan for meeting the one-year deadline after registration.
- Slovakia: we go through the notification to NBÚ (60 days), the deadline for security measures (12 months) and their scope under Section 20(2).
- Slovakia: we set up incident reporting 24 h / 72 h / 1 month (Section 24) and – if you were already regulated before 2025 – the use of the transitional period until 31 December 2026.
What exactly we go through.
Czech Republic
- Scope: sector under the decree, size counted for the group, exemptions for separate assets
- Regime of obligations: higher or lower, including the exceptions in manufacturing and chemicals
- Notification of the service and deadlines after delivery of the registration decision
- Security measures: asset and risk management, access, backups, detection, continuity
- Role and responsibility of management, including demonstrable training
- Contractual requirements for suppliers and your position in someone else’s supply chain
Slovakia
- Size of a medium-sized enterprise + sector under Annex 1 or Annex 2 (Section 17(1)(e))
- Entities regulated regardless of size – electronic communications, trust services, DNS, TLD (Section 17(1)(c))
- Notification to NBÚ within 60 days of starting the activity (Section 17(2))
- Security measures within 12 months of registration, scope under Section 20(2)
- Contract with the supplier when network operation is outsourced (Section 19(2))
- Incident reporting: 24 h early warning / 72 h notification / final report within 1 month (Section 24)
- Transitional period until 31 December 2026 for entities regulated up to 31 December 2024 (Section 34b)
- Critical essential service vs. others (Section 18) – a stricter regime and stricter sanctions
The scope is based on verified facts – every point is linked to a specific provision of the EU act or of the Czech or Slovak law in its current wording. The binding texts are the legislation itself; our English outputs explain it and cite the provisions.
A fixed price in advance. No hourly billing.
The check is free. A fixed price for the result, not for time. Prices in euros, excluding VAT.
Map
For a company that does not know whether and under which regime NIS2 applies to it
- Assessment of whether and under which regime you are in scope
- Overview of the main obligations
- Recommended first steps
- 3 months of Watch free
Delivery usually within 10 working days of confirming the scope and receiving your documents.
Order MapGuide
For a company that knows it is in scope and wants to know what it is missing
Everything in Map, plus:
- Gap analysis against NIS2 requirements
- Prioritised remediation roadmap
- Input for registration with NÚKIB (CZ) or notification to NBÚ (SK)
- Split: what to do in-house / with a partner
Delivery usually 3 to 5 weeks after confirming the scope and receiving your documents.
Order GuideOngoing Support
For a company implementing measures with a cybersecurity partner
Everything in Guide, plus:
- Management of remediation
- Support during implementation with a cybersecurity partner
- Preparation for an inspection by NÚKIB (CZ) or NBÚ (SK)
- 6 months of Watch free (instead of 3)
Delivery according to the scope agreed in the confirmation, usually 6 to 10 weeks.
Order Ongoing SupportWhat each package includes
| Map | Guide | Ongoing Support | |
|---|---|---|---|
| Scope | whole company | whole company | whole company, with full support |
| Map of obligations for your role (with citations of the law) | ✓ | ✓ | ✓ |
| Recommended next steps | ✓ | prioritised remediation roadmap | prioritised remediation roadmap |
| Ready-made documents | — | gap analysis, input for registration with NÚKIB (CZ) / notification to NBÚ (SK) | gap analysis, input for registration with NÚKIB (CZ) / notification to NBÚ (SK) |
| Implementation, support and tailored consultations | — | — | remediation management, implementation, preparation for an inspection |
| Indicative delivery time | usually within 10 working days | usually 3–5 weeks | usually 6–10 weeks |
| Watch free | 3 mo. | 3 mo. | 6 mo. |
| Money-back guarantee | ✓ | — | — |
| Price credited on upgrade within 60 days | towards Guide | — | — |
NIS2 Watch €129 per month keeps track of rule changes in this area for you: a report every Monday, cancel any time with effect from the end of the month. Order the Watch →
Prices excluding VAT · fixed price for the result · paid by bank transfer against an invoice in EUR due in 14 days (we may ask for payment in advance for Guide and Ongoing Support, and for any package from companies established outside the EU – Terms Art. 4.2). By ordering you agree to the terms and conditions (English translation; the Czech version prevails).
What you ask most often.
We are a manufacturer, not an IT company – does this apply to us at all?
We are a medium-sized company in industry or IT. Does NIS2 apply to us in Slovakia?
We heard that manufacturers in the Czech Republic always only have the lower regime. Is that true?
By when must we notify and have everything in place?
What deadlines apply to a cyber incident?
We were already regulated under the old Slovak act. Do we have to change everything at once?
We are not in scope. Can we relax?
Is the Map or the Guide the same as an audit with a guarantee of compliance?
In depth: the national rules explained.
3 minutes to fill in. Within 2 working days you know what applies to you.
We will send you the Pravano Kompas: an overview of obligations for your company, deadlines and recommended steps. Free and without obligation.
- Data protected under the GDPR, analytics cookies only with consent
- No spam – marketing only with your explicit consent
- Pravano Kompas within 2 working days – prepared with the help of AI, checked and approved by a person
- Protected (Cloudflare Turnstile)
Prefer to write? info@pravano.cz – a person reads it and replies in English.