Critical infrastructure, or NIS2?
How to determine which cybersecurity regime applies to your company
A company hears about critical infrastructure and about NIS2 and is unsure which regime applies. In fact these are two separate laws, and both can apply to the same company at once. The lawyers of ARROWS advokátní kancelář walk management through a simple test that shows where each service falls, and set out what to do before the authority comes knocking.

Executive Summary
Why these are two laws, and not two variants of a single regime
The Cybersecurity Act regulates the rights and obligations of persons in ensuring cybersecurity and the powers of the National Cyber and Information Security Agency, and applies to persons established in the Czech Republic (Section 1 of the Cybersecurity Act). It focuses on the security of information, networks, and systems, i.e., ensuring that a company's technology works.
The Critical Infrastructure Act aims elsewhere: at the resilience of the entire essential service. It establishes measures to increase and ensure the resilience of critical infrastructure entities and the rights and obligations in ensuring the provision of essential services, with increasing resilience being part of crisis management under the Crisis Act. Cyber is just one of many threats here, alongside fires, power outages, or physical attacks.
This leads to a practical difference. The first act asks how you protect your systems and information; the second asks whether you can maintain a service on which the state and society depend, no matter what happens. A company therefore cannot choose between them as two variants, but must verify separately for each whether it falls under it, and one verification does not replace the other.
The difference is also reflected in who the addressee of the obligations is. The Cybersecurity Act targets providers of regulated services and works with assets, risks, and incidents in cyberspace. The Critical Infrastructure Act targets essential service providers and works with a resilience plan, risk assessment, and incident reporting that disrupt the provision of the essential service as a whole, whether caused by an attack, failure, or natural event.
Both acts also involve different authorities. Under the Cybersecurity Act, the authority is the National Cyber and Information Security Agency. For critical infrastructure, the Ministry of the Interior operates, whose competence is exercised by the Directorate General of the Fire and Rescue Service, and, depending on the sector, also the relevant ministries, other central administrative authorities, or the Czech National Bank. A company that contacts the wrong authority wastes time, which is why the distinction is important from the very first step.
First test: is your service a regulated service under the Cybersecurity Act
The Act does not apply to the company as a whole, but to an individual service. A regulated service is a service so designated by the authority through a registration decision, and the conditions for registration are met if it is a service of importance for securing essential social or economic activities or for security in the Czech Republic in one of the listed sectors, and the provider is a medium or large enterprise, or is significant within the meaning of the Act (Section 4 of the Cybersecurity Act).
The list of specific services and the criteria for a provider's significance are not set by the Act, but by an implementing decree. This is Decree No. 408/2025 Coll., on Regulated Services, effective from 1 November 2025. In the manufacturing industry, it only lists the manufacture of computers, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles, trailers and semi-trailers, and other transport equipment under divisions 26 to 30 of the CZ-NACE classification. For large and medium-sized enterprises, this is a lower-obligation regime; only serial manufacturers of passenger cars are in the higher-obligation regime.
The scope of sectors is broad and does not only concern energy and transport. The Act lists, among others, public administration, energy, manufacturing, food industry, chemical industry, water and waste management, transport, digital infrastructure and services, financial market, healthcare, science, research and education, postal and courier services, as well as defense and space industries. A medium-sized manufacturing enterprise can thus fall under the regime without realizing it yet, but only if its activity corresponds to a service listed in the annex to the decree.
The deadline is also essential. A service provider that meets the conditions under Section 4(1) is obliged to report the service to the authority no later than 60 days from the day the conditions were met (Section 6(1) of the Cybersecurity Act). A company that grows and crosses the threshold of medium size will therefore trigger its obligation without any warning from the state.
Imagine a medium-sized enterprise that manufactures machinery and equipment. It operates in the manufacturing industry and its activity corresponds to a service on the decree's list, so as a medium-sized enterprise, it may meet the conditions for registration. Yet, the enterprise has never considered itself an operator of anything critical. Nevertheless, it may incur an obligation to report the service, within a deadline that no one is monitoring. A manufacturer whose activity is not among the listed services is not regulated in this way.
The authority will decide on registration if the conditions under Section 4(1) or Section 5 are met, and this decision may be the first act in the proceedings. An appeal filed against it does not have a suspensive effect, so the registration obligations apply even while the company is defending itself against the decision. The provider must start implementing security measures no later than 1 year from the date of delivery of the decision (Section 13(4)). Relying on an appeal as a postponement is therefore not possible.
Second test: are you an essential service provider and a critical infrastructure entity
The Critical Infrastructure Act distinguishes several levels, and classification is significantly narrower than in the case of cybersecurity. An essential service is a service necessary for maintaining essential functions of the state, economic activities, security, public health, or the environment in sectors according to the annex to the Act, and an essential service provider is one who provides it in the Czech Republic and meets the significance criterion (Section 2 of the Critical Infrastructure Act).
The essential service provider must submit the information to the ministry itself. Through the critical infrastructure portal, it provides information on the essential service, on meeting at least one significance criterion, and on its critical infrastructure, within 3 months from the date of starting the service provision or within 1 month from the request of the relevant authority (Section 9 of the Critical Infrastructure Act). Providers who were already providing the service as of 30 November 2025 were required to submit the information for the first time by 1 March 2026 (Section 30(5) of the Critical Infrastructure Act).
A company becomes a critical infrastructure entity only by decision of the Ministry of the Interior. The status of an entity is established by placing the essential service provider on the list of critical infrastructure entities (Section 2(1)(d)). The relevant ministry, other central administrative authority, or the Czech National Bank will assess the submitted information and submit a proposal to the Ministry of the Interior; the Ministry of the Interior then decides on the inclusion (Section 11(1) and (2)).
Essential services in individual sectors and significance criteria are established by Government Regulation No. 127/2026 Coll., effective from 18 July 2026; both are listed in its annex. The company therefore has an objective test: look at the annex to the regulation to see if its service is among the essential ones, and check whether it meets the significance criterion.
The decision on inclusion may be the first act in the proceedings, and an appeal against it does not have a suspensive effect. The list is non-public, and the entity must comply with the obligations under the Act from the date of delivery of the decision (Section 11(3), (4), and (6)). The critical infrastructure test therefore differs from the cyber one: the company must submit the information itself in a timely manner, but the authority decides on the inclusion.
The practical question is therefore who in the company monitors communication with ministries and sector regulators and keeps track of deadlines. A request to provide information on the service provided triggers a one-month deadline and therefore belongs in the hands of both a lawyer and a crisis manager simultaneously, as the answers can determine what obligations await the company.
In addition, an entity placed on the list bears obligations regulated by implementing Decree No. 122/2026 Coll., on the resilience plan, risk assessment, resilience measures, and incident reporting, effective from 1 August 2026. Their exact scope must be assessed according to the decree and the sector in which the company operates.
What happens when both regimes apply at the same time
For a critical infrastructure entity, both acts meet. Under the Cybersecurity Act, the conditions for registration of a regulated service are also met when the service provider is a critical infrastructure entity; the regulated service is then the service corresponding to the critical infrastructure element designated for that entity (Section 5 of the Cybersecurity Act).
A company on the critical infrastructure list thus also falls under the cyber regime. The authority registers such a service ex officio, so the provider does not need to report anything, and is furthermore in the higher-obligation regime, regardless of the size of the enterprise (Section 6(3) and Section 8(3) of the Cybersecurity Act). The Ministry of the Interior informs the National Cyber and Information Security Agency of the inclusion within 1 month of the delivery of the decision (Section 11(5) of the Critical Infrastructure Act). A small company can thus enter the cyber regime precisely through critical infrastructure.
State authorities coordinate procedures among themselves. The strategy for strengthening the resilience of critical infrastructure entities also includes the method of coordination of authorities under the Critical Infrastructure Act with authorities under the Cybersecurity Act for sharing information on risks, threats, and incidents, and for conducting inspections (Section 3(2)(g) of the Critical Infrastructure Act). Information about a single incident can therefore reach both authorities.
In practice, this means that the company must have a single person or team that is aware of both regimes and monitors both sets of obligations. Otherwise, there is a risk that the technical department will fulfill what the cyber authority wants, while no one monitors the resilience requirements of the entire service, or vice versa. Cooperation between the two authorities cannot be taken as a substitute for one's own overview.
Suppliers and companies off the lists: who can be indirectly affected
A company that is not on any list can still be affected through its customer. The Critical Infrastructure Act defines a critical supplier as a person who has entered into a legal relationship with a critical infrastructure entity and, on this basis, provides goods or services necessary to ensure the provision of an essential service (Section 2(1)(l) of the Critical Infrastructure Act). In addition, the Ministry of the Interior may issue warnings and decide on the conditions or prohibition of using the performance of such a supplier (Section 6(1)(m)).
The Cybersecurity Act also considers a supplier as a supporting asset. A supporting asset is an asset ensuring the functioning of primary assets, in particular an employee, supplier, technical asset, or building. A regulated service provider implementing security measures through a supplier must select them in accordance with the requirements resulting from the measures and include these requirements in contracts with them (Section 13(5)).
Suppliers can therefore be indirectly affected by the requirements of a regulated entity or a critical infrastructure entity, particularly through supply chain management and contractual obligations. Typically, this will involve the obligation to report incidents, allow audits, comply with security measures, or keep records. A company that rejects these requirements without consideration risks losing a key customer, which is why it is reasonable to assess them and potentially negotiate an adjustment of the scope, rather than having the supplier accept or reject them blindly.
It is also important to know your own position. A manufacturer supplying components to the energy or transport sectors may meet the definition of a critical supplier without knowing it until informed by the customer. It is therefore recommended to proactively ask customers whether they consider you a supporting asset or a critical supplier, and adjust contracts according to the response.
How to proceed in practice
The first step is to verify whether the company provides any of the specific services defined for the given sector by Decree No. 408/2025 Coll., and only then evaluate the size of the enterprise according to statutory rules and other significance criteria. If the conditions under Section 4(1) are met, a 60-day period for reporting to the authority begins. It is advisable to do this part immediately, as it cannot be postponed retroactively.
The second step is to verify whether the service is among the essential services under Government Regulation No. 127/2026 Coll. If so, the provider must submit the information to the ministry itself and not wait for a request; in case of uncertainty about the significance criterion, it is reasonable to proactively communicate with the relevant ministry. The sooner the company learns about its status, the more time it has to prepare a resilience plan and risk assessment.
The third step is to review your own supply chain. A company providing a regulated service needs to know which suppliers are essential for its service and have contractually regulated reporting, access, and liability with them. Similar issues are addressed in the text on liability for a cyber incident.
The fourth step is to designate a person within the company responsible for both regimes. Practice shows that both areas are often addressed separately, one by the IT security department and the other by the crisis management department, and the gap between them is precisely where obligations are overlooked. A general overview of the new act is offered in the text on the new Cybersecurity Act.
The fifth step is to align established procedures with practical implementation. How NIS2 is implemented in a company's day-to-day operations is discussed in the text on the implementation of NIS2 in practice. Furthermore, if a company manufactures products with digital elements, it also has obligations under the European Cyber Resilience Act in addition to both domestic laws, including the obligation to report actively exploited vulnerabilities within 24 hours.
It is useful for management to keep a brief record of the entire assessment: which services the company provides, which sector it belongs to, what its size is, and when the conditions were verified. Such a record will save time when dealing with the authority and demonstrate that the company addressed the issue with due care. It is then advisable to repeat the assessment with every major change in the group structure, new service, or acquisition.
How exactly to set up the verification of the company's status and the resilience plan depends on the sector and whether the company is a service provider, a supplier, or both at the same time – which is why the lawyers of the Prague-based ARROWS law firm always assess this based on the specific service, rather than a universal checklist.
Risks of incorrect classification under the cybersecurity regime
Risk within the company | How ARROWS will verify and secure it |
The company thinks that critical infrastructure and NIS2 are the same thing. It complies with one regime and overlooks the other. | We will assess the company's status under both acts separately. We will provide an expert legal opinion on which obligations apply to the company. |
The company has exceeded the size of a medium enterprise for a service on the decree's list, and the 60-day deadline has expired. It has not reported the service and is unaware of the obligation. | We will verify the service, size, and sector, and prepare the report for the authority. We will check the documentation before submission. |
The service is among the essential ones, but no one has verified the significance criteria or the information obligation. The company only learns of its inclusion from the decision. | We will verify the service according to the government regulation and set up communication with the ministry. We will prepare the documentation for the risk assessment. |
The supply chain is not contractually regulated. The customer demands obligations from the company for which it has no contract template. | We will adjust contracts with suppliers and customers to cover reporting, audits, and liability. We will negotiate the terms directly with the counterparty. |
Final Summary
Critical infrastructure and NIS2 are not two variants of a single regime, but two separate acts that can apply to a single company simultaneously. This article has shown that the cyber regime is verified based on the specific service, sector, and size, and is reported to the authority within 60 days, whereas the status of a critical infrastructure entity is established by a decision on inclusion in the list, preceded by the information obligation of the essential service provider, and that both regimes meet for a critical infrastructure entity.
For company management, this results in a clear task: perform both tests separately, designate a person responsible for both regimes, and review the supply chain. A company that is unaware of its status cannot meet deadlines or prepare contracts, and its status will ultimately be decided by the authority.
The lawyers of the Czech legal team at ARROWS assess the status of companies under the Cybersecurity Act and the Critical Infrastructure Act, prepare reports and resilience plans, and adjust contracts with suppliers and customers. Write to us at consultation@arws.cz or review our practice for contracts and negotiations.
About the author
Disclaimer:
The information contained in this article is of a general informative nature only and serves as a basic guide to the issue under the legal status as of 2026. Although we ensure maximum accuracy of the content, legal regulations and their interpretation evolve over time. We are ARROWS, a Prague-based law firm registered with the Czech Bar Association (our supervisory body), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of regulations and their application to your specific situation, it is necessary to contact ARROWS law firm directly (consultation@arws.cz). We accept no liability for any damages resulting from the independent use of information from this article without prior individual legal consultation.

