Skip to content
Law

Critical infrastructure, or NIS2?

How to determine which cybersecurity regime applies to your company

A company hears about critical infrastructure and about NIS2 and is unsure which regime applies. In fact these are two separate laws, and both can apply to the same company at once. The lawyers of ARROWS advokátní kancelář walk management through a simple test that shows where each service falls, and set out what to do before the authority comes knocking.

Critical infrastructure or NIS2? How to determine which cybersecurity regime applies to your company

Executive Summary

The Cyber Security Act (Act No. 264/2025 Coll.) and the Critical Infrastructure Act (Act No. 266/2025 Coll.) are two distinct legislative frameworks, each governed by a different authority, serving different purposes, and employing different classification mechanisms.
A service becomes a "regulated service" upon an official registration decision by the authority; the criteria are met if the service is included in the list provided by the implementing decree within one of the specified sectors, provided that the provider is a medium-sized or large enterprise or is otherwise significant, and the provider must notify the authority within 60 days.
A provider of an essential service must proactively submit information regarding the service and significance criteria to the ministry, and it only becomes a critical infrastructure entity upon a decision by the Ministry of the Interior to include it on a non-public list.
If a service provider is a critical infrastructure entity, it automatically meets the registration requirements under the Cyber Security Act; in such cases, the service corresponding to its critical infrastructure element is considered a regulated service, and the registration process is initiated ex officio.
Even a company not included on any official list may be affected as a supplier, albeit indirectly, through the requirements of its customers and supply chain management protocols.

ARE YOU DETERMINING WHETHER YOUR COMPANY IS SUBJECT TO NIS2 OR CRITICAL INFRASTRUCTURE REGULATIONS?

We will assess your company's status under both acts and prepare the necessary notifications and resilience plans.

ARROWS law firm

Why these are two laws, and not two variants of a single regime

The Cybersecurity Act regulates the rights and obligations of persons in ensuring cybersecurity and the powers of the National Cyber and Information Security Agency, and applies to persons established in the Czech Republic (Section 1 of the Cybersecurity Act). It focuses on the security of information, networks, and systems, i.e., ensuring that a company's technology works.

The Critical Infrastructure Act aims elsewhere: at the resilience of the entire essential service. It establishes measures to increase and ensure the resilience of critical infrastructure entities and the rights and obligations in ensuring the provision of essential services, with increasing resilience being part of crisis management under the Crisis Act. Cyber is just one of many threats here, alongside fires, power outages, or physical attacks.

This leads to a practical difference. The first act asks how you protect your systems and information; the second asks whether you can maintain a service on which the state and society depend, no matter what happens. A company therefore cannot choose between them as two variants, but must verify separately for each whether it falls under it, and one verification does not replace the other.

The difference is also reflected in who the addressee of the obligations is. The Cybersecurity Act targets providers of regulated services and works with assets, risks, and incidents in cyberspace. The Critical Infrastructure Act targets essential service providers and works with a resilience plan, risk assessment, and incident reporting that disrupt the provision of the essential service as a whole, whether caused by an attack, failure, or natural event.

Both acts also involve different authorities. Under the Cybersecurity Act, the authority is the National Cyber and Information Security Agency. For critical infrastructure, the Ministry of the Interior operates, whose competence is exercised by the Directorate General of the Fire and Rescue Service, and, depending on the sector, also the relevant ministries, other central administrative authorities, or the Czech National Bank. A company that contacts the wrong authority wastes time, which is why the distinction is important from the very first step.

First test: is your service a regulated service under the Cybersecurity Act

The Act does not apply to the company as a whole, but to an individual service. A regulated service is a service so designated by the authority through a registration decision, and the conditions for registration are met if it is a service of importance for securing essential social or economic activities or for security in the Czech Republic in one of the listed sectors, and the provider is a medium or large enterprise, or is significant within the meaning of the Act (Section 4 of the Cybersecurity Act).

The list of specific services and the criteria for a provider's significance are not set by the Act, but by an implementing decree. This is Decree No. 408/2025 Coll., on Regulated Services, effective from 1 November 2025. In the manufacturing industry, it only lists the manufacture of computers, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles, trailers and semi-trailers, and other transport equipment under divisions 26 to 30 of the CZ-NACE classification. For large and medium-sized enterprises, this is a lower-obligation regime; only serial manufacturers of passenger cars are in the higher-obligation regime.

The scope of sectors is broad and does not only concern energy and transport. The Act lists, among others, public administration, energy, manufacturing, food industry, chemical industry, water and waste management, transport, digital infrastructure and services, financial market, healthcare, science, research and education, postal and courier services, as well as defense and space industries. A medium-sized manufacturing enterprise can thus fall under the regime without realizing it yet, but only if its activity corresponds to a service listed in the annex to the decree.

The deadline is also essential. A service provider that meets the conditions under Section 4(1) is obliged to report the service to the authority no later than 60 days from the day the conditions were met (Section 6(1) of the Cybersecurity Act). A company that grows and crosses the threshold of medium size will therefore trigger its obligation without any warning from the state.

Imagine a medium-sized enterprise that manufactures machinery and equipment. It operates in the manufacturing industry and its activity corresponds to a service on the decree's list, so as a medium-sized enterprise, it may meet the conditions for registration. Yet, the enterprise has never considered itself an operator of anything critical. Nevertheless, it may incur an obligation to report the service, within a deadline that no one is monitoring. A manufacturer whose activity is not among the listed services is not regulated in this way.

The authority will decide on registration if the conditions under Section 4(1) or Section 5 are met, and this decision may be the first act in the proceedings. An appeal filed against it does not have a suspensive effect, so the registration obligations apply even while the company is defending itself against the decision. The provider must start implementing security measures no later than 1 year from the date of delivery of the decision (Section 13(4)). Relying on an appeal as a postponement is therefore not possible.

Frequently Asked Questions about Regulated Service Registration

1. Does the entire company have to register, or just one service?

The service is registered, not the company as a whole. A company may have multiple services, and it is assessed which of them meets the conditions in one of the listed sectors, always in connection with the size of the provider.

2. How do I know if I am a medium or large enterprise?

The Act refers to Commission Recommendation 2003/361/EC and establishes deviations from it (Section 7). Persons whose technical assets are completely separated from the assets used by the assessed person in providing the regulated service are not considered partner or linked enterprises. The size must therefore be calculated according to the specific structure of the group, not by the number of employees of a single company.

3. What if I report the service late?

Failure to comply with the reporting obligation is an offense for which a fine of up to CZK 250 million or up to 2% of the total worldwide annual turnover of the undertaking, whichever is higher, can be imposed (Section 60(1)(a) and (7)(a) of the Cybersecurity Act). The specific penalty depends on the circumstances, which is why any delay must be addressed before dealing with the authority.

ARROWS law firm

Second test: are you an essential service provider and a critical infrastructure entity

The Critical Infrastructure Act distinguishes several levels, and classification is significantly narrower than in the case of cybersecurity. An essential service is a service necessary for maintaining essential functions of the state, economic activities, security, public health, or the environment in sectors according to the annex to the Act, and an essential service provider is one who provides it in the Czech Republic and meets the significance criterion (Section 2 of the Critical Infrastructure Act).

The essential service provider must submit the information to the ministry itself. Through the critical infrastructure portal, it provides information on the essential service, on meeting at least one significance criterion, and on its critical infrastructure, within 3 months from the date of starting the service provision or within 1 month from the request of the relevant authority (Section 9 of the Critical Infrastructure Act). Providers who were already providing the service as of 30 November 2025 were required to submit the information for the first time by 1 March 2026 (Section 30(5) of the Critical Infrastructure Act).

A company becomes a critical infrastructure entity only by decision of the Ministry of the Interior. The status of an entity is established by placing the essential service provider on the list of critical infrastructure entities (Section 2(1)(d)). The relevant ministry, other central administrative authority, or the Czech National Bank will assess the submitted information and submit a proposal to the Ministry of the Interior; the Ministry of the Interior then decides on the inclusion (Section 11(1) and (2)).

Essential services in individual sectors and significance criteria are established by Government Regulation No. 127/2026 Coll., effective from 18 July 2026; both are listed in its annex. The company therefore has an objective test: look at the annex to the regulation to see if its service is among the essential ones, and check whether it meets the significance criterion.

The decision on inclusion may be the first act in the proceedings, and an appeal against it does not have a suspensive effect. The list is non-public, and the entity must comply with the obligations under the Act from the date of delivery of the decision (Section 11(3), (4), and (6)). The critical infrastructure test therefore differs from the cyber one: the company must submit the information itself in a timely manner, but the authority decides on the inclusion.

The practical question is therefore who in the company monitors communication with ministries and sector regulators and keeps track of deadlines. A request to provide information on the service provided triggers a one-month deadline and therefore belongs in the hands of both a lawyer and a crisis manager simultaneously, as the answers can determine what obligations await the company.

In addition, an entity placed on the list bears obligations regulated by implementing Decree No. 122/2026 Coll., on the resilience plan, risk assessment, resilience measures, and incident reporting, effective from 1 August 2026. Their exact scope must be assessed according to the decree and the sector in which the company operates.

Who you can contact

JUDr. Jakub Dohnal, Ph.D., LL.M.

JUDr. Jakub Dohnal, Ph.D., LL.M.

advokát, řídící partner

dohnal@arws.cz
Mgr. Petr Hanzel, LL.M.

Mgr. Petr Hanzel, LL.M.

advokát

hanzel@arws.cz
ARROWS law firm

What happens when both regimes apply at the same time

For a critical infrastructure entity, both acts meet. Under the Cybersecurity Act, the conditions for registration of a regulated service are also met when the service provider is a critical infrastructure entity; the regulated service is then the service corresponding to the critical infrastructure element designated for that entity (Section 5 of the Cybersecurity Act).

A company on the critical infrastructure list thus also falls under the cyber regime. The authority registers such a service ex officio, so the provider does not need to report anything, and is furthermore in the higher-obligation regime, regardless of the size of the enterprise (Section 6(3) and Section 8(3) of the Cybersecurity Act). The Ministry of the Interior informs the National Cyber and Information Security Agency of the inclusion within 1 month of the delivery of the decision (Section 11(5) of the Critical Infrastructure Act). A small company can thus enter the cyber regime precisely through critical infrastructure.

State authorities coordinate procedures among themselves. The strategy for strengthening the resilience of critical infrastructure entities also includes the method of coordination of authorities under the Critical Infrastructure Act with authorities under the Cybersecurity Act for sharing information on risks, threats, and incidents, and for conducting inspections (Section 3(2)(g) of the Critical Infrastructure Act). Information about a single incident can therefore reach both authorities.

In practice, this means that the company must have a single person or team that is aware of both regimes and monitors both sets of obligations. Otherwise, there is a risk that the technical department will fulfill what the cyber authority wants, while no one monitors the resilience requirements of the entire service, or vice versa. Cooperation between the two authorities cannot be taken as a substitute for one's own overview.

Suppliers and companies off the lists: who can be indirectly affected

A company that is not on any list can still be affected through its customer. The Critical Infrastructure Act defines a critical supplier as a person who has entered into a legal relationship with a critical infrastructure entity and, on this basis, provides goods or services necessary to ensure the provision of an essential service (Section 2(1)(l) of the Critical Infrastructure Act). In addition, the Ministry of the Interior may issue warnings and decide on the conditions or prohibition of using the performance of such a supplier (Section 6(1)(m)).

The Cybersecurity Act also considers a supplier as a supporting asset. A supporting asset is an asset ensuring the functioning of primary assets, in particular an employee, supplier, technical asset, or building. A regulated service provider implementing security measures through a supplier must select them in accordance with the requirements resulting from the measures and include these requirements in contracts with them (Section 13(5)).

Suppliers can therefore be indirectly affected by the requirements of a regulated entity or a critical infrastructure entity, particularly through supply chain management and contractual obligations. Typically, this will involve the obligation to report incidents, allow audits, comply with security measures, or keep records. A company that rejects these requirements without consideration risks losing a key customer, which is why it is reasonable to assess them and potentially negotiate an adjustment of the scope, rather than having the supplier accept or reject them blindly.

It is also important to know your own position. A manufacturer supplying components to the energy or transport sectors may meet the definition of a critical supplier without knowing it until informed by the customer. It is therefore recommended to proactively ask customers whether they consider you a supporting asset or a critical supplier, and adjust contracts according to the response.

How to proceed in practice

The first step is to verify whether the company provides any of the specific services defined for the given sector by Decree No. 408/2025 Coll., and only then evaluate the size of the enterprise according to statutory rules and other significance criteria. If the conditions under Section 4(1) are met, a 60-day period for reporting to the authority begins. It is advisable to do this part immediately, as it cannot be postponed retroactively.

The second step is to verify whether the service is among the essential services under Government Regulation No. 127/2026 Coll. If so, the provider must submit the information to the ministry itself and not wait for a request; in case of uncertainty about the significance criterion, it is reasonable to proactively communicate with the relevant ministry. The sooner the company learns about its status, the more time it has to prepare a resilience plan and risk assessment.

The third step is to review your own supply chain. A company providing a regulated service needs to know which suppliers are essential for its service and have contractually regulated reporting, access, and liability with them. Similar issues are addressed in the text on liability for a cyber incident.

The fourth step is to designate a person within the company responsible for both regimes. Practice shows that both areas are often addressed separately, one by the IT security department and the other by the crisis management department, and the gap between them is precisely where obligations are overlooked. A general overview of the new act is offered in the text on the new Cybersecurity Act.

The fifth step is to align established procedures with practical implementation. How NIS2 is implemented in a company's day-to-day operations is discussed in the text on the implementation of NIS2 in practice. Furthermore, if a company manufactures products with digital elements, it also has obligations under the European Cyber Resilience Act in addition to both domestic laws, including the obligation to report actively exploited vulnerabilities within 24 hours.

It is useful for management to keep a brief record of the entire assessment: which services the company provides, which sector it belongs to, what its size is, and when the conditions were verified. Such a record will save time when dealing with the authority and demonstrate that the company addressed the issue with due care. It is then advisable to repeat the assessment with every major change in the group structure, new service, or acquisition.

How exactly to set up the verification of the company's status and the resilience plan depends on the sector and whether the company is a service provider, a supplier, or both at the same time – which is why the lawyers of the Prague-based ARROWS law firm always assess this based on the specific service, rather than a universal checklist.

Risks of incorrect classification under the cybersecurity regime

Risk within the company

How ARROWS will verify and secure it

The company thinks that critical infrastructure and NIS2 are the same thing. It complies with one regime and overlooks the other.

We will assess the company's status under both acts separately. We will provide an expert legal opinion on which obligations apply to the company.

The company has exceeded the size of a medium enterprise for a service on the decree's list, and the 60-day deadline has expired. It has not reported the service and is unaware of the obligation.

We will verify the service, size, and sector, and prepare the report for the authority. We will check the documentation before submission.

The service is among the essential ones, but no one has verified the significance criteria or the information obligation. The company only learns of its inclusion from the decision.

We will verify the service according to the government regulation and set up communication with the ministry. We will prepare the documentation for the risk assessment.

The supply chain is not contractually regulated. The customer demands obligations from the company for which it has no contract template.

We will adjust contracts with suppliers and customers to cover reporting, audits, and liability. We will negotiate the terms directly with the counterparty.

ARROWS law firm

Final Summary

Critical infrastructure and NIS2 are not two variants of a single regime, but two separate acts that can apply to a single company simultaneously. This article has shown that the cyber regime is verified based on the specific service, sector, and size, and is reported to the authority within 60 days, whereas the status of a critical infrastructure entity is established by a decision on inclusion in the list, preceded by the information obligation of the essential service provider, and that both regimes meet for a critical infrastructure entity.

For company management, this results in a clear task: perform both tests separately, designate a person responsible for both regimes, and review the supply chain. A company that is unaware of its status cannot meet deadlines or prepare contracts, and its status will ultimately be decided by the authority.

The lawyers of the Czech legal team at ARROWS assess the status of companies under the Cybersecurity Act and the Critical Infrastructure Act, prepare reports and resilience plans, and adjust contracts with suppliers and customers. Write to us at consultation@arws.cz or review our practice for contracts and negotiations.

Frequently Asked Questions about Critical Infrastructure and NIS2

1. Is NIS2 the same as the Cybersecurity Act?

The Cybersecurity Act transposes the relevant European Union regulation and builds on directly applicable regulations, so the terms are used interchangeably in practice. For a company, the decisive act is Czech Act No. 264/2025 Coll.

2. Can a company be on the critical infrastructure list without knowing it?

No. The list is non-public, but the decision on inclusion is delivered to the entity, which must comply with the obligations from the date of delivery (Section 11(4) and (6) of the Critical Infrastructure Act). Furthermore, inclusion is preceded by the information obligation of the essential service provider, which is why it is necessary to verify whether the company submitted the information to the ministry in time.

3. Does the Cybersecurity Act also apply to a company established abroad?

The Act applies to persons established in the territory of the Czech Republic, as well as to persons who provide networks or electronic communications services in the Czech Republic, regardless of their place of establishment. A foreign company with Czech operations must therefore be assessed according to its specific structure.

4. Does a supplier have to fulfill the customer's obligations?

Directly under the law, only if they fall under the regime themselves. However, the customer may impose obligations on them by contract, which is why it is important to read the purchasing terms.

5. Who decides on inclusion in the critical infrastructure list?

The decision on inclusion is issued by the Ministry of the Interior upon a proposal from the relevant ministry, another central administrative authority, or the Czech National Bank. Essential services and significance criteria are established by Government Regulation No. 127/2026 Coll.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

JUDr. Jakub Dohnal, Ph.D., LL.M.
JUDr. Jakub Dohnal, Ph.D., LL.M.

Associate, managing partner

Jakub Dohnal is an attorney-at-law and managing partner of ARROWS. He focuses on company sales, investor entries into private companies and real estate transactions — most often acting for the owner who is selling a business built over many years and needs the deal to close on the agreed terms.

Disclaimer:

The information contained in this article is of a general informative nature only and serves as a basic guide to the issue under the legal status as of 2026. Although we ensure maximum accuracy of the content, legal regulations and their interpretation evolve over time. We are ARROWS, a Prague-based law firm registered with the Czech Bar Association (our supervisory body), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of regulations and their application to your specific situation, it is necessary to contact ARROWS law firm directly (consultation@arws.cz). We accept no liability for any damages resulting from the independent use of information from this article without prior individual legal consultation.