Skip to content

Cybersecurity and Critical Infrastructure

Laws significantly expanding management liability

From 2026, the amendment to the Czech Act on Cybersecurity (transposing the NIS2 Directive) will introduce an obligation to report a cybersecurity incident within 24 hours and expand the personal liability of management for insufficient security – both the company and a specific manager may face a separate fine. Find out which companies the new rules affect and how to prepare for them.

The photograph depicts an expert providing consultation on strengthening management accountability for cybersecurity.

Who the law affects: a regulated service instead of critical infrastructure

Act No. 264/2025 Coll., on Cybersecurity, is effective from 1 November 2025 and replaced the previous Act No. 181/2014 Coll. Company management needs to know one main thing: obligations are no longer tied to whether the company operates a critical information infrastructure, but to whether it provides a regulated service. A regulated service is a service determined as such by the National Cyber and Information Security Agency (hereinafter referred to as the Agency) through a registration decision.

The registration conditions are met by a service in one of fifteen sectors whose provider is a medium or large enterprise. In addition to public administration, energy, transport, healthcare, and digital infrastructure, the law also names the manufacturing, food, and chemical industries, water and waste management, the financial market, science and education, postal and courier services, and the defense and space industry (Section 4). The scope of affected companies is therefore significantly broader than what is usually considered critical infrastructure.

However, the sector itself is not the deciding factor. The specific list of services, the provider's materiality criteria, and the division of providers into higher and lower obligation regimes are set out in Decree No. 408/2025 Coll., on Regulated Services, also effective from 1 November 2025. A company should therefore not rely solely on the list of sectors in the law, but must compare its activities with the annex to the decree, which also specifies which regime their provider belongs to for each service.

The size of the enterprise is assessed according to Commission Recommendation 2003/361/EC, but with statutory deviations. For corporate groups, it is essential that an entity whose technical assets are completely separated from the assets used by the assessed company in providing the service is not considered a partner or linked enterprise (Section 7). A holding company with separate IT may thus qualify as a smaller enterprise than consolidated figures would suggest, but the separation must be real and demonstrable.

Critical infrastructure entities form a special category. A service corresponding to a critical infrastructure element always meets the registration conditions, regardless of the provider's size, and the provider is automatically in the higher obligations regime (Section 5(d) and Section 8(3)). Proceedings for such registration are initiated only by the Agency ex officio. The Cybersecurity Act is linked here to Act No. 266/2025 Coll., on Critical Infrastructure, and both regimes need to be managed together.

At the same time, the law yields to sector-specific European Union regulations. If a directly applicable EU regulation or a law implementing an EU regulation imposes obligations regarding security measures or incident reporting with at least a comparable effect, the relevant provisions of the law do not apply, including supervision (Section 70); this typically applies to the financial sector. A broader overview of the changes is offered in the text on the new Cybersecurity Act.

Deadlines from notification to implementation of measures

Obligations do not start on the same day for all companies. The deadlines run individually for each provider and follow on from each other: the first is calculated from the moment the company meets the registration conditions, the next from the delivery of the Agency's decision. A company that fails to notice that it meets the conditions therefore not only loses preparation time but violates its obligation already in the first phase, when it is not even aware of the regulation.

The first step is to notify the service to the Agency no later than 60 days from the day it met the registration conditions (Section 6(1)). The Agency will then decide on the registration, and may do so even without notification if the conditions are met. The decision may be the first act in the proceedings, and an appeal (remonstrance) against it does not have a suspensive effect, so a company may only learn about its new role from the delivered decision.

Failure to notify the service is not just a formal error. The law explicitly classifies it as an administrative offense and allows for a fine of up to CZK 250 million or 2% of the enterprise's net global annual turnover, whichever is higher (Section 60 of the Cybersecurity Act). This is the same upper limit that applies to the failure to implement security measures in the higher obligations regime.

Following the delivery of the decision, two other deadlines run. Within 30 days, the company must report the contact details of persons authorized to act under the law, additional details on the ownership structure, technical details of the service, and information on its geographical distribution, with changes reported within 14 days (Section 11). No later than 1 year from delivery, it must start implementing security measures and fulfilling the obligation to report incidents (Section 13(4) and Section 15(4)).

Companies that were already regulated under Act No. 181/2014 Coll. do not have a free transition period. Until the new deadlines expire, they must fulfill at least the obligations under the previous Act, and they must report incidents in accordance with the new Act starting from the day of delivery of the registration decision (Section 71). For them, the one-year deadline therefore concerns security measures in the new scope, not the reporting method.

Before implementing measures, the company must define what the regulation applies to. It must identify all primary assets, i.e., processed information and services provided, assess which ones relate to the regulated service, and identify supporting assets for them, such as employees, suppliers, technology, and buildings (Section 12). Until an asset is assessed, it is deemed to fall within the specified scope, so delaying the analysis does not narrow the scope but expands it.

Changes must also be monitored after registration. If the service changes in a way that could lead to a change in the regime, the company must report this to the Agency within 60 days, and upon transitioning to the higher obligations regime, new deadlines begin to run (Section 9). This typically involves an acquisition, expanding the service to new customers, or integration into a group where the assessment of the enterprise size changes.

Exactly when the company met the registration conditions and whether it falls under the higher or lower regime determines all subsequent deadlines – which is why the Czech legal team at ARROWS law firm assesses this for each service individually according to the annex to the decree and the actual structure of the group.

Incident reporting: who, to whom, and by when

Not every event needs to be reported. A provider in the higher obligations regime reports to the Agency incidents that have manifested within the specified scope, originate in cyberspace, and for which intentional fault cannot be ruled out within 24 hours. A provider in the lower obligations regime reports to the National CERT only those that also have a significant impact on the provision of the regulated service (Section 15).

The initial report is submitted without undue delay, no later than 24 hours after the incident is detected. It only needs to contain identification data, basic details about the incident, and information on whether the company assumes an unlawful interference or cross-border impact. Waiting for the results of an investigation therefore makes no sense, and failure to submit the initial report is a separate administrative offense (Section 59).

Subsequent steps differ in both regimes. In the higher obligations regime, the Agency will communicate within 24 hours of the report whether the incident has a significant impact on the state's cyberspace, and only then does a notification with an initial assessment follow within 72 hours of detection, and a final report within 30 days of the notification. In the lower obligations regime, only significant incidents are reported, so both the notification and the final report are always submitted (Section 16 of the Cybersecurity Act).

What is a significant impact must be determined in advance by the provider in the lower obligations regime itself. Decree No. 410/2025 Coll. requires them to determine an acceptable level of harm and the areas by which the impact is assessed, such as operational impact, number of affected users, resources needed for recovery, and data sensitivity. A significant incident is one that exceeds the acceptable level and, at the same time, one of the areas is assessed as significant (Section 14 of the Decree).

Reports are submitted via the Agency Portal, and if it cannot be used, by email or to the data box of the Agency, or to the National CERT in the case of the lower obligations regime. Accesses, authorized persons, and their deputies should be prepared before an incident occurs, because the 24-hour deadline runs over the weekend as well, and searching for login credentials does not belong in it.

A single event can trigger multiple reporting obligations at once. An attack in which personal data was leaked is usually both a cyber incident under the law and a personal data breach under GDPR, which the controller must notify to the Office for Personal Data Protection without undue delay and, where feasible, not later than 72 hours. This involves two recipients and two forms, so a company needs a single procedure that covers both regimes simultaneously.

In addition to reporting to the authorities, the company also addresses the private law consequences for customers and suppliers after an incident, which are analyzed in the text on liability for a cyber incident. Records of when the incident was detected, who decided on the report, and what was reported serve both purposes: they document compliance with deadlines and the company's course of action in any potential dispute.

Frequently asked questions about incident reporting

1. Do we have to report an incident if we don't yet know who is behind it?

Yes, if intentional fault cannot be ruled out within 24 hours and the incident meets other statutory conditions. The initial report requires only basic details, and the company will state in it whether it assumes unlawful interference; the rest will be provided in the notification.

2. To whom is the report made in the lower obligations regime?

To the National CERT, via the Agency Portal; if the portal cannot be used, by email or to the data box of the National CERT. In the higher obligations regime, the recipient is the Agency.

3. Is it necessary to report an incident involving a personal data leak under GDPR as well?

Usually yes. Reporting under the Cybersecurity Act does not replace the notification of a personal data breach to the Office for Personal Data Protection, which has its own deadline and content.

ARROWS law firm

What the decrees impose on top management and where their liability ends

The law classifies requirements for top management as security measures in both regimes (Section 14). The specific content was brought by implementing decrees effective from 1 November 2025, and they are more detailed than company management often expects. Top management is defined as the statutory body or another person or group of persons in a similar managerial position, so obligations cannot simply be transferred to the IT department.

In the higher obligations regime, management must demonstrably undergo training, secure resources, and establish a cybersecurity management committee. The committee must include at least one member of top management or their authorized representative and the cybersecurity manager, and the committee must meet at least once a year, with minutes recorded. Management will also designate a cybersecurity manager, architect, and auditor, as well as asset guarantors, and ensure deputies are available for both the manager and the architect.

Management must also demonstrably familiarize itself with the information security management system review report, the risk assessment report, the risk treatment plan, the results of the impact analysis, and the results of audits (Section 4 of Decree No. 409/2025 Coll.). The word "demonstrably" is essential: it is not enough that the documents exist; the company must be able to prove that management actually received and discussed them.

In the lower obligations regime, the requirements are more modest, but not non-existent. Management will designate a person in charge of cybersecurity and entrust them with the necessary powers, demonstrably undergo training itself, secure resources, familiarize itself with the status of implementation of measures, and set the recovery priority for primary assets (Section 4 of Decree No. 410/2025 Coll.). The overview of security measures is updated at least once a year and kept for at least four years.

The personal sanction that the law provides for members of management is narrowly defined. The Agency may ban a member of the statutory body of a provider in the higher obligations regime from performing their duties until the deficiencies are remedied, for at least 6 months, if, in direct connection with the implementation of the Agency's corrective decision, they repeatedly or seriously breached their duties and thereby thwarted its fulfillment (Section 58). The ban is recorded in the Commercial Register.

Broader liability stems from the general duty of due managerial care (care of a prudent businessman). A member of an elected body acts with due care if they could in good faith reasonably assume that they were acting in an informed manner and in the defensible interest of the corporation (Section 51 of the Business Corporations Act), and in a dispute, they bear the burden of proof themselves (Section 52(2)). Minutes of committee meetings, proof of training, and evidence of familiarization with reports are therefore the best defense for the members of management themselves.

How these obligations affect the personal position of executive directors and board members is discussed in more detail in the text on why cybersecurity is becoming a personal liability for directors. In practice, the same follows from both texts: cybersecurity decisions must leave a paper trail in the corporate body's documents, not just in the IT department's emails.

Whether the management's documentation will hold up during an inspection or in a potential dispute depends on the provider's regime and how the group's management is actually divided between the parent and subsidiary companies – which is why the Czech legal team at ARROWS law firm verifies this for each corporate body individually.

Where companies make mistakes: from overlooked registration to supplier contracts

In practice, the most expensive mistakes do not happen during an attack, but months before. They include overlooked registration, undefined scope, supplier contracts without security requirements, and a reporting process that exists only on paper. Each of these is an administrative offense in itself, even if no incident occurs, and some only come to light during the first inspection by the Agency.

The first mistake is relying on the assumption that the company does not belong to critical infrastructure. A medium-sized manufacturing enterprise with several hundred employees can meet the registration conditions without management tracking it, and the 60-day deadline runs regardless of whether they know about it. The result is not only lost preparation time but the risk of a fine at the highest rate known to the law.

The second mistake is delaying the definition of the specified scope. Failure to identify primary or supporting assets, failure to assess them, missing records, and failure to update the scope are separate administrative offenses (Section 59(1) and (2)). Furthermore, a company that does not define its scope cannot reasonably plan measures, as under the law, everything that has not yet been assessed falls within it.

The third mistake is supplier contracts without requirements from security measures. The law requires selecting suppliers in accordance with these requirements and including them in contracts (Section 13(5)), and non-compliance is an administrative offense of the provider, not the supplier. Furthermore, in the higher obligations regime, the provider must identify significant suppliers, inform them in writing, and incorporate provisions from Annex No. 5 to Decree No. 409/2025 Coll. into contracts with them.

For the lower obligations regime, a similar list is contained in Annex No. 2 to Decree No. 410/2025 Coll.: provisions on confidentiality and non-disclosure, supplier audits, supplier chaining, exit strategy, sanctions, incidents related to performance, continuity management, service level agreements, and secure development rules. Master IT agreements concluded earlier often do not contain these points and need to be reviewed and supplemented with an amendment.

The fourth mistake is a reporting process that no one has tested. The initial report requires only basic data, but the company needs to know who will assess the incident, who has access to the Agency Portal, and who will approve the report. A short drill on a model situation, such as a Friday evening attack, will reveal gaps faster than any guideline.

The fifth mistake is considering the implementation of measures as a one-off project. In the higher obligations regime, the decree requires evaluating the effectiveness of the information security management system at least once a year and conducting risk assessments at least once a year and upon significant changes. Cybersecurity thus becomes a regular agenda for management, similar to the annual financial statements or insurance risk reviews.

Risks for the company and management in case of non-compliance

Risk for the company

How ARROWS lawyers will mitigate it

Service was not notified. The company met the registration conditions and the 60-day deadline passed unnoticed.

We will assess the services under the law and the annex to Decree No. 408/2025 Coll. We will prepare the notification and negotiate with the Agency.

Missing scope definition and asset inventory. An administrative offense is risked even without any incident.

We will help define the specified scope and set up the asset inventory. We will review the security documentation.

Supplier contracts lack mandatory provisions. The provider bears the liability, not the supplier.

We will prepare amendments according to the annexes to Decrees No. 409/2025 Coll. and 410/2025 Coll. We will negotiate the terms directly with the suppliers.

Reporting process is not prepared. The company will not make the initial report within 24 hours.

We will set up the procedure, roles, and deputies for reporting. We will train the responsible persons.

Management lacks documented training and familiarization with reports. In a dispute over due managerial care, the member of the corporate body bears the burden of proof.

We will set up the documentation for management and committee decision-making. We will represent you in proceedings before the Agency.

ARROWS law firm

Final Summary

The Cybersecurity Act and its implementing decrees transfer obligations from critical infrastructure to a wide range of regulated service providers. This article has shown that regulation is determined by the annex to the decree on regulated services, that deadlines run individually for each company, and that failure to notify a service is an administrative offense with the same upper limit as the penalty for failing to implement measures in the higher obligations regime.

For company management, this leads to three decisions: verify whether it provides a regulated service, determine who is responsible for reporting, and document its own training and familiarization with reports. All three can be done within a few weeks, and without them, the company cannot defend itself during an inspection or in a dispute.

Delay does not pay off, because deadlines do not run from the moment the company starts taking an interest in regulation, but from the fulfillment of the conditions and from the delivery of the Agency's decision. Management that postpones decisions thus risks receiving the first information about its obligation only in initiated proceedings.

The Czech legal team at ARROWS law firm assesses whether companies' services fall under the regulation, prepares notifications and amendments to supplier contracts, and sets up management documentation as well as the incident reporting process. Write to us at consultation@arws.cz or review our IT and software law and cybersecurity practice.

Frequently asked questions about cybersecurity and critical infrastructure

1. Does the law also apply to companies outside of energy and transport?

Yes. The law lists fifteen sectors, including manufacturing, food, and chemical industries, waste management, or postal services. The deciding factor is whether the company's service is listed in the annex to Decree No. 408/2025 Coll. and whether the company is a medium or large enterprise.

2. What are the penalties for failing to notify a service?

Failure to notify is an administrative offense with a fine of up to CZK 250 million or 2% of net global annual turnover, whichever is higher. Furthermore, the Agency can decide on registration even without notification.

3. By when must we have security measures implemented?

No later than 1 year from the delivery of the registration decision. Companies already regulated under the previous Act must fulfill at least their existing obligations until then.

4. Can the Agency penalize the executive director directly?

The law only provides for a temporary ban on performing duties for a provider in the higher obligations regime, specifically in the event of repeated or serious breaches of duties when implementing a corrective decision. Fines are imposed on the company; liability towards the company is governed by due managerial care.

5. Does the law apply if the company is already regulated by an EU sector-specific regulation?

If an EU regulation or a law implementing it imposes at least comparable obligations regarding measures or reporting, the relevant provisions of the law do not apply. Comparability needs to be assessed for each specific company, typically in the financial sector.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

JUDr. Jakub Dohnal, Ph.D., LL.M.
JUDr. Jakub Dohnal, Ph.D., LL.M.

Associate, managing partner

Jakub Dohnal is an attorney-at-law and managing partner of ARROWS. He focuses on company sales, investor entries into private companies and real estate transactions — most often acting for the owner who is selling a business built over many years and needs the deal to close on the agreed terms.

Disclaimer:

The information contained in this article is for general informative purposes only and serves as a basic guide to the issue under Czech legislation as of 2026. Although we ensure maximum accuracy of the content, legal regulations and their interpretation evolve over time. We are ARROWS, a Prague-based law firm registered with the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we carry professional liability insurance with a limit of CZK 350,000,000. To verify the current wording of regulations and their application to your specific situation, it is essential to contact the Czech legal team at ARROWS directly (consultation@arws.cz). We accept no liability for any damages resulting from the independent use of information from this article without prior individual legal consultation.