New Cybersecurity Act
What companies and their management must do now
The new Czech Act on Cybersecurity expands the range of companies that must manage cybersecurity risks, secure their supply chain, and report serious incidents, with responsibility also falling directly on the company's management. It is therefore not enough to leave security solely to the IT department. This article explains how to determine if the Act applies to your company, which regime applies to it, and what steps management must implement.

Key takeaways
New Digital Reality: From the IT Department to the Boardroom
This change means that cybersecurity is no longer exclusively a technical topic for the IT department but is becoming a strategic priority for which the board of directors and executive officers bear full responsibility. The law explicitly targets the obligations of top management, ending the era when they could distance themselves from the consequences of cyber incidents by claiming it was a technical failure. Digital resilience is thus becoming as fundamental a part of corporate governance as a financial audit.
Does This Affect You? Key Steps to Identify Your Obligations
The law is built on the key principle of self-identification. This means that every company has an obligation to actively assess whether it meets the legal criteria and, if so, to register itself through the NÚKIB (National Cyber and Information Security Agency) Portal. Inaction does not pay off here and can be very costly.
The key deadline for registration is 60 days from the law's effective date, i.e., by 30 December 2025 at the latest. Missing this deadline is considered a serious offence, punishable by a fine of up to CZK 250 million or 2% of the company's total worldwide turnover, whichever is higher.
Are You a Provider of a Regulated Service? Two Key Factors
To determine whether the law applies to you, you must assess two cumulative conditions set out in Section 4 of the Act:
1. Sector: You operate in one of the regulated sectors. This includes not only traditional sectors like energy, healthcare, transport, banking, and the financial market, but now also a wide range of others, including the manufacturing and food industries, waste management, postal services, and digital infrastructure.
2. Size: You are a medium-sized or large enterprise. This means you have either 50 or more employees OR your annual turnover or annual balance sheet total reaches at least EUR 10 million (approximately CZK 250 million). For some services, such as in the digital infrastructure sector, size does not matter.
Higher or Lower Regime? A Fundamental Difference in the Scope of Obligations
The law divides obliged entities into two categories with different scopes of obligations: a higher-obligations regime (for so-called essential entities) and a lower-obligations regime (for so-called important entities). The classification into a specific regime determines the stringency of security measures, the frequency of audits, and the details for incident reporting.
If your company provides multiple services, at least one of which falls under the higher regime, the stricter rules apply to all your regulated activities.
A New Era of Accountability: What the Law Requires Directly from Company Management
The most significant change for senior managers is the introduction of direct and personal liability. The new law explicitly imposes obligations on "top management" (i.e., statutory bodies).
Your direct responsibilities include approving cybersecurity policies, overseeing their implementation, and ensuring sufficient financial, technical, and human resources for their fulfilment. Neglecting these duties constitutes a breach of the duty of due managerial care.
Mandatory Training for Management: The Law Requires You to Understand the Risks
The law explicitly requires members of top management to undergo regular training in cybersecurity. The goal is not to turn you into IT experts, but to provide you with the knowledge needed to ask the right questions, evaluate risks, and make informed strategic decisions.
Carefully kept records of these training sessions will be key evidence that you have not neglected your duty.
Risks and Sanctions | How ARROWS Helps |
Temporary ban on holding office for up to 3 years for serious or repeated failures. | Expert training for management, including a certificate, which demonstrably fulfils the legal obligation and demonstrates due managerial care. Need to train your management? Write to consultation@arws.cz. |
Personal liability for damages – recovery of fines and costs from the personal assets of an executive in case of a breach of the duty of due managerial care. | Preparation of documentation that protects against fines and sanctions, such as minutes of meetings, approved policies, and budget allocations. Secure your legal protection – contact us at consultation@arws.cz. |
Administrative offence and a fine for failing to approve or oversee cybersecurity risk management measures. | Legal opinions and consultations that provide management with clear guidance on what decisions to make and how to document them correctly. Want to be sure of your steps? Consult with us at consultation@arws.cz. |
Reputational damage associated with personal failure, which can end a managerial career. | Preparation of a crisis communication strategy and legal support in dealing with regulators and the public. Are you addressing reputational risks? Get in touch with us at consultation@arws.cz. |
The Ten Pillars of Your Digital Resilience: Key Security Measures in Practice
Complying with the law's requirements is not about buying a single "NIS2-certified" product – such products do not even exist. It is about implementing a comprehensive and functional Information Security Management System (ISMS). This must include a range of interconnected technical and organisational measures.
Key measures include: risk analysis and management, incident handling plans, business continuity (including backup and recovery plans), supply chain security, human resources security (regular employee training), and access control, including mandatory multi-factor authentication (MFA).
The Core of It All: Risk Management and Supplier Security
Two areas deserve special attention. The first is risk management, which runs like a common thread throughout the entire regulation. It is not a one-off analysis, but a continuous process of identifying, assessing, and mitigating threats. The second is securing the supply chain. Companies must actively vet their suppliers and contractually oblige them to adhere to security standards.
An incident caused by an inadequately secured supplier and a weak contract can lead to enormous damages that you will be unable to recover.
At ARROWS, we specialise in reviewing and preparing contracts with IT suppliers that reflect the requirements of the new law and protect you from third-party risks. For an immediate solution to your situation, write to us at consultation@arws.cz.
When the Worst Happens: New Rules for Reporting Cyber Incidents
After the one-year transition period, the obligation to report cybersecurity incidents to NÚKIB through its portal comes into effect, with very strict deadlines. The process is multi-phased:
An initial report within 24 hours of becoming aware of the incident.
A detailed notification within 72 hours, which includes an initial impact assessment and so-called indicators of compromise.
A final report within 1 month of the notification, providing a detailed analysis of the incident, its causes, and the corrective measures taken.
What Gets Reported? The Difference Between the Higher and Lower Regimes
The reporting obligation differs according to your regime:
Higher-obligations regime: All incidents where malicious intent cannot be ruled out must be reported. NÚKIB will then assess for itself whether the incident is considered "significant".
Lower-obligations regime: Only incidents with a significant impact that meet specific criteria set by the implementing decree and where malicious intent cannot be ruled out are reported.
Risks and Sanctions | How ARROWS Helps |
A fine of up to CZK 250 million or 2% of worldwide turnover for non-compliance. | Representation before administrative authorities (NÚKIB) during inspections and in proceedings for imposing sanctions. Need legal assistance during an inspection? Contact us at consultation@arws.cz. |
Business interruption and loss of revenue as a result of an attack (e.g., ransomware). | Legal support in claiming damages from suppliers or other culprits and advice on making claims under insurance policies. Want to know your legal options? Write to us at consultation@arws.cz. |
Loss of client trust and reputational damage due to a data breach or inability to restore services. | Preparation of internal policies and incident response plans that minimise chaos and enable a quick and professional response. Need to prepare a crisis plan? Get in touch with us at consultation@arws.cz. |
Costs of system recovery, forensic analysis, and legal disputes with affected clients. | Comprehensive legal crisis management, from coordination with technical experts to resolving contractual and non-contractual claims. For an immediate solution to your situation, write to us at consultation@arws.cz. |
International Context: How ARROWS Solves It
Although the NIS2 Directive establishes a uniform framework for the entire EU, its transposition into national laws varies between member states. A company operating in the Czech Republic, Germany, and France, for example, faces a complex puzzle of different regulatory nuances.
For instance, while Germany proposes to establish a single point of contact for reporting incidents (for both NIS2 and GDPR), the Czech law requires dual reporting, which increases the administrative burden and the risk of error.
ARROWS International: Your Local Expertise on a Global Scale
The solution to this complexity is the ARROWS International network. Thanks to our network, built over ten years, we handle cases with an international element daily and can ensure compliance with local NIS2 implementations across Europe. We provide our clients with a single point of contact for solving problems in multiple jurisdictions, thereby saving their time, reducing complexity, and ensuring consistent protection for their business.
Does your company operate in multiple EU states? Do you need to ensure compliance with NIS2 across borders? Contact us at consultation@arws.cz and get a tailor-made legal solution.
Conclusion: From Obligation to Opportunity – How ARROWS Can Help You Turn NIS2 into an Advantage
The new Cybersecurity Act brings a new era of responsibility for company management, critical deadlines, and the threat of unprecedented sanctions. We understand that these changes may seem like a burden. However, a properly handled implementation is not just a cost, but a strategic investment in resilience, trustworthiness, and ultimately, a competitive advantage. A company that demonstrably meets the requirements of NIS2 is more trustworthy to its partners and customers.
At ARROWS, we have extensive experience providing legal services to more than 150 joint-stock companies and 250 limited liability companies. We pride ourselves on speed and high quality. But we are more than just lawyers. We are your strategic business partner. At ARROWS, we value entrepreneurial ideas and actively connect our clients when we see interesting business or investment synergies.
Implementing the new Cybersecurity Act is a complex and urgent task. Our team of experts is ready to guide you through the entire process, protect your company and you personally, and help you turn this obligation into an opportunity. Do not hesitate to contact our office – consultation@arws.cz.
About the author
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.
