Skip to content

New Cybersecurity Act

What companies and their management must do now

The new Czech Act on Cybersecurity expands the range of companies that must manage cybersecurity risks, secure their supply chain, and report serious incidents, with responsibility also falling directly on the company's management. It is therefore not enough to leave security solely to the IT department. This article explains how to determine if the Act applies to your company, which regime applies to it, and what steps management must implement.

The image shows a cybersecurity expert ready to advise companies on the new legislation.

Key takeaways

Cybersecurity is now the responsibility of company management. The new act shifts full responsibility for cybersecurity from the IT department to the board of directors and executive directors, making it a strategic priority for the company.
You must self-identify and register. Every company is obliged to actively assess whether it meets the statutory criteria and, if so, register through the NÚKIB Portal.
Missing the registration deadline will be costly. The key deadline for registration is no later than 30 December 2025; failure to meet this deadline carries a fine of up to CZK 250 million or 2% of global turnover.
The act affects a wide range of industries. To fall under the act, you must operate in a regulated industry, which includes not only traditional sectors like energy and banking but now also manufacturing, food production, waste management, and digital infrastructure.
ARROWS law firm

New Digital Reality: From the IT Department to the Boardroom

This change means that cybersecurity is no longer exclusively a technical topic for the IT department but is becoming a strategic priority for which the board of directors and executive officers bear full responsibility. The law explicitly targets the obligations of top management, ending the era when they could distance themselves from the consequences of cyber incidents by claiming it was a technical failure. Digital resilience is thus becoming as fundamental a part of corporate governance as a financial audit.

Does This Affect You? Key Steps to Identify Your Obligations

The law is built on the key principle of self-identification. This means that every company has an obligation to actively assess whether it meets the legal criteria and, if so, to register itself through the NÚKIB (National Cyber and Information Security Agency) Portal. Inaction does not pay off here and can be very costly.

The key deadline for registration is 60 days from the law's effective date, i.e., by 30 December 2025 at the latest. Missing this deadline is considered a serious offence, punishable by a fine of up to CZK 250 million or 2% of the company's total worldwide turnover, whichever is higher.

Are You a Provider of a Regulated Service? Two Key Factors

To determine whether the law applies to you, you must assess two cumulative conditions set out in Section 4 of the Act:

1. Sector: You operate in one of the regulated sectors. This includes not only traditional sectors like energy, healthcare, transport, banking, and the financial market, but now also a wide range of others, including the manufacturing and food industries, waste management, postal services, and digital infrastructure.

2. Size: You are a medium-sized or large enterprise. This means you have either 50 or more employees OR your annual turnover or annual balance sheet total reaches at least EUR 10 million (approximately CZK 250 million). For some services, such as in the digital infrastructure sector, size does not matter.

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

Higher or Lower Regime? A Fundamental Difference in the Scope of Obligations

The law divides obliged entities into two categories with different scopes of obligations: a higher-obligations regime (for so-called essential entities) and a lower-obligations regime (for so-called important entities). The classification into a specific regime determines the stringency of security measures, the frequency of audits, and the details for incident reporting.

If your company provides multiple services, at least one of which falls under the higher regime, the stricter rules apply to all your regulated activities.

FAQ – Legal Tips for Determining Your Obligations

1. What if we are a supplier to a company that falls under the regulation?

Even if you are not directly subject to the law, your clients are. They will contractually require you to implement comparable security measures to protect their supply chain. Ignoring NIS2 could cost you key contracts. Need to review your contracts with customers? Contact us at consultation@arws.cz.

2. How is company size assessed within a holding structure?

Size is assessed with regard to partner and linked enterprises. A small subsidiary may thus be considered a large enterprise due to its parent company, thereby falling under the regulation. A correct assessment is crucial to avoid penalties. For a comprehensive assessment of your corporate structure, write to us at consultation@arws.cz.
ARROWS law firm

A New Era of Accountability: What the Law Requires Directly from Company Management

The most significant change for senior managers is the introduction of direct and personal liability. The new law explicitly imposes obligations on "top management" (i.e., statutory bodies).

Your direct responsibilities include approving cybersecurity policies, overseeing their implementation, and ensuring sufficient financial, technical, and human resources for their fulfilment. Neglecting these duties constitutes a breach of the duty of due managerial care.

Mandatory Training for Management: The Law Requires You to Understand the Risks

The law explicitly requires members of top management to undergo regular training in cybersecurity. The goal is not to turn you into IT experts, but to provide you with the knowledge needed to ask the right questions, evaluate risks, and make informed strategic decisions.

Carefully kept records of these training sessions will be key evidence that you have not neglected your duty.

Risks and Sanctions

How ARROWS Helps

Temporary ban on holding office for up to 3 years for serious or repeated failures.

Expert training for management, including a certificate, which demonstrably fulfils the legal obligation and demonstrates due managerial care. Need to train your management? Write to consultation@arws.cz.

Personal liability for damages – recovery of fines and costs from the personal assets of an executive in case of a breach of the duty of due managerial care.

Preparation of documentation that protects against fines and sanctions, such as minutes of meetings, approved policies, and budget allocations. Secure your legal protection – contact us at consultation@arws.cz.

Administrative offence and a fine for failing to approve or oversee cybersecurity risk management measures.

Legal opinions and consultations that provide management with clear guidance on what decisions to make and how to document them correctly. Want to be sure of your steps? Consult with us at consultation@arws.cz.

Reputational damage associated with personal failure, which can end a managerial career.

Preparation of a crisis communication strategy and legal support in dealing with regulators and the public. Are you addressing reputational risks? Get in touch with us at consultation@arws.cz.

ARROWS law firm

The Ten Pillars of Your Digital Resilience: Key Security Measures in Practice

Complying with the law's requirements is not about buying a single "NIS2-certified" product – such products do not even exist. It is about implementing a comprehensive and functional Information Security Management System (ISMS). This must include a range of interconnected technical and organisational measures.

Key measures include: risk analysis and management, incident handling plans, business continuity (including backup and recovery plans), supply chain security, human resources security (regular employee training), and access control, including mandatory multi-factor authentication (MFA).

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

The Core of It All: Risk Management and Supplier Security

Two areas deserve special attention. The first is risk management, which runs like a common thread throughout the entire regulation. It is not a one-off analysis, but a continuous process of identifying, assessing, and mitigating threats. The second is securing the supply chain. Companies must actively vet their suppliers and contractually oblige them to adhere to security standards.

An incident caused by an inadequately secured supplier and a weak contract can lead to enormous damages that you will be unable to recover.

At ARROWS, we specialise in reviewing and preparing contracts with IT suppliers that reflect the requirements of the new law and protect you from third-party risks. For an immediate solution to your situation, write to us at consultation@arws.cz.

FAQ – Legal Tips on Security Measures

1. Do we have to implement all measures immediately on 1 November 2025?

No. After receiving the registration decision from NÚKIB, there is a one-year transition period to implement security measures and start reporting incidents. The time for preparation is therefore limited, and you need to start immediately. Need to create an implementation plan? Contact us at consultation@arws.cz.

2. What is the relationship between measures under NIS2 and GDPR?

NIS2 and GDPR are complementary, but not merged. NIS2 protects networks and systems as a whole, while GDPR focuses on the protection of personal data. A major cyber incident often violates both regulations, which means an obligation to report the incident to two different authorities (NÚKIB and the Office for Personal Data Protection) and the risk of double fines. Our lawyers are ready to help you coordinate the fulfilment of your obligations – write to consultation@arws.cz.
ARROWS law firm

When the Worst Happens: New Rules for Reporting Cyber Incidents

After the one-year transition period, the obligation to report cybersecurity incidents to NÚKIB through its portal comes into effect, with very strict deadlines. The process is multi-phased:

  1. An initial report within 24 hours of becoming aware of the incident.

  2. A detailed notification within 72 hours, which includes an initial impact assessment and so-called indicators of compromise.

  3. A final report within 1 month of the notification, providing a detailed analysis of the incident, its causes, and the corrective measures taken.

What Gets Reported? The Difference Between the Higher and Lower Regimes

The reporting obligation differs according to your regime:

  • Higher-obligations regime: All incidents where malicious intent cannot be ruled out must be reported. NÚKIB will then assess for itself whether the incident is considered "significant".

  • Lower-obligations regime: Only incidents with a significant impact that meet specific criteria set by the implementing decree and where malicious intent cannot be ruled out are reported.

Risks and Sanctions

How ARROWS Helps

A fine of up to CZK 250 million or 2% of worldwide turnover for non-compliance.

Representation before administrative authorities (NÚKIB) during inspections and in proceedings for imposing sanctions. Need legal assistance during an inspection? Contact us at consultation@arws.cz.

Business interruption and loss of revenue as a result of an attack (e.g., ransomware).

Legal support in claiming damages from suppliers or other culprits and advice on making claims under insurance policies. Want to know your legal options? Write to us at consultation@arws.cz.

Loss of client trust and reputational damage due to a data breach or inability to restore services.

Preparation of internal policies and incident response plans that minimise chaos and enable a quick and professional response. Need to prepare a crisis plan? Get in touch with us at consultation@arws.cz.

Costs of system recovery, forensic analysis, and legal disputes with affected clients.

Comprehensive legal crisis management, from coordination with technical experts to resolving contractual and non-contractual claims. For an immediate solution to your situation, write to us at consultation@arws.cz.

ARROWS law firm

International Context: How ARROWS Solves It

Although the NIS2 Directive establishes a uniform framework for the entire EU, its transposition into national laws varies between member states. A company operating in the Czech Republic, Germany, and France, for example, faces a complex puzzle of different regulatory nuances.

For instance, while Germany proposes to establish a single point of contact for reporting incidents (for both NIS2 and GDPR), the Czech law requires dual reporting, which increases the administrative burden and the risk of error.

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm

ARROWS International: Your Local Expertise on a Global Scale

The solution to this complexity is the ARROWS International network. Thanks to our network, built over ten years, we handle cases with an international element daily and can ensure compliance with local NIS2 implementations across Europe. We provide our clients with a single point of contact for solving problems in multiple jurisdictions, thereby saving their time, reducing complexity, and ensuring consistent protection for their business.

Does your company operate in multiple EU states? Do you need to ensure compliance with NIS2 across borders? Contact us at consultation@arws.cz and get a tailor-made legal solution.

Conclusion: From Obligation to Opportunity – How ARROWS Can Help You Turn NIS2 into an Advantage

The new Cybersecurity Act brings a new era of responsibility for company management, critical deadlines, and the threat of unprecedented sanctions. We understand that these changes may seem like a burden. However, a properly handled implementation is not just a cost, but a strategic investment in resilience, trustworthiness, and ultimately, a competitive advantage. A company that demonstrably meets the requirements of NIS2 is more trustworthy to its partners and customers.

At ARROWS, we have extensive experience providing legal services to more than 150 joint-stock companies and 250 limited liability companies. We pride ourselves on speed and high quality. But we are more than just lawyers. We are your strategic business partner. At ARROWS, we value entrepreneurial ideas and actively connect our clients when we see interesting business or investment synergies.

Implementing the new Cybersecurity Act is a complex and urgent task. Our team of experts is ready to guide you through the entire process, protect your company and you personally, and help you turn this obligation into an opportunity. Do not hesitate to contact our office – consultation@arws.cz.

FAQ – Most Common Legal Questions about the New Cybersecurity Act

1. What are the most important deadlines I need to watch out for?

The law comes into effect on 1 November 2025. The most important deadlines are: to self-identify and register with NÚKIB by 30 December 2025. After receiving the registration decision, you have 1 year to implement all security measures and start reporting incidents. If you are working on an implementation schedule, contact us at consultation@arws.cz.

2. Can D&O (Directors and Officers liability) insurance cover fines or damages arising from NIS2?

Standard D&O policies may have exclusions for regulatory fines. However, some specialised insurance products may cover regulatory fines and defence costs. It is essential to review your existing insurance policies and possibly extend them. We can help you with the review of your insurance contracts. Write to us at consultation@arws.cz.

3. What specific security roles must be newly established in the company?

The Act and its implementing decrees define several key roles, such as Cybersecurity Manager or Cybersecurity Architect. In smaller organisations or in the lower-obligations regime, one person may hold multiple roles if they meet the qualification requirements. Correctly setting up and filling these roles is crucial. For legal advice on defining roles and responsibilities, contact consultation@arws.cz.

4. How does the law address the security of cloud services?

Cloud service providers are among the regulated entities. If you use their services, you must ensure, as part of your supply chain management, that they also comply with the law's requirements, and this must be contractually addressed. The responsibility towards NÚKIB always remains with you. We can help you review your contracts with cloud providers. Contact us at consultation@arws.cz.

5. What is the "supply chain security screening mechanism" and who does it apply to?

This is a specific process for strategically important services (designated by a government regulation), typically in the higher-obligations regime. NÚKIB can screen suppliers for critical parts of systems and, in the event of a security risk, issue a ban on their use. This is a matter of protecting national security. If you are unsure whether this mechanism applies to you, write to us at consultation@arws.cz.

6. Do we have to have all documentation in Czech?

For the purposes of an inspection by NÚKIB, key documentation (policies, risk analyses, incident records) must be comprehensible and available in the Czech language upon request. For international teams, it is common to maintain documentation bilingually. We have experience with preparing bilingual documentation. Get in touch with us at consultation@arws.cz.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

JUDr. Jakub Dohnal, Ph.D., LL.M.
JUDr. Jakub Dohnal, Ph.D., LL.M.

Associate, managing partner

Jakub Dohnal is an attorney-at-law and managing partner of ARROWS. He focuses on company sales, investor entries into private companies and real estate transactions — most often acting for the owner who is selling a business built over many years and needs the deal to close on the agreed terms.

Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.