New cybersecurity rules: what are the most common self-identification mistakes?
The new Cybersecurity Act, which is likely to be in force from mid-2025, substantially expands the number of companies that are obliged to comply with specific security requirements. The self-identification obligation affects tens of thousands of companies in the Czech Republic. Failure to do so can lead to fines of up to CZK 250,000,000 or 2% of global annual turnover.

1. Self-identification obligations - ignorance is no excuse
Businesses often do not realise that cyberregulation has long since ceased to apply only to big players in critical infrastructure. The new law targets a much wider range of businesses, from digital service providers to manufacturing companies, and even more so companies that are part of strategic supply chains.
Self-identification and registration of the regulated service is a fundamental obligation under the new legislation. The authority will not come to you, it will not send you a data message: "Hello, the new rules apply to you, you have to do exactly this (...)." The comprehensive identification of the impact of the completely new legislation must be done by companies themselves and done correctly.
2. Regulated services assessment
One of the most common mistakes in self-identification is the incorrect assessment of whether your company provides regulated services. The new Cybersecurity Act covers a wide range of activities in areas that are strategic or critical to the operation of the company.
In the self-identification process, companies often consider only their primary activity and overlook ancillary or support activities that may be distinct from the primary activity but are still subject to regulation. It is always necessary to assess each individual activity actively carried out to determine whether or not it is a regulated service within the meaning of the new legislation.
3. Correctly assessing the size of the undertaking: Think about the whole structure
The size of the company is another criterion that determines whether the new law applies to you. Many companies misinterpret the rules, for example, underestimating their number of employees or misjudging financial ratios.
The law also takes interconnected businesses into account - if you are part of a larger group, you may be affected by the regulations even if you don't meet the headcount or turnover requirements on the face of it. For example, a small subsidiary of a large corporation may be regulated based on its interconnectedness.
Properly assessing the size of your business is a key step in making it clear what obligations apply to you.
4. Key steps to ensure regulatory compliance
To make sure you meet all the requirements of the new Cybersecurity Act, focus on the following steps:
- Verify your industry: determine if you fall into regulated sectors such as manufacturing, energy, or digital infrastructure.
- Company Size Analysis: Evaluate all parameters of company size, including interconnections with parent companies.
- Regime of action: after self-identification, determine whether you are exempt from the legislation or will be subject to a lower or higher regime obligation.
- Gap analysis: Identify the difference between the existing measures and the measures you will be obliged to introduce.
- Resourcing: Secure funding, experts and time for implementation in advance. These resources are likely to be scarce once the law comes into force. Work with experts to help you identify gaps and address them in a timely manner.
- Keep track of developments: regularly monitor legislative changes and validate your preliminary conclusions.
The new cybersecurity law brings major changes that require careful preparation. by performing self-identification before the legislation takes effect, you will gain a competitive advantage in the marketplace, ensure you have sufficient resources and minimize risk.
If you need help with a preliminary self-identification or want to verify the accuracy of your conclusions, please do not hesitate to contact us.
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2025. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 400,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.