What your company must comply with by the end of 2026: NIS2 checklist
Act 264/2025 Coll. Is in force, but many companies still do not know exactly where they stand. We have prepared a clear checklist covering all key areas, print it out, share it with your team and tick off the items.
3 November 2025·7 minutes reading·NIS2 Checklist
Act No. 264/2025 Coll. On cybersecurity entered into force in October 2025. Regulated entities: approximately 6,000 companies and organisations in the Czech Republic, are required to gradually meet the requirements set out by the Act and Implementing Decree No. 409/2025 Coll. Deadlines vary according to the entity category, but 2026 is a key year for implementation for most companies.
This checklist covers four main areas: organisational measures, technical measures, documentation and registration with NÚKIBEach item refers to specific requirements of Decree No. 409/2025 Coll.
Are you unsure whether the law applies to you at all?
First verify whether your company is a regulated entity under Act No. 264/2025 Coll. Use the free online audit at secureon.cz nis2ok.cz - result within 10 minutes.
1. Organisational measures
Organisational measures form the foundation of NIS2 compliance. Without a properly established organisational structure and clear responsibilities, neither technical nor documentation requirements can be effectively met.
Organisational measures
2. Technical measures
Technical measures under Decree 409/2025 Coll. Cover network security, access management, cryptography, monitoring and recovery after an incident. This is the broadest area with the greatest potential impact on IT infrastructure.
Technical measures
3. Documentation
Decree No. 409/2025 Coll. Explicitly requires a set of documents that the regulated entity must have available and update regularly. Without documentation, compliance cannot be demonstrated, even during an inspection by NÚKIB.
Mandatory documentation
4. Registration with NÚKIB
The obligation to register with the National Cyber and Information Security Authority (NÚKIB) is one of the first specific duties arising from Act No. 264/2025 Coll.
Registration and communication with NÚKIB
What are the next steps?
If you have ticked off fewer than half of the items, we recommend immediately launching a structured gap analysis process. Start by a free online audit on nis2ok.cz, which will show you priority areas within 10 minutes. For an in-depth gap analysis and the preparation of an action plan, contact us. SecureOn.czIf you need a certified cybersecurity manager, visit secureon.cz. NIS2Manager.cz.