We have 35 employees and annual revenue of 80 million Kč. Do we need to comply with NIS2?" This question comes up very often, and the answer depends on it. In which sector do you operate?, not just on your size. Act No. 264/2025 Coll. Contains both size thresholds and sectoral exemptions, which may mean an obligation even for a small company.
Let us break this down systematically.
Basic rule: medium-sized enterprise as the starting threshold
Act No. 264/2025 Coll. Adopts the definition from the EU NIS2 Directive and stipulates that a company becomes a regulated entity if:
- Employs 50 or more employees, OR
- Achieves annual turnover or balance sheet total of 10 million EUR or more
And at the same time:
- Operates in one of sectors listed in the annexes to the Act (viz níže)
The key word is OR Regarding the size criteria, meeting just one of the conditions is sufficient. A company with 40 employees and a turnover of 12 million EUR therefore falls under NIS2. So does a company with 60 employees and a turnover of 3 million EUR.
Quick test: Do you have fewer than 50 employees and at the same time a turnover of under 10 million EUR? Then you are probably outside the basic scope of NIS2 - but read on about sector exemptions!
Two categories: critical versus important entity
If you meet the thresholds, the law will place you into one of two categories with differing levels of obligations and supervision.
Key entities (Annex I)
These are organisations in the most critical sectors: energy, transport, banking, financial infrastructure, healthcare, drinking water, wastewater, digital infrastructure (DNS, TLD, data centres, cloud), space industry and public administration.
Key entities are subject to compliance requirements. ex ante supervision - NÚKIB may carry out preventive inspections without any incident having occurred. Fines are higher (up to 250 million Kč or 2% of turnover).
Important entities (Annex II)
They include postal and courier services, waste management, the chemical industry, food production, manufacturing (medical devices, electronics, engineering, automobiles), digital marketplaces, research organisations and others.
Important entities are subject to ex post supervision - NÚKIB intervenes primarily in response to an incident or a report. Fines are lower (up to 125 mil. Kč or 1.4% of turnover).
Exceptions: when size does not matter
This is the most important part for small businesses: The law explicitly stipulates cases where it applies to a company regardless of the number of employees or the level of turnover.
The Prague surcharge does not apply if the company:
- It is provider of qualified and reliable services (qualified electronic signatures, time stamps, etc.)
- It is operator or manager of critical information infrastructure designated by the Ministry of the Interior or NÚKIB
- It is registrar or administrator of top-level domains (TLD)
- It is provider of a public communications network or electronic communications service
- Meets the criteria the only company in the sector providing a key service at a national level
- The national competent authority is explicitly designated as a critical entity
Warning: A small company with 15 employees operating a critical part of energy infrastructure or a healthcare information system can be an essential entity. The sector is primary; size is secondary.
Supply chain: indirect obligation
There is another way in which NIS2 affects small businesses without directly impacting them: through larger customers.
The law requires regulated entities to manage security risks in the supply chain. In practice, this means that your large customers (banks, hospitals, energy companies) they may require proof of your safety qualifications from you - security questionnaires, certificates, penetration tests or proof of NIS2 compliance.
Even if Act No. 264/2025 Coll. Does not directly apply to you, the ability to demonstrate your security level will help you retain and acquire customers in regulated sectors.
How to verify your obligation: free of charge, in 10 minutes
The simplest way to find out whether your company is subject to NIS2 is to use the free online tool. nis2ok.czThe tool guides you through structured questions about your sector, size and services offered, and based on your answers it will inform you:
- Whether you are a regulated entity and in which category
- What are your registration obligations and deadlines?
- Basic overview of obligations applicable to you
- Recommendations for further action
For more complex cases, particularly companies near the thresholds or in sectors with unclear classification. We recommend consulting an expert. Experts from NIS2Manager.cz they will assist with legal interpretation and precise categorisation.
What to do if you are subject to NIS2
If you have found that the law applies to you, do not panic. Although the law sets out obligations, they can be met systematically by taking it "step by step". We recommend:
- Register in the NÚKIB registry (deadlines depend on the entity category)
- Conduct an asset inventory and initial risk analysis.
- Proceed NIS2 checklist: 20 steps and identify the largest gaps
- Draw up an action plan for remediation with priorities and responsibilities.
- Set up the incident reporting process
For small companies subject to NIS2, the key is proportional approach - the law itself emphasises that measures must be proportionate to the size, resources and level of risk of the organisation. You do not need to build a security centre like a large bank, but you must demonstrate a systematic approach to cybersecurity.