If you have recently come across the terms NIS2 and NÚKIB and are unsure how they relate, you are not alone. Confusion also exists among managers of companies legally required to address both topics. Simply put: NIS2 is the rule of the game, NÚKIB is the referee..
NIS2: European cybersecurity law
NIS2 (Network and Information Security Directive 2, EU 2022/2555) is a European directive that replaced the original NIS1 from 2016. Its aim is to raise the level of cybersecurity across the entire European Union and ensure that critical sectors in all member states meet similar security standards.
Key characteristics of NIS2:
- Applies to approximately 160,000 organisations across the EU in 18 sectors
- Distinguishes key entities (essential entities) and key entities (important entities)
- Sets minimum security measures: risk management, incident response, supply chain, training, MFA, encryption.
- Requires reporting of incidents within 24 hours of discovery.
- Introduces personal liability for management.
NIS2 is in itself an EU directive. That is, instructions for Member States on how to adjust their legislation. Companies do not comply with NIS2 directly, but through the national law that implements it.
How did the Czech Republic implement NIS2?
In the Czech Republic, the NIS2 Act No. Act No. 264/2025 Coll. On Cybersecurity, which entered into force in October 2025. It is supplemented by implementing decree No. 409/2025 Coll., which specifies technical and organisational measures in detail.
Act No. 264/2025 Coll. Goes beyond NIS2 in certain respects. It adapts requirements to the Czech reality, defines specific deadlines and specifies conditions for categorising entities.
NÚKIB: national regulator for NIS2
NÚKIB (National Cyber and Information Security Authority) is the body that enforces Act No. 264/2025 Coll. It is an administrative authority: a regulator, just as the ČNB is for banking or the ČTÚ for telecommunications.
The specific role of NÚKIB in the context of NIS2:
- Registry of entities administration - maintains a list of all regulated entities in the Czech Republic
- Accepting registrations - companies register with NÚKIB under NIS2, not with the EU
- Accepts incident reports - report serious cyber incidents to NÚKIB
- Carries out inspections - verifies compliance with obligations on-site or remotely
- Imposes sanctions - for violation of Act No. 264/2025 Coll.
- Issues warnings and recommendations - ongoing information on threats
- Coordinates response to incidents - during extensive attacks on critical infrastructure
Timeline: from NIS2 to your registration
Direct communication with NÚKIB: what must you do?
As a regulated entity, you will have an active relationship with NÚKIB: not just passively complying with the law, but actually communicating with the authority.
- Registration - one-off, via the NÚKIB portal (nukib.gov.cz)
- Incident reporting - obligation to report within 24 hours of detecting a serious incident; detailed report within 72 hours
- Notice of Changes - if key information changes (sector, size, contact person), you must notify the ÚKIB.
- Response to inspections - cooperation during planned and unplanned inspections
- Compliance with binding instructions - if NÚKIB issues an instruction, you are legally obliged to comply within the specified deadline
NIS2 vs. NÚKIB: what is your priority?
For practical business planning, a simple rule applies: Comply with Act No. 264/2025 Coll. And Decree No. 409/2025 Coll., this will automatically ensure compliance with NIS2.You do not need to read European directives: Czech legislation and NÚKIB methodologies are sufficient.
Key areas where NÚKIB directly affects your processes:
- Registration: without it, you will be in breach from October 2025
- Incident reporting: failure to report a serious incident is itself a breach of the law.
- Documentation, During an inspection, NÚKIB will require a risk analysis, security policy, and training records.
- Contact person management: must always be available and respond to requests from NÚKIB
For a deeper understanding of the NÚKIB's role, read our introductory article. What is NÚKIB and what does it doIf you are handling registration, visit the guide. Step-by-step registration in the NÚKIB system.
Are you unsure of your position?
SecureOn will carry out a gap analysis of your current status against Act 264/2025 Coll. And prepare a specific action plan. Start with a free consultation or an online audit at nis2ok.cz.