Blog NIS2 & NÚKIB

NIS2 and NÚKIB: how they relate and what this means for your company

Many companies confuse NIS2 and NÚKIB or do not know how they are precisely related. NIS2 is a European law; NÚKIB is the Czech implementing authority. The relationship is direct and the consequences for businesses are specific: registration, inspections, and sanctions.

3 April 2026 · 8 minutes reading · NIS2 & NÚKIB

If you have recently come across the terms NIS2 and NÚKIB and are unsure how they relate, you are not alone. Confusion also exists among managers of companies legally required to address both topics. Simply put: NIS2 is the rule of the game, NÚKIB is the referee..

NIS2: European cybersecurity law

NIS2 (Network and Information Security Directive 2, EU 2022/2555) is a European directive that replaced the original NIS1 from 2016. Its aim is to raise the level of cybersecurity across the entire European Union and ensure that critical sectors in all member states meet similar security standards.

Key characteristics of NIS2:

NIS2 is in itself an EU directive. That is, instructions for Member States on how to adjust their legislation. Companies do not comply with NIS2 directly, but through the national law that implements it.

How did the Czech Republic implement NIS2?

In the Czech Republic, the NIS2 Act No. Act No. 264/2025 Coll. On Cybersecurity, which entered into force in October 2025. It is supplemented by implementing decree No. 409/2025 Coll., which specifies technical and organisational measures in detail.

Act No. 264/2025 Coll. Goes beyond NIS2 in certain respects. It adapts requirements to the Czech reality, defines specific deadlines and specifies conditions for categorising entities.

NÚKIB: national regulator for NIS2

NÚKIB (National Cyber and Information Security Authority) is the body that enforces Act No. 264/2025 Coll. It is an administrative authority: a regulator, just as the ČNB is for banking or the ČTÚ for telecommunications.

The specific role of NÚKIB in the context of NIS2:

Timeline: from NIS2 to your registration

December 2022 - NIS2 approved by the EU The European Parliament has approved EU Directive 2022/2555. Member States have been given 21 months to implement it into national legislation.
October 2025, Act No. 264/2025 Coll. Enters into force The Czech implementation of NIS2 is now in force. From this moment, companies are obliged to begin fulfilling their obligations.
By the end of 2025: mandatory registration with NÚKIB Existing regulated entities must have completed registration. New entities have 3 months from meeting the conditions.
2026 - gradual implementation of security measures Deadlines for implementing technical and organisational measures according to the entity category. NÚKIB launches the first inspection waves.

Direct communication with NÚKIB: what must you do?

As a regulated entity, you will have an active relationship with NÚKIB: not just passively complying with the law, but actually communicating with the authority.

NIS2 vs. NÚKIB: what is your priority?

For practical business planning, a simple rule applies: Comply with Act No. 264/2025 Coll. And Decree No. 409/2025 Coll., this will automatically ensure compliance with NIS2.You do not need to read European directives: Czech legislation and NÚKIB methodologies are sufficient.

Key areas where NÚKIB directly affects your processes:

For a deeper understanding of the NÚKIB's role, read our introductory article. What is NÚKIB and what does it doIf you are handling registration, visit the guide. Step-by-step registration in the NÚKIB system.

Are you unsure of your position?

SecureOn will carry out a gap analysis of your current status against Act 264/2025 Coll. And prepare a specific action plan. Start with a free consultation or an online audit at nis2ok.cz.

Do you need advice on safety?

Our experts will prepare a security audit tailored to your company. The first consultation is free of charge.

Get a free consultation →