One of the most frequent questions we hear from company directors and board members is: What actually happens to us if we fail to comply with NIS2? The answer is not pleasant. Act No. 264/2025 Coll. Has introduced one of the strictest sanction regimes in the history of Czech cybersecurity regulation, and unlike GDPR, personal liability for management is explicitly enshrined directly in the law.
This article explains who enforces fines, what the specific amounts are and what individuals face: not just companies as abstract entities.
NÚKIB: regulator with real teeth
The National Cyber and Information Security Authority (NÚKIB) is the main supervisory authority for implementing Act 264/2025 Coll. Unlike the previous legal framework, NÚKIB now has significantly strengthened powers, which include:
- On-site inspections without prior notice for key entities (Annex I)
- Requesting documentation - all policies, risk analyses, incident records and audits
- Ordering remedial measures with specific deadlines
- Temporary ban on operation systems or services in case of immediate danger
- Imposition of fines by administrative decision
- Submitting reports to initiate criminal proceedings in case of suspicion of a criminal offence
It is important to understand that NÚKIB does not only inspect when something goes wrong. Planned and unplanned inspections can also be carried out at companies that have reported no incidents. The mere absence of registration or failure to report an incident constitutes a separate ground for initiating proceedings.
Fine amounts: exact figures
The Act distinguishes between two basic categories of regulated entities and sets a different fine cap for each. Penalties are always calculated as the higher of the two values - an absolute limit or a percentage of turnover.
| Entity category | Maximum fine (absolute) | Maximum fine (% of turnover) |
|---|---|---|
| Key entity (Annex I) | 250 000 000 Kč | 2% of global annual turnover |
| Key stakeholder (Annex II) | 125 000 000 Kč | 1.4% of global annual turnover |
For a company with a global turnover of 500 million Kč, the maximum fine as a key entity amounts to 10 million Kč (2 % of 500 mil.). For a company with a turnover of 20 billion Kč, the absolute cap of 250 million Kč applies.
In addition to the fine itself, NÚKIB may impose:
- Obligation to publish information about a breach of duty (so-called naming and shaming)
- Remedial measures with specific deadlines and penalties for delay
- In case of repeated or serious violations, a temporary restriction or ban on providing the service may be imposed.
Personal responsibility of management
This is an aspect that many directors and board members still underestimate. Act No. 264/2025 Coll. Introduced direct personal liability for senior persons, on two levels.
1. Administrative offence committed by a senior person
If a senior person (a member of the statutory body, director, prokurist or any other person with decision-making authority) seriously breaches or persistently neglects obligations arising from the Act, the Office for Personal Data Protection may impose a fine imposed directly on an individual up to a maximum of 5 000 000 Kč.
2. Temporary suspension of duties
The most serious sanction for management is the possibility of NÚKIB proposing to the court. temporary ban on performing the control function. This measure may be applied when:
- The company repeatedly or seriously breaches the law and management has been demonstrably informed.
- The management actively obstructed or hindered the inspection activities of NÚKIB.
- There is an immediate threat of a serious cyber incident due to neglected obligations.
A ban on exercising a function is not merely a symbolic penalty; it means that the person concerned may not hold any managerial position in any regulated organisation for the duration of the ban. The length of the ban ranges from 3 months to 2 years.
How enforcement works in practice
The NÚKIB control process typically consists of several phases:
- Notice of Inspection Commencement (for scheduled inspections; unscheduled inspections at key entities are carried out without prior notice)
- Collection of documentation - NÚKIB requires the submission of policies, risk analyses, incident records and audit results.
- On-site inspection - inspectors survey the premises and interview key staff members
- Inspection Report - description of findings with a deadline for the inspected entity to provide its statement
- Remedial measure or initiation of administrative proceedings - upon discovery of a breach of the law
- Decision on the fine - with an appeal proceeding under the Administrative Procedure Code
The entire process, from the initiation of the inspection to the legally binding decision, typically takes 6-18 months. Fines are payable once the decision has become legally binding.
Most common reasons for initiating proceedings
Based on experience from EU countries where NIS2 came into force earlier, the most common triggers for an inspection or investigation are:
- Failure to report a serious incident within the specified deadline (24 hours for preliminary notification, 72 hours for detailed report)
- Lack of registration at the regulator, even though the company meets the criteria for a regulated entity
- Discovery of a serious security gap in the event of an incident or based on information from a third party
- Repeated incident reports of the same type: indicates an inability to rectify the system fault
- Information from employees or suppliers on gross negligence of safety
How to prepare as early as today
The best defence is a proactive approach. Before the NÚKIB inspection arrives, we recommend:
- Carry out an internal gap analysis or use the free audit on nis2ok.cz
- Ensure that company management is demonstrably aware of legal requirements and their personal liability.
- Compile and approve basic security documentation (policy, risk analysis, incident response plan).
- Set up the NÚKIB incident reporting process with clear responsibilities and deadlines.
- In case of uncertainty regarding categorisation or obligations, consult an expert. NIS2Manager.cz
For ongoing monitoring of compliance status and preparation for audits, we recommend the SecureOn tool. nis2manager.cz, which helps organisations keep track of their obligations and prepare supporting documentation.