Registration in the NÚKIB system is the first and most fundamental step for companies required to comply with Act No. 264/2025 Coll. Without registration, you cannot legally report incidents, you fail to meet your legal obligation, and you expose yourself to sanctions. Yet the registration process itself is not technically complex, provided you know what you need.
Who is required to register?
The registration obligation applies to so-called regulated entities in accordance with Act No. 264/2025 Coll. These are organisations that comply at the same time two conditions:
- Sectoral condition - the company operates in one of the listed sectors (energy, transport, healthcare, digital infrastructure, banking, public administration and approximately 15 other areas)
- Size requirement - the company employs at least 50 people or has an annual turnover of at least 10 million EUR
The exception applies to entities whose outage would have an immediate impact on safety or critical services, these must register regardless of size (e.g., operators of critical infrastructure).
Are you unsure whether you are a regulated entity?
Use the free test on nis2ok.cz - An interactive questionnaire will determine your obligation within 10 minutes. It covers all sectors according to the annex of Act No. 264/2025 Coll.
How does registration with NÚKIB take place?
Registration is conducted exclusively electronically via the NÚKIB portal. The entire process can be completed in 1-2 hours if you have the required information ready.
Verify the registration obligation
Consult Annexes I and II of Act No. 264/2025 Coll. Or use the online questionnaire. Determine your sector and entity category (critical vs. Important).
Ensure access to the portal is available.
To register for the NÚKIB portal you need a company data box or a qualified electronic signature. Prepare your IČO, DIČ and basic company details.
Fill in the registration form
The form includes: basic details about the organisation, sector and subsector identification, company size, description of key services and the contact person for cybersecurity (CISO or other responsible employee).
Name the contact person for NÚKIB
In the registration, you must specify a contact person for communication with NÚKIB. This person receives notifications and warnings and serves as the first point of contact with the authority in the event of an incident.
Send and save the confirmation
After submission, you will receive a registration confirmation. Keep it. It serves as proof of fulfilling the legal obligation. NÚKIB will enter you into the register of entities.
Registration deadlines
Act No. 264/2025 Coll. Entered into force in October 2025. The following key deadlines apply for registration:
- Existing entities (companies that met the requirements before the law came into force): the registration obligation applied from the date the law took effect, i.e. From October 2025
- New entities (companies that meet the conditions after they come into force), obligation to register within 3 months from the moment they start meeting the conditions
- Incident reporting - after registration, you are obliged to report serious incidents to NÚKIB within 24 hours of discovery.
If you have not yet completed registration, do not delay. NÚKIB is launching the first wave of inspections and unregistered entities are easily traceable.
What are the penalties for failing to register?
Failure to meet registration obligations is an administrative offence under Section 138 of Act No. 264/2025 Coll. The following penalties apply:
- Fine up to 10 million Kč or 2% of total annual turnover (the higher of both values will be used)
- Mandatory instruction from NÚKIB for immediate rectification
- In repeated cases or in the event of serious violations, suspension of certifications or authorisation to carry out certain activities.
Sanctions are also imposed on management, personal liability of statutory bodies is one of the key new provisions of Act No. 264/2025 Coll.
What happens after registration?
Registration is just the beginning. Once completed, you must progressively fulfil further obligations under Decree 409/2025 Coll.: risk analysis, security policy, technical measures, employee training and setting up incident reporting processes.
For more information on cyber security courses and training directly from NÚKIB, see the article. NÚKIB courses and training in cybersecurity. The overall relationship between NIS2 and NÚKIB is then discussed in the article. NIS2 and NÚKIB: how they are related.
We will assist you with registration and the entire NIS2 process.
SecureOn will handle registration, gap analysis and full implementation of NIS2 measures. Start with a free consultation.
Contact SecureOn →