What does Act 264/2025 require?
Act 264/2025 on cybersecurity transposes NIS2 in Czechia and replaced Act 181/2014 on 1 November 2025. A provider of a service that meets the conditions notifies it to the National Cyber and Information Security Agency (NÚKIB) within 60 days, and NÚKIB decides on its registration as a regulated service. Within 30 days of that decision the provider reports its contact and supplementary data, and changes within 14 days. Notifications and reports go through Portál NÚKIB.
Higher or lower regime
- Higher regime: providers of significant economic, social or security importance follow Decree 409/2025, with a full management system, security roles, a risk assessment, audits and technical measures.
- Lower regime: the other providers follow Decree 410/2025, a shorter set of minimum measures with an overview of measures that is updated every year.
- Deadline: the security measures and incident reporting must be in place within one year of the registration decision.
In Dazr you record your regime in one control. The controls of the other regime are marked as not applicable in the Statement of Applicability, with the registration decision as the reason.
What you get in Dazr
Each control cites its section, such as Decree 409/2025 § 8, and turns its requirements into steps with a default review cadence.
Reporting incidents to NÚKIB or Národní CERT
Under § 16 of Act 264/2025 an initial report is due without undue delay and within 24 hours of detecting the incident. An incident with a significant impact also needs a notification within 72 hours of detection, an interim report on request and a final report within 30 days of the notification. Providers in the higher regime report to NÚKIB, those in the lower regime report incidents with a significant impact to Národní CERT, both through Portál NÚKIB. With the NÚKIB framework turned on, the incident register in Dazr counts down each of these deadlines.
The decrees next to NIS2
Every measure in Dazr names the ISO 27001 controls and the NIS2 article it maps to. Turn on the NÚKIB framework next to NIS2 or ISO 27001 and link the same evidence to each of them.
| Area | Higher regime (409/2025) | Lower regime (410/2025) | NIS2 |
|---|---|---|---|
| Governance and roles | § 3 to § 6 | § 3 and § 4 | Art. 20; Art. 21(2)(a) |
| Assets, risks and suppliers | § 7 to § 9 | § 3 | Art. 21(2)(a) and (d) |
| People and awareness | § 10 | § 5 | Art. 20(2); Art. 21(2)(g) and (i) |
| Changes, acquisition and access | § 11 to § 13 | § 7 | Art. 21(2)(e) and (i) |
| Incidents and continuity | § 14 and § 15 | § 6, § 10 and § 14 | Art. 21(2)(b) and (c); Art. 23 |
| Audit and review | § 16 | § 3 (yearly review of effectiveness) | Art. 21(2)(f) |
| Technical measures | § 17 to § 27 | § 7 to § 9 and § 11 to § 13 | Art. 21(2)(b), (e), (h) and (j) |
How Dazr helps with the NÚKIB measures
With Dazr Compliance you can:
- Record the registration decision, your regime and the one-year deadline, and keep the reported data up to date
- Run the measures of your regime on schedule, with owners, evidence, reminders and a weekly overdue chaser
- Keep top management’s approvals and training on file
- Report incidents on time: the incident register counts down the 24-hour, 72-hour and 30-day deadlines
- Give your auditor a time-limited, read-only login, or hand over a PDF audit trail

Sources: Act 264/2025 on cybersecurity, Decree 409/2025, Decree 410/2025, NÚKIB, reporting incidents, Portál NÚKIB.