Home › Frameworks › NÚKIB measures

NÚKIB’s NIS2 measures, ready to run.

Dazr includes the security measures of NÚKIB’s Decrees 409/2025 and 410/2025 as a ready-made framework, next to EU NIS2, with registration and incident reporting under Act 264/2025. Every measure becomes a recurring control with an owner, evidence and reminders. On every plan, including Free.

At a glance

  • Source: Act 264/2025 on cybersecurity, in force since 1 November 2025, with Decrees 409/2025 and 410/2025.
  • Higher regime: Decree 409/2025, 25 measures in §§ 3 to 27.
  • Lower regime: Decree 410/2025, 12 measures in §§ 3 to 14.
  • Controls: 43, the 37 measures plus registration, reported data, regime, scope and incident reporting under the Act.
  • Plan: on every plan, including Free.

On this page

  1. What does Act 264/2025 require?
  2. Higher or lower regime
  3. What you get in Dazr
  4. Reporting incidents to NÚKIB or Národní CERT
  5. The decrees next to NIS2
  6. How Dazr helps with the NÚKIB measures

What does Act 264/2025 require?

Act 264/2025 on cybersecurity transposes NIS2 in Czechia and replaced Act 181/2014 on 1 November 2025. A provider of a service that meets the conditions notifies it to the National Cyber and Information Security Agency (NÚKIB) within 60 days, and NÚKIB decides on its registration as a regulated service. Within 30 days of that decision the provider reports its contact and supplementary data, and changes within 14 days. Notifications and reports go through Portál NÚKIB.

Higher or lower regime

  • Higher regime: providers of significant economic, social or security importance follow Decree 409/2025, with a full management system, security roles, a risk assessment, audits and technical measures.
  • Lower regime: the other providers follow Decree 410/2025, a shorter set of minimum measures with an overview of measures that is updated every year.
  • Deadline: the security measures and incident reporting must be in place within one year of the registration decision.

In Dazr you record your regime in one control. The controls of the other regime are marked as not applicable in the Statement of Applicability, with the registration decision as the reason.

What you get in Dazr

Registration and scopeNotifying the service, reporting contact and supplementary data, your regime and deadline, and the scope of cybersecurity management.
Higher regime: organisational measuresThe management system, top management, security roles, policy, assets, risks, suppliers, people, changes, access, incidents, continuity and audit.
Higher regime: technical measuresPhysical and network security, identity and authentication, access rights, detection, logging, vulnerability scans and penetration tests, cryptography, availability and industrial systems.
Lower regime: security measuresThe minimum measures of Decree 410/2025, from the overview of measures and top management to passwords, logging, network security and assessing how significant an incident is.

Each control cites its section, such as Decree 409/2025 § 8, and turns its requirements into steps with a default review cadence.

Reporting incidents to NÚKIB or Národní CERT

Under § 16 of Act 264/2025 an initial report is due without undue delay and within 24 hours of detecting the incident. An incident with a significant impact also needs a notification within 72 hours of detection, an interim report on request and a final report within 30 days of the notification. Providers in the higher regime report to NÚKIB, those in the lower regime report incidents with a significant impact to Národní CERT, both through Portál NÚKIB. With the NÚKIB framework turned on, the incident register in Dazr counts down each of these deadlines.

The decrees next to NIS2

Every measure in Dazr names the ISO 27001 controls and the NIS2 article it maps to. Turn on the NÚKIB framework next to NIS2 or ISO 27001 and link the same evidence to each of them.

AreaHigher regime (409/2025)Lower regime (410/2025)NIS2
Governance and roles§ 3 to § 6§ 3 and § 4Art. 20; Art. 21(2)(a)
Assets, risks and suppliers§ 7 to § 9§ 3Art. 21(2)(a) and (d)
People and awareness§ 10§ 5Art. 20(2); Art. 21(2)(g) and (i)
Changes, acquisition and access§ 11 to § 13§ 7Art. 21(2)(e) and (i)
Incidents and continuity§ 14 and § 15§ 6, § 10 and § 14Art. 21(2)(b) and (c); Art. 23
Audit and review§ 16§ 3 (yearly review of effectiveness)Art. 21(2)(f)
Technical measures§ 17 to § 27§ 7 to § 9 and § 11 to § 13Art. 21(2)(b), (e), (h) and (j)

How Dazr helps with the NÚKIB measures

With Dazr Compliance you can:

  • Record the registration decision, your regime and the one-year deadline, and keep the reported data up to date
  • Run the measures of your regime on schedule, with owners, evidence, reminders and a weekly overdue chaser
  • Keep top management’s approvals and training on file
  • Report incidents on time: the incident register counts down the 24-hour, 72-hour and 30-day deadlines
  • Give your auditor a time-limited, read-only login, or hand over a PDF audit trail
Incident register with a GDPR notification countdown and a NIS2 incident-notification milestone
The register with a GDPR notification countdown and the next NIS2 milestone.

Sources: Act 264/2025 on cybersecurity, Decree 409/2025, Decree 410/2025, NÚKIB, reporting incidents, Portál NÚKIB.

NÚKIB measures, questions answered.

Is this the official text of the decrees?

No. Each control sums up one section in plain words and cites the act or decree and the section, so you can check it against the text in the Collection of Laws. The binding texts are Act 264/2025 and Decrees 409/2025 and 410/2025.

We are in the lower regime. Do we also see Decree 409/2025?

Yes, so you know what changes if your service moves to the higher regime. Mark the controls of the other regime as not applicable in the Statement of Applicability, with NÚKIB’s registration decision as the reason.

Do we need EU NIS2 as well?

No. The NÚKIB framework already covers the Czech measures and the reporting deadlines. If you also operate in other EU countries, turn on EU NIS2 next to it and link the same evidence to both.

Which plan do we need?

The NÚKIB framework is on every plan, including Free with one user and one framework. Pro, €99 a month, adds up to five users and five frameworks, the auditor login and the vendor register; try it free for 14 days.

Ready for the NÚKIB measures?