Czech Republic NIS2: NUKIB vs CSIRT.CZ — Which Authority Oversees You and How to Register Within 60 Days
The Czech Republic has an unusual NIS2 oversight architecture. While most EU member states route all regulated entities through a single national authority, the Czech Zákon o kybernetické bezpečnosti (ZoKB, Act No. 264/2025 Coll.) splits supervisory responsibility across two separate bodies — determined by whether your organisation is classified as an essential or an important entity.
One of those bodies, CSIRT.CZ, is operated by CZ.NIC, an association best known for running the Czech .cz domain registry. The other, NUKIB (the National Cyber and Information Security Agency), is the state authority that issues registration decisions, holds full enforcement powers, and operates a 24/7 government CERT. Understanding which body applies to your organisation is not a technical footnote — it determines who receives your incident reports, who can inspect your premises, and who can impose fines.
ZoKB came into force on 1 November 2025. NUKIB began issuing bulk registration decisions in February 2026 to establish a uniform compliance start date across entities that registered in the November–December 2025 window [6]. If your organisation received a decision then, your two 12-month compliance clocks — for security measures under §13(4) and incident reporting under §15(4) — are already running.
Does ZoKB Apply to Your Organisation?
ZoKB applies to providers of regulated services across 15+ sectors defined in Decree No. 408/2025. The default scope follows the NIS2 Directive threshold: organisations with 50 or more employees and annual turnover exceeding €10 million (approximately CZK 250 million) that operate in a regulated sector fall under ZoKB [3].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Size alone does not determine scope. Under §5 of ZoKB, an entity must be regulated regardless of employee count or turnover if any of the following apply [2]:
- The organisation holds a monopoly position in a regulated sector
- A disruption would affect national security
- A disruption would affect the lives of more than 125,000 people
Within scope, ZoKB follows the NIS2 two-tier structure:
| Classification | ZoKB term | Example sectors | Incident reporting channel |
|---|---|---|---|
| Essential entity | Vyšší povinnosti (higher obligations) | Energy, transport, banking, health, water, digital infrastructure, public administration, space | NUKIB / GovCERT.CZ |
| Important entity | Nižší povinnosti (lower obligations) | Postal services, waste management, food, chemicals, manufacturing, digital services | CSIRT.CZ (CZ.NIC) |
For a full sector-by-sector breakdown and size threshold decision tool, see How NIS2 Defines Essential vs Important Entities.
NUKIB’s Three Roles Under Czech NIS2
NUKIB holds three distinct statutory roles under ZoKB and the underlying Directive, and understanding each clarifies why essential entities face a more demanding compliance regime.
Role 1 — National Competent Authority (NCA)
Under Article 8(1) of Directive 2022/2555, each member state must designate at least one national competent authority responsible for cybersecurity supervision and enforcement [8]. The Czech Republic designated NUKIB as its sole NCA. In practice this means NUKIB issues registration decisions, conducts supervisory inspections of essential entities, and imposes administrative sanctions for violations of ZoKB obligations.
Role 2 — Single Point of Contact (SPOC)
Article 8(3) of the Directive provides that where a member state designates only one NCA, that authority automatically functions as the SPOC for cross-border liaison [8]. NUKIB therefore represents the Czech Republic in EU-level NIS2 cooperation with other member states’ authorities, the European Commission, and ENISA.
Role 3 — Government CERT (GovCERT.CZ)
Under Article 10 of Directive 2022/2555, member states must designate one or more CSIRTs covering all sectors in Annexes I and II [9]. NUKIB operates GovCERT.CZ as the national CSIRT for essential entities — the operational arm that receives incident reports, coordinates response, and provides round-the-clock emergency assistance [7].
The incident reporting obligation for essential entities is stricter than the EU baseline. Where the NIS2 Directive requires notification of “significant” incidents, ZoKB requires essential entities to report all cyber-origin incidents where intentional conduct cannot be ruled out [4]. That is a materially broader trigger than what important entities face.
GovCERT.CZ emergency contacts: +420 541 110 555 (working hours) and +420 725 502 878 (out of hours) [7].
CSIRT.CZ — CZ.NIC’s Role for Important Entities
CSIRT.CZ is operated by CZ.NIC, a non-profit association whose primary function is managing the national .cz domain registry. CZ.NIC has run a national CERT since 2010 under a memorandum with the Czech Ministry of Interior, giving it over 15 years of incident coordination experience before NIS2 came into force.
Designating a non-governmental domain registry operator as the national CSIRT for an entire tier of regulated entities is uncommon in the EU — most member states assign a unified governmental CSIRT to all entity types. France, for example, routes all entities through CERT-FR, operated by the state authority ANSSI. The Czech dual model reflects CZ.NIC’s established technical reputation and its long-standing cooperative relationship with NUKIB.
Under ZoKB, important entities direct their significant incident notifications to CSIRT.CZ [2]. CSIRT.CZ receives, triages, and provides methodological support to these entities — it does not impose fines or conduct formal supervisory inspections. Enforcement authority for both tiers sits with NUKIB.
Two practical points follow from this structure. First, the initial reporting deadline is identical for both tiers: 24 hours from discovery of a qualifying incident [3]. The channel differs; the urgency does not. Second, if an important entity incident escalates in severity, NUKIB retains authority to open a supervisory investigation regardless of which body received the initial report.
For the statutory incident notification requirements that govern what you must report and when, once §15(4) obligations activate, see NIS2 Article 23 — Incident Notification Explained.
Registering at portal.nukib.gov.cz — The Four-Step Process
Every entity in scope — essential or important — registers through the same platform: portal.nukib.gov.cz. This is NUKIB’s unified web system for regulated service notifications, contact data management, and ongoing communication with registered providers.
The 60-day window
Organisations that were already in scope on 1 November 2025 had until 31 December 2025 to submit their notification [3]. Entities that first meet ZoKB scope criteria after that date have 60 days from the moment they satisfy the conditions. NUKIB has confirmed that the duration of any delay in registration is a direct factor in fine calculation — the longer the non-compliance period, the higher the potential sanction, up to the statutory maximum [5].
Step 1 — Log in via electronic identity
The portal requires authenticated access using one of three Czech electronic identity options: bank identity (bankovní identita), the Mobile Key of eGovernment (Mobilní klíč eGovernmentu), or mojeID. Standard username and password access is not available. Foreign organisations without Czech digital identity will need to make alternative arrangements with NUKIB [5].
Step 2 — Verify authorisation
If the person completing the notification is not the organisation’s statutory officer (jednatel), a formally authorised representative must be confirmed first. Authorisation requires a signed PDF submitted through the Czech data mailbox (datová schránka) system — a step that can take several days to arrange if not prepared in advance. Build this into your timeline [5].
Step 3 — Complete the Regulated Service Notification form
The notification form collects [5]:
- Organisation identification data
- The specific regulated service being reported
- Technical infrastructure data: public IP address ranges and domains exclusively used by your organisation. Exclude all private ranges (10.x.x.x, 172.16–31.x.x, 192.168.x.x)
- Contact persons: at minimum two named individuals — one from IT or security, one with authority to make organisational decisions. Generic mailboxes such as security@company.com are explicitly insufficient; NUKIB requires the individual’s name, role title, direct phone number, and personal email address
You can include supplementary contact data in this step rather than waiting for the post-decision 30-day window, which simplifies the process.
Step 4 — Submit and await the registration decision
NUKIB reviews the notification and issues a formal written registration decision. Delivery of that decision starts three statutory clocks simultaneously: 30 days to submit any supplementary data under §11(1), 12 months to implement security measures under §13(4), and 12 months before incident reporting obligations begin under §15(4) [6].
Any subsequent change to your registered data — new staff contacts, updated IP ranges, modified services — must be reported through the portal within 14 days of the change [5].
The 12-Month Compliance Clock: What Starts After Registration
Receiving NUKIB’s registration confirmation is the start of your compliance window, not evidence of compliance. Two parallel 12-month obligations run from the decision date [6]:
| Obligation | ZoKB provision | What it requires |
|---|---|---|
| Implement security measures | §13(4) | Technical and organisational controls across risk management, access controls, incident detection, supply chain security, cryptography, and business continuity |
| Begin mandatory incident reporting | §15(4) | Qualified incident notifications to NUKIB (essential entities) or CSIRT.CZ (important entities) within statutory timeframes from the moment of discovery |
NUKIB issued its bulk decisions during February 2026 to create a uniform starting point across entities that had registered in November–December 2025 [6]. For most registered organisations, both the §13(4) security measures deadline and the §15(4) incident reporting activation date fall in approximately February 2027.
The role ZoKB places at the centre of compliance delivery is the Cybersecurity Manager (Manažer kybernetické bezpečnosti). This individual bears statutory responsibility for ensuring that security measures are implemented within the 12-month window and that incident reports are filed on schedule once obligations activate. Designating this person — and briefing them on the specific §13(4) and §15(4) deadlines derived from your decision date — is the highest-priority action following receipt of NUKIB’s registration decision [6].
Essential entities face a more demanding security programme than important entities. Beyond the Cybersecurity Manager, they must designate a Cybersecurity Architect and a Cybersecurity Auditor, conduct regular penetration testing, implement supply chain vendor verification mechanisms, and maintain service availability with operations hosted within Czech territory [4]. Important entities implement proportionately reduced controls calibrated to their operational scope and risk profile.
For a detailed breakdown of the incident notification obligations that activate after this window, see NIS2 Incident Reporting: Timelines, Thresholds, and What to Submit.
Penalties Under ZoKB
ZoKB mirrors the NIS2 Directive’s penalty structure while adding Czech-specific offense categories and management liability provisions [2][3]:
| Entity type | Maximum administrative fine | Offense categories |
|---|---|---|
| Essential (higher obligations) | CZK 250 million (~€10.3 million) or 2% of worldwide annual net turnover, whichever is higher | 15 categories |
| Important (lower obligations) | CZK 175 million (~€7.2 million) or 1.4% of worldwide annual net turnover, whichever is higher | 8 categories |
NUKIB is the sole enforcement authority for both entity tiers. CSIRT.CZ provides incident coordination support for important entities but does not issue fines, conduct formal supervisory inspections, or impose binding orders [2].
ZoKB introduces direct management accountability: board members of non-compliant entities can face a temporary prohibition from their role of at least six months for serious violations [3]. This mirrors the management body accountability principle in the NIS2 Directive, which requires that those governing essential and important entities approve cybersecurity risk-management measures and can be held personally responsible for systematic failures.
Organisations subject to GDPR enforcement should note that ZoKB — consistent with the underlying Directive — contains a double-jeopardy safeguard: where the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, ÚOOÚ) has already imposed an administrative fine for a personal data breach, NUKIB may not additionally impose a NIS2 penalty for the same underlying conduct. Non-monetary measures such as warnings and binding orders remain available under both regimes. For how ZoKB interacts with other Czech security legislation, see NIS2 Scope: Who Must Comply in the Czech Republic.
Five Actions to Take Now
The Czech NIS2 structure splits supervisory responsibility across NUKIB and CSIRT.CZ by entity tier, but registration, compliance timelines, and penalties run through a single framework. The following checklist covers the most time-sensitive steps:
- Confirm your entity tier — apply the ≥50 employees AND turnover >€10M threshold together with the §5 size-independent criteria (monopoly position, national security impact, 125,000-person disruption threshold) to determine whether you are under higher or lower obligations
- Register if you have not yet done so — portal.nukib.gov.cz; 60 days from the moment your organisation first meets ZoKB scope criteria; the delay duration affects fine calculation
- Identify your registration decision date — if NUKIB delivered your decision in February 2026, your §13(4) security measures deadline and §15(4) incident reporting activation date both fall in approximately February 2027
- Designate your Cybersecurity Manager — the statutory role that bears responsibility for security measure implementation and incident reporting compliance under ZoKB; brief this person on both §13(4) and §15(4) deadlines derived from your specific decision date
- Verify your registered contact data — two named individuals with direct phones and personal email addresses; any change must be reported to NUKIB via the portal within 14 days
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- European Commission — NIS2 Directive Implementation in the Czech Republic
- OpenKRITIS — EU NIS2 in Czech Republic
- Copla — NIS2 Czech Republic: Implementation, Deadlines, and Compliance
- ICLG — Cybersecurity Laws and Regulations Report 2026: Czech Republic
- Sedlakova Legal — NÚKIB Portal: What to Fill In, Who Signs It
- TAYLLORCOX — NÚKIB Delivering Registration Decisions (ZoKB)
- NUKIB — GovCERT.CZ (nukib.gov.cz/en/cyber-security/government-cert/govcert-cz/) [hyperlinked inline above]
- NIS2 Directive Article 8 — Competent Authorities (nis-2-directive.com) [hyperlinked inline above]
- NIS2 Directive Article 10 — CSIRTs (nis-2-directive.com) [hyperlinked inline above]
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
