NIS2: who is affected by the new cyber law?

Updated 7 July 2026 · Let IT Bee

The abbreviation NIS2 has been appearing with increasing frequency over the past year, even outside sectors traditionally associated with cybersecurity. However, many directors of smaller companies are unsure whether the new regulations apply to them and what steps they need to take. This article summarises the basic facts - without unnecessary alarmism based on unverified figures.

What is NIS2 and where did it come from

NIS2 is European Union Directive 2022/2555, aimed at raising the level of cybersecurity across Member States. The directive itself does not directly impose obligations on companies; this is done by national law, through which each Member State transposes it into its legal system.

The Czech law introducing NIS2

In the Czech Republic, this is the new Cybersecurity Act No. 264/2025 Coll., effective from 1 November 2025. The supervisory authority responsible for monitoring compliance with the Act and processing company registrations is the National Office for Cyber and Information Security (NÚKIB).

Who is covered by the law

Compared to the previous amendment, the Act applies to a significantly wider range of entities - typically companies in sectors such as energy, transport, healthcare, digital infrastructure, public administration, or manufacturing and distribution in sensitive industries. However, the Act does not distinguish solely by sector; company size and the importance of the service provided also play a role. Therefore, an accurate assessment of whether the obligation applies to a specific company must be made individually, without relying on the assumption that "this certainly does not apply to us, we are small".

It is also important that obligations are not limited only to companies explicitly listed in the law. If you are a supplier or subcontractor of a company falling under the law, it may contractually require you to meet similar security requirements - even without a direct obligation to register with NÚKIB.

Mandatory self-identification and registration

The law is based on the principle of self-identification: it is up to each company to assess whether it meets the criteria and, if so, to register with NÚKIB. The state does not contact companies individually - the responsibility for timely assessment and registration lies with the company's management.

This is a fundamental change from previous practice, when a company could afford to wait and see whether the regulator would contact it. Now, the active step - assessment and possible registration - lies with the company, and failure to take it is treated as any other breach of the law, regardless of whether it was intentional or simply overlooked within the company.

Two compliance regimes

The Act distinguishes between two obligation regimes based on the significance of the service provided and the size of the entity. Companies in the stricter regime have a wider range of obligations and are subject to more rigorous control; companies in the second regime have fewer obligations but must still comply with them and provide proper documentation. Which regime applies to a company is determined by an individual assessment based on the criteria set out in the Act.

Failure to meet obligations may result in significant fines - specific amounts vary depending on the severity and nature of the breach, so it is better to have the situation assessed rather than relying on estimates.

Why this also concerns smaller suppliers

In practice, the impact of the Act does not stop at the boundary of directly listed entities. Large companies and institutions falling under the Act are beginning to incorporate similar security requirements into contracts with their suppliers - regardless of whether the supplier itself is subject to registration with NÚKIB. A smaller company may therefore be asked to demonstrate the security of its systems, backups or access control simply because it is part of the supply chain of a larger regulated company. It is therefore worthwhile to maintain order in IT security even if the company does not have its own registration obligation.

What to do now

NIS2 is no cause for panic, but it is a good reason to get your IT security in order before an incident or audit forces you to do so.

Are you unsure whether NIS2 applies to you?

We will carry out an IT audit and tell you what really matters.

Related articles