The NIS2 Directive will affect at least 6,000 Czech subjects

New legislation on cybersecurity is expected to be passed in response to the implementation of the NIS2 Directive. The law should be endorsed and enter into force as early as mid-2024, but no later than 17 October 2024 in accordance with the transposition requirements.

A major change is the broadening of the scope of obligations in the field of cybersecurity, in particular as regards determining obliged persons to include service providers in 18 sectors, such as energy and healthcare, and also the food industry and certain types of equipment manufacturing.

According to the new Directive, selected hitherto non-obliged entities will be required to implement technical and organizational security measures, report cyber incidents and threats, and submit to inspections, audits and other requirements of the competent authorities.

The NIS2 Directive sets a maximum fine requirement for national legislation of at least CZK 250 million or 2% of turnover.

For more information on NIS2, go to the NÚKIB website.