6,000 Czech towns and firms have months left to meet a new cybersecurity law

Many small firms don't even know the law covers them, and the first deadlines hit in late 2026.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.Complaint · A firm that misses its deadline can be fined up to 2% of its turnover (which is A LOT of money).Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation ·

Good for Someone with cybersecurity skills who's interested in grants and public-sector sales.

Category
Legal
Entry
Hard
Verified

The opportunity

2/2 · Clear, recurring pain

The new cybersecurity law makes each covered organisation register, then put security measures in place within a year.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation ·

  • About 6,000 towns and firms are covered, in energy, manufacturing, food, logistics and digital services.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.Complaint ·
  • Many small firms do not yet know the law covers them.SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.Complaint ·
  • The top fine is CZK 250m or 2% of global turnover.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.Statistic ·

Suggested solution

Build a small security agency that does the security work, and writes EU grant applications for the towns that qualify.

  1. A consultant who checks what the law requires. Today: Checks whether the new cybersecurity law covers the organisation, and what it owes. With the suggested solution: One fixed-price provider makes the same check, before the organisation's deadline.
  2. The town or care home. Today: Registers with the national cyber-security agency, which starts its one-year deadline for security measures. With the suggested solution: Unchanged: registering is the organisation's own duty.
  3. A consultant who writes grant applications. Today: Writes the EU grant application for the organisations that can get one. With the suggested solution: The same provider writes the application, inside the fixed price.
  4. A seller of ready-made compliance documents. Today: Sells the required documents as a package, without doing the security work. With the suggested solution: The documents describe security work the provider has actually done.
  5. Nobody in-house, at most of these organisations. Today: Nobody carries out the security measures; one university had to re-run its tender for an outside security manager. With the suggested solution: The provider does the security work itself, at the same fixed price.
  6. Who does this is not known. Today: Who checks the measures after the deadline, and when, is not known. With the suggested solution: Unchanged: the provider prepares the organisation for that check but does not perform it.

Not known: who checks the measures after the deadline, and when.

Why now

3/3 · Deadline with penalties

Towns, care homes and firms under the new law run out of time in late 2026, and first steps already cost about 100,000 CZK.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.Subsidy ·

  • A firm's owner has one year from registering with the national cyber-security agency to put the required security in place, so the first deadlines fall in late 2026.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · A firm that misses its deadline can be fined up to 2% of its turnover.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.Statistic ·
  • A town's director who wants the EU to pay half of the work first pays a consultant about 121,000 CZK just to write the grant application.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.Subsidy · IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.Subsidy · The grant stops taking applications on 17 December 2026, so a town that has not applied by then pays the full cost itself.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.Subsidy ·
  • Hiring someone to do the work is hard. Mendel University in Brno had to run its tender for an outside security manager, the person the law requires to be in charge of security, a second time in August 2026, and in September it pushed the closing date for bids back to 22 October 2026.2 sourcesTEDted.europa.euMendel University cybersecurity manager — repeat procurement procedure (another site)Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. The notice was posted to the EU's TED procurement portal on 26 August 2026 under the govtech sector.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”Tender · TEDted.europa.euTED — Mendel University pushes its security-manager deadline back (another site)The university's repeated tender for the outsourced security manager the law requires was still open in September 2026, with its closing date moved from 29 September to 22 October.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”Tender · A care home bought a ready-made package instead, at the price shown under Willing to pay.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Contract ·

Willing to pay

2/2 · Clear signs

The covered organisations pay, and towns, regions and hospitals can get half back from an EU grant.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Regulation · IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.Subsidy ·

  • About €33M in public cyber-security tenders and awards landed in June–August 2026 alone.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Contract ·
  • About 121,000 CZK is what one town paid a consultant just to write its grant application.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.Subsidy ·
  • €500–6,000 a year is what compliance software costs one organisation.reglyze.comReglyze — NIS2 tooling price survey (another site)Named annual prices for NIS2 compliance software: Reglyze from €490/yr, Secfix ~€500 a month, Vanta and Drata ~$7,500 a year, OneTrust $30k+ — what a per-firm product can realistically charge.Statistic ·

Per seat, monthly

One purchase

Validated abroad

3/3 · Proven in 2+ markets

Two funded European companies sell software that automates security compliance.2 sourcesVestbeevestbee.comSecfix (another site)Berlin, €10.2M Series A (Feb 2026) for AI-driven security-compliance automation for SMEs — the closest funded template for a productised NIS2 offer.Funding round · Vestbeevestbee.comCopla (another site)Vilnius, €6M Series A (Feb 2026) for real-time compliance monitoring — a second funded compliance-automation player next door, covering NIS2, DORA and ISO 27001.Funding round ·

Where it works: DE, LT — home market CZDELTCZ
  1. Secfix (another site)Based in Germany
  2. Copla (another site)Based in Lithuania

Market gap

1/2 · Early rivals only

Four Czech sellers offer the paperwork the law requires, and none sells the security work itself.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Contract · Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.Market check ·

New, selling this: Lexnova Energy (since 2025), NIS2 Doku (since 2025), NIS2 Průvodce (since 2025), Compligen (since 2026). Established, selling this: nobody on file. New, selling something nearby: nobody on file. Established, selling something nearby: ICZ Risk*Guide (since 1997). No established player sells this here.

The space is still open

Execution difficulty

1/3 · Hard

Makes it easier

  • The law's deadlines push towns and firms to buy now.
  • An EU grant pays half for towns.
  • No licence is needed to do the work.

Makes it harder

  • The buyers are public bodies.
  • They want references a new provider does not have yet.

Suggested first moves

  1. Build a simple, fixed-price check that tells a small town exactly what the new cybersecurity law requires of it and by when.
  2. Call the directors of care homes and small towns that are already paying for help with this law, and offer them the check.
  3. For each town that can get the EU grant, write its grant application, so the EU pays half of the security work that follows.