localproblems.orgvol. 2026 · no. 33
P-0008

6,000+ Czech firms and municipalities must implement NIS2 security measures on rolling deadlines through late 2026-2027 and most lack the capacity — many don't know they're in scope

Category
Legal
Locality
Czechia · national
Updated
Created
Sources
08
Proof0/3UNPROVEN

no foreign analog.

Money2/2ATTACHED

OPEN tender or grant ≥ ~5M CZK, or recurring annual spend.

S3 · ted-373331-2026 · ted · CZ · 2026-06-01 · €6.1MMotol + Homolka hospitals — cyber threat detection

Fakultní nemocnice Motol + Homolka awarded ~€6.1M for a cyber-threat detection & response tool ('Výzva č. 113 – Nástroj pro detekci a reakci na kybernetické hrozby', dynamic purchasing system). Hospital NIS2/ZKB security spending is real and large.

ted-373331-2026: FN Motol + Homolka awarded ~€6.1M for cyber threat detection & response tooling (TED, Jun 2026); smaller hospital awards in the same window (Hustopeče ~€1.4M, Třebíč ~€1.2M, Národní knihovna ~€1.4M) show the buying pattern.

S4 · ted-472636-2026 · ted · CZ · 2026-07-09 · €5.3MCity of Prague — SIEM security-event platform

Hlavní město Praha awarded ~€5.3M for a SIEM tool for collection and advanced analysis of security events across MHMP, city police and city districts. Municipal-scale NIS2/ZKB security buying, complementing the hospital cluster.

ted-472636-2026: Hl. m. Praha awarded ~€5.3M for a SIEM across MHMP, city police and districts (Jul 2026), plus ~€1.9M central cyber platform for městské části (ted-542109-2026, Aug 2026) — two security awards from one buyer in six weeks. Recurring public spend ≥5M CZK per award: money scored 2.

S6 · hlidac-39084314 · hlidac · CZ · 2026-08-11 · €367kČeský Brod — municipal cyber-security package

Město Český Brod (a ~7k-inhabitant town) signed 'Kybernetická bezpečnost města Český Brod' for ~9.0M CZK (11 Aug 2026). Registr smluv shows 341 cyber-security contracts since June, including NPO výzva č. 41 'Kyberbezpečnost' subsidy-funded audits (ZZS Středočeského kraje, město Jaroměř) — the small-municipality tier below TED's threshold is buying, and a subsidy stream funds it.

hlidac-39084314: město Český Brod (~7k inhabitants) signed 'Kybernetická bezpečnost města' for ~9.0M CZK (registr smluv, 11 Aug 2026); 341 cyber contracts in registr smluv since June, incl. NPO výzva č. 41 subsidy-funded audits (ZZS Středočeského kraje, Jaroměř) — the small-municipality tier is buying and a subsidy stream funds it, answering this record's open follow-up on NPO funding.

S7 · hlidac-38911766 · hlidac · CZ · 2026-06-22 · €4kNapajedla senior home — NIS2 package

Domov pro seniory Napajedla ordered an 'NIS 2 package — cyber security' from Lexnova Energy (~91k CZK, Jun 2026).

hlidac-38911766: Domov pro seniory Napajedla ordered an 'NIS 2 package — cyber security' from Lexnova Energy (~91k CZK, Jun 2026); a second Lexnova package order followed within weeks (Zlín-region disability services, hlidac-38723900) and Týn nad Vltavou bought a NIS2 scope analysis (hlidac-38370127) — the smallest obligated tier is buying productised compliance packages off the shelf. The 2026-08-13 TED run adds scale: ~77 cyber-security records from ~45 distinct public buyers (~€33M) in the Jun–Aug window alone.

S8 · hlidac-38438158 · hlidac · CZ · 2026-06-19 · €5kMěsto Boskovice — IROP call 120 cyber grant application

Boskovice contracted enovation to write and submit its subsidy application under IROP 21-27 call No. 120 'Cyber security' (~121k CZK, Jun 2026).

hlidac-38438158: Boskovice paid enovation to write its IROP 21-27 call No. 120 'Cyber security' subsidy application (~121k CZK, Jun 2026) — one of a grant-application cluster with České Budějovice (hlidac-38351500, incl. mandatory OHA/Archimate paperwork) and PN Jihlava (hlidac-38824338). A dedicated EU subsidy channel funds the municipal compliance market, and towns pay consultants just to enter the queue.

Urgency3/3FORCING

compliance date <18mo (forcing function live) (2/2); newest source < 90 days (1/1).

S1 · reg-nis2-cz-zkb · reg-scan · CZ · 2026-12-31Cybersecurity Act 264/2025 — NIS2 transposition

Czech Cybersecurity Act No. 264/2025 Coll. (NIS2 transposition, effective 1 Nov 2025) requires 6,000+ CZ firms and municipalities to register with NUKIB (deadline was 31 Dec 2025) and implement security measures within 1 year of registration, i.e. rolling deadlines through late 2026/2027; creates demand for compliance audits, vCISO services, GRC tooling and managed security for SMEs unaware they are in scope.

reg-nis2-cz-zkb: Act No. 264/2025 Coll. (NIS2 transposition), effective 1 Nov 2025; registration with NÚKIB was due ~31 Dec 2025 and security measures must be implemented within 1 year of registration — most deadlines land Q4 2026 - H1 2027 (<18 months). Fines up to 2% of global turnover / CZK 250m.

S2 · complaint · 2026-12-31complaint — sme-union.cz

SME UNION: 6,000+ firms affected across energy, manufacturing, food, logistics, digital services; many SMEs still unaware they are in scope — documented association-level alarm about capacity and awareness.

S5 · reg-cer-zakon-266 · reg-scan · CZ · 2026-07-17CER Act 266/2025 — critical-entity resilience

CER Directive transposed as zákon č. 266/2025 Sb. o odolnosti subjektů kritické infrastruktury: essential-service providers reported data to MV ČR by 1 Mar 2026, the state designates critical entities by 17 Jul 2026, and designated entities then owe risk assessments and resilience plans on statutory clocks through 2026–2027. The physical-resilience sibling of NIS2/ZKB, hitting an overlapping entity set with distinct obligations; compliance cost estimated in tens of millions CZK per firm (PORTOS).

reg-cer-zakon-266: zákon č. 266/2025 Sb. (CER transposition) — critical-entity designations by 17 Jul 2026, resilience plans and incident reporting through 2026–2027; the same under-capacity entities now owe a parallel physical-resilience stack, compliance cost estimated in tens of millions CZK per firm (PORTOS).

Demand2/2DOCUMENTED

recurring documented complaints, petition, or industry pressure.

S2 · complaint · 2026-12-31complaint — sme-union.cz

SME UNION: 6,000+ firms affected across energy, manufacturing, food, logistics, digital services; many SMEs still unaware they are in scope — documented association-level alarm about capacity and awareness.

Gap0/2UNCHECKED

CZ incumbent check not done.

Total07/12FAIR

score = proof + money + urgency + demand + gap · every point is justified by a source on file · bands: PRIME 10–12 · STRONG 8–9 · FAIR 5–7 · FAINT 0–4

The problem

Czech Act No. 264/2025 Coll. transposes NIS2 and pulls 6,000+ firms and municipalities into a regulated cybersecurity regime — energy, manufacturing, food, logistics and digital services among them. Registration with NÚKIB was due by roughly the end of 2025; security measures must be implemented within one year of registration, so the compliance wall lands on rolling deadlines from Q4 2026 through H1 2027. SME UNION documents that many affected SMEs are still unaware they are in scope at all.

Why now: the one-year implementation clocks are running, the implementing decrees (e.g. Vyhláška 409/2025 for the higher-obligations regime) are in force, and fines reach 2% of global turnover or CZK 250m. For a typical in-scope SME or small municipality there is no internal security function to absorb the work.

Who pays: the regulated entities themselves — SMEs and municipal IT budgets buying gap analyses, ISMS implementation, incident-reporting workflows and ongoing managed security (vCISO). The buyer is compelled, not persuaded: this is one of the cases where the compliance burden itself is the problem.

Existing non-solutions: the supply side exists (security consultancies, MSPs) but is a fragmented services market with no evidence of productized, SME-priced NIS2 compliance at the scale of 6,000 obligated entities; no arbitrage/gap search was run this cycle, so those dimensions score 0 rather than being asserted.

Money is now receipted from the first successful TED run (2026-08-13): hospitals and municipalities placed at least five cyber-security awards between June and August 2026, from Motol's ~€6.1M detection-and-response buy to Prague's ~€5.3M SIEM — recurring spend, multiple buyers, values above the 5M CZK bar. The demand side also widened: zákon č. 266/2025 Sb. (CER transposition) puts a parallel physical-resilience compliance stack on an overlapping entity set, with designations landing July 2026 and plan obligations running through 2027.

Updated 2026-08-13: the buying wave now runs the full size spectrum. TED shows ~77 cyber records from ~45 public buyers (~€33M) between June and August 2026; below the threshold, care homes and small towns order productised "NIS 2 packages" from Lexnova Energy repeatedly, Týn nad Vltavou paid to find out which parts of it are even regulated, and an IROP call-120 subsidy channel funds municipal projects — with towns hiring consultants just to write the applications. Note for the gap dimension: Lexnova's repeat package sales and Institut kybernetické bezpečnosti's scope-analysis product are evidence that productised CZ offerings for the small-entity tier are emerging — the supply side is no longer only fragmented consulting.

A structured gap check on productized CZ NIS2 offerings at the 6,000-entity scale is still the missing dimension; with money, deadline and demand all receipted and first productised sellers named, gap evidence is what separates this from newsletter-lead territory.

Sources

  1. Cybersecurity Act 264/2025 — NIS2 transposition
  2. complaint — sme-union.cz
  3. Motol + Homolka hospitals — cyber threat detection
  4. City of Prague — SIEM security-event platform
  5. CER Act 266/2025 — critical-entity resilience
  6. Český Brod — municipal cyber-security package
  7. Napajedla senior home — NIS2 package
  8. Město Boskovice — IROP call 120 cyber grant application