The opportunity
2/2 · Clear, recurring pain
The new cybersecurity law makes each covered organisation register, then put security measures in place within a year.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.
- About 6,000 towns and firms are covered, in energy, manufacturing, food, logistics and digital services.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.
- Many small firms do not yet know the law covers them.SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.
- The top fine is CZK 250m or 2% of global turnover.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
The opportunity
About this section
- What this shows
- The problem as it is today: what goes wrong, and who it costs.
- Why it matters to a builder
- Documented pain means you will not have to convince buyers the problem exists before you can sell them the fix.
- How to read the score
- 2/2 means clear, recurring pain: documented complaints, a petition or industry pressure. Scattered complaints make it 1/2.
The new cybersecurity law makes each covered organisation register, then put security measures in place within a year.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.
- About 6,000 towns and firms are covered, in energy, manufacturing, food, logistics and digital services.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.
- Many small firms do not yet know the law covers them.SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope.
- The top fine is CZK 250m or 2% of global turnover.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
- 4,825 had registered by February 2026, so over a thousand had not.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
- One university had to re-run its tender for an outside security manager, and in September it pushed the closing date back again.2 sourcesTEDted.europa.euMendel University cybersecurity manager — repeat procurement procedure (another site)Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. The notice was posted to the EU's TED procurement portal on 26 August 2026 under the govtech sector.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”TEDted.europa.euTED — Mendel University pushes its security-manager deadline back (another site)The university's repeated tender for the outsourced security manager the law requires was still open in September 2026, with its closing date moved from 29 September to 22 October.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”
The law is Act No. 264/2025, the Czech version of the EU's NIS2 directive (its common cybersecurity rules).Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m. Each organisation registers with NÚKIB (the national cyber-security agency), telling it that it runs a covered service, and its year for security measures runs from that registration.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.
- The agency counts a long delay against an organisation when it sets a fine.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
- The security measures are concrete steps set out in two decrees, No. 409/2025 and No. 410/2025.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies. They include a list of the organisation's computers and data, a risk assessment, supplier checks, staff training, and reporting an attack to the agency within 24 hours.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
- The university is Mendel University in Brno. In August 2026 it went back to market for an outsourced security manager, a role the law requires.TEDted.europa.euMendel University cybersecurity manager — repeat procurement procedure (another site)Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. The notice was posted to the EU's TED procurement portal on 26 August 2026 under the govtech sector.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení” In September it moved the closing date for bids to 22 October 2026, so it had still not found one.TEDted.europa.euTED — Mendel University pushes its security-manager deadline back (another site)The university's repeated tender for the outsourced security manager the law requires was still open in September 2026, with its closing date moved from 29 September to 22 October.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”
Suggested solution
Build a small security agency that does the security work, and writes EU grant applications for the towns that qualify.
- A consultant who checks what the law requires. Today: Checks whether the new cybersecurity law covers the organisation, and what it owes. With the suggested solution: One fixed-price provider makes the same check, before the organisation's deadline.
- The town or care home. Today: Registers with the national cyber-security agency, which starts its one-year deadline for security measures. With the suggested solution: Unchanged: registering is the organisation's own duty.
- A consultant who writes grant applications. Today: Writes the EU grant application for the organisations that can get one. With the suggested solution: The same provider writes the application, inside the fixed price.
- A seller of ready-made compliance documents. Today: Sells the required documents as a package, without doing the security work. With the suggested solution: The documents describe security work the provider has actually done.
- Nobody in-house, at most of these organisations. Today: Nobody carries out the security measures; one university had to re-run its tender for an outside security manager. With the suggested solution: The provider does the security work itself, at the same fixed price.
- Who does this is not known. Today: Who checks the measures after the deadline, and when, is not known. With the suggested solution: Unchanged: the provider prepares the organisation for that check but does not perform it.
Not known: who checks the measures after the deadline, and when.
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Suggested solution
About this section
- What this shows
- One way to solve the problem, and how the work would run with it.
- Why it matters to a builder
- It is a starting point to test with buyers, not a plan. The sections below are the evidence for and against it.
Build a small security agency that does the security work, and writes EU grant applications for the towns that qualify.
A covered town or care home buys help in pieces: one seller checks what it owes, another writes the grant application, a third sells paperwork.3 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
One provider does the check, the application and the security work, so the organisation buys once instead of three times.
- A consultant who checks what the law requires. Today: Checks whether the new cybersecurity law covers the organisation, and what it owes. With the suggested solution: One fixed-price provider makes the same check, before the organisation's deadline.
- The town or care home. Today: Registers with the national cyber-security agency, which starts its one-year deadline for security measures. With the suggested solution: Unchanged: registering is the organisation's own duty.
- A consultant who writes grant applications. Today: Writes the EU grant application for the organisations that can get one. With the suggested solution: The same provider writes the application, inside the fixed price.
- A seller of ready-made compliance documents. Today: Sells the required documents as a package, without doing the security work. With the suggested solution: The documents describe security work the provider has actually done.
- Nobody in-house, at most of these organisations. Today: Nobody carries out the security measures; one university had to re-run its tender for an outside security manager. With the suggested solution: The provider does the security work itself, at the same fixed price.
- Who does this is not known. Today: Who checks the measures after the deadline, and when, is not known. With the suggested solution: Unchanged: the provider prepares the organisation for that check but does not perform it.
Not known: who checks the measures after the deadline, and when.
Why now
3/3 · Deadline with penalties
Towns, care homes and firms under the new law run out of time in late 2026, and first steps already cost about 100,000 CZK.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.
- A firm's owner has one year from registering with the national cyber-security agency to put the required security in place, so the first deadlines fall in late 2026.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m. A firm that misses its deadline can be fined up to 2% of its turnover.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
- A town's director who wants the EU to pay half of the work first pays a consultant about 121,000 CZK just to write the grant application.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026. The grant stops taking applications on 17 December 2026, so a town that has not applied by then pays the full cost itself.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
- Hiring someone to do the work is hard. Mendel University in Brno had to run its tender for an outside security manager, the person the law requires to be in charge of security, a second time in August 2026, and in September it pushed the closing date for bids back to 22 October 2026.2 sourcesTEDted.europa.euMendel University cybersecurity manager — repeat procurement procedure (another site)Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. The notice was posted to the EU's TED procurement portal on 26 August 2026 under the govtech sector.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”TEDted.europa.euTED — Mendel University pushes its security-manager deadline back (another site)The university's repeated tender for the outsourced security manager the law requires was still open in September 2026, with its closing date moved from 29 September to 22 October.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení” A care home bought a ready-made package instead, at the price shown under Willing to pay.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Why now
About this section
- What this shows
- The dated rules and events that push buyers to act, soonest first.
- Why it matters to a builder
- A dated rule turns “nice to have” into “must buy by”, and tells you how long the window stays open.
- How to read the score
- 3/3 means an enacted rule binds these buyers within 18 months and names a penalty. Without a named penalty it is 2/3. A draft law, a rule on someone else, or a date further out is 1/3.
Towns, care homes and firms under the new law run out of time in late 2026, and first steps already cost about 100,000 CZK.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.
- A firm's owner has one year from registering with the national cyber-security agency to put the required security in place, so the first deadlines fall in late 2026.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m. A firm that misses its deadline can be fined up to 2% of its turnover.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
- A town's director who wants the EU to pay half of the work first pays a consultant about 121,000 CZK just to write the grant application.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026. The grant stops taking applications on 17 December 2026, so a town that has not applied by then pays the full cost itself.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
- Hiring someone to do the work is hard. Mendel University in Brno had to run its tender for an outside security manager, the person the law requires to be in charge of security, a second time in August 2026, and in September it pushed the closing date for bids back to 22 October 2026.2 sourcesTEDted.europa.euMendel University cybersecurity manager — repeat procurement procedure (another site)Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. The notice was posted to the EU's TED procurement portal on 26 August 2026 under the govtech sector.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”TEDted.europa.euTED — Mendel University pushes its security-manager deadline back (another site)The university's repeated tender for the outsourced security manager the law requires was still open in September 2026, with its closing date moved from 29 September to 22 October.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení” A care home bought a ready-made package instead, at the price shown under Willing to pay.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- Many small firms do not yet know the law covers them.SME Unionsme-union.czSME UNION — the deadlines are running (another site)The business association's alarm: 6,000+ firms affected across energy, manufacturing, food, logistics and digital services — and many SMEs still unaware they are in scope. An organisation that has not registered already faces proceedings and a fine.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
The dates behind these deadlines come from the law itself, and from a second law on critical infrastructure:2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.Rowan Legalrowan.legalAct No. 266/2025 Coll. (critical infrastructure) (another site)The CER transposition puts a parallel physical-resilience compliance stack on an overlapping entity set — designations from July 2026, resilience plans and incident reporting through 2027.
- On 1 November 2025 the new cybersecurity law took effect.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.
- By 17 July 2026 the state had to name the organisations covered by the second law, on critical infrastructure.Rowan Legalrowan.legalAct No. 266/2025 Coll. (critical infrastructure) (another site)The CER transposition puts a parallel physical-resilience compliance stack on an overlapping entity set — designations from July 2026, resilience plans and incident reporting through 2027.
- In late 2026 the first one-year deadlines for security measures run out.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.
- On 17 December 2026 the EU grant for towns, regions and hospitals stops taking applications.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
- By mid 2027 most of the remaining deadlines have run out.Zákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.
- The top fine is CZK 250m or 2% of global turnover, and the agency counts a long delay against an organisation when it sets the fine.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.NÚKIBnukib.gov.czNÚKIB — registration tally (another site)The regulator's own count: 4,825 of ~6,000 expected entities had reported a regulated service by 8 Feb 2026 — verifying the 6,000 figure, with over a thousand obligated organisations not yet even registered.
The second law is Act No. 266/2025, the Czech version of the EU's CER directive (its rules for critical entities).Rowan Legalrowan.legalAct No. 266/2025 Coll. (critical infrastructure) (another site)The CER transposition puts a parallel physical-resilience compliance stack on an overlapping entity set — designations from July 2026, resilience plans and incident reporting through 2027. It puts physical-resilience duties on many of the same organisations: resilience plans, meaning how they keep essential services running through physical threats, and incident reporting, through 2027.Rowan Legalrowan.legalAct No. 266/2025 Coll. (critical infrastructure) (another site)The CER transposition puts a parallel physical-resilience compliance stack on an overlapping entity set — designations from July 2026, resilience plans and incident reporting through 2027. Many customers for the first law will need this work too.Rowan Legalrowan.legalAct No. 266/2025 Coll. (critical infrastructure) (another site)The CER transposition puts a parallel physical-resilience compliance stack on an overlapping entity set — designations from July 2026, resilience plans and incident reporting through 2027.
Willing to pay
2/2 · Clear signs
The covered organisations pay, and towns, regions and hospitals can get half back from an EU grant.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
- About €33M in public cyber-security tenders and awards landed in June–August 2026 alone.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- About 121,000 CZK is what one town paid a consultant just to write its grant application.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.
- €500–6,000 a year is what compliance software costs one organisation.reglyze.comReglyze — NIS2 tooling price survey (another site)Named annual prices for NIS2 compliance software: Reglyze from €490/yr, Secfix ~€500 a month, Vanta and Drata ~$7,500 a year, OneTrust $30k+ — what a per-firm product can realistically charge.
Per seat, monthly
One purchase
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Willing to pay
About this section
- What this shows
- Who already spends money on this problem, how much, and how they buy.
- Why it matters to a builder
- If people already pay for this, even by hand or through a consultant, you are replacing a spend, not creating a budget.
- How to read the score
- 2/2 means a Czech buyer has paid for this, or a priced job also gets public money that pays part of it. A price on file makes it 1/2. Public money alone earns nothing. Only public buyers publish what they pay, so problems sold to private firms often score lower.
The covered organisations pay, and towns, regions and hospitals can get half back from an EU grant.2 sourcesZákony pro lidizakonyprolidi.czAct No. 264/2025 Coll. (new cybersecurity act) (another site)The Czech NIS2 transposition, effective 1 Nov 2025 — registration was due end-2025, security measures fall due within one year of registration, and fines reach 2% of global turnover or CZK 250m.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
- About €33M in public cyber-security tenders and awards landed in June–August 2026 alone.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- About 121,000 CZK is what one town paid a consultant just to write its grant application.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.
- €500–6,000 a year is what compliance software costs one organisation.reglyze.comReglyze — NIS2 tooling price survey (another site)Named annual prices for NIS2 compliance software: Reglyze from €490/yr, Secfix ~€500 a month, Vanta and Drata ~$7,500 a year, OneTrust $30k+ — what a per-firm product can realistically charge.
The €33M is spread over about 77 tenders and awards.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance. Buyers range from large hospitals to small towns:
- Motol and Homolka, two large Prague hospitals, bought threat detection and response for about €6.1M.TEDted.europa.euTED — Motol & Homolka award (~€6.1M) (another site)Prague's biggest hospitals bought cyber threat detection and response for ~€6.1M in June 2026 — the top of the public buying wave, with smaller hospital awards in the same window.
- The city of Prague bought security monitoring across the city for about €5.3M.TEDted.europa.euTED — Prague SIEM award (~€5.3M) (another site)The city of Prague bought a SIEM across the city hall, city police and districts — two security awards from one buyer in six weeks.
- Český Brod, a town of about 7,000, bought its whole cyber-security job; its price is in the table of what one buyer pays.Registr smluvsmlouvy.gov.czRegistr smluv — Český Brod (~9M CZK) (another site)A town of 7,000 signed ~9M CZK for municipal cyber security — one of 341 cyber contracts in the contract registry since June 2026.
- The smallest buyers choose ready-made packages. A care home in Napajedla bought one, and social-care services in the Zlín region ordered the same package within weeks; its price is in the same table.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- 341 cyber-security contracts have entered the state contracts register since June 2026.Registr smluvsmlouvy.gov.czRegistr smluv — Český Brod (~9M CZK) (another site)A town of 7,000 signed ~9M CZK for municipal cyber security — one of 341 cyber contracts in the contract registry since June 2026.
- The town of Týn nad Vltavou paid just to find out whether the law applied to it.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- Prague 5, a city district, is tendering two years of outside running of its security tools, including handling attacks, estimated at 11.8M CZK.TEDted.europa.euTED — Prague 5 outsources the running of its security tools (another site)A Prague city district tenders two years of outside administration, monitoring and evaluation of its cyber-security tools, including handling security incidents, at an estimated 11.8M CZK.In the source’s words“Czechia – System and support services – Správa, nastavení a dohled nad vybranými nástroji kybernetické bezpečnosti — 11827200 CZK”
- Jihlava's psychiatric hospital, one of the grant applicants, signed about 22.9M CZK in September 2026 for security hardware and software, part-paid by the EU's regional-development programme.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.Registr smluvsmlouvy.gov.czRegistr smluv — Jihlava psychiatric hospital, grant-funded purchase (~22.9M CZK) (another site)A psychiatric hospital signed about 22.9M CZK for security hardware and software with installation and five years of support, part-paid by the EU's regional-development programme.In the source’s words“Kupní smlouva - Zvýšení kyberbezpečnosti PNJ — 27748306.85”
The EU grant is IROP call 120 (the cyber-security call of the EU's regional-development programme). It holds about €99.6M and pays 50% of the cost.IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
A rough estimate from the software price range: if a quarter of the 6,000 paid €3,000 a year, software alone would bring about €4.5M a year.reglyze.comReglyze — NIS2 tooling price survey (another site)Named annual prices for NIS2 compliance software: Reglyze from €490/yr, Secfix ~€500 a month, Vanta and Drata ~$7,500 a year, OneTrust $30k+ — what a per-firm product can realistically charge. That is before the security work itself, which is what the public contracts buy.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
Across Europe, cybersecurity spending is about $70 billion in 2026, growing about 11% a year.Mordor Intelligencemordorintelligence.comMordor Intelligence — Europe cybersecurity (another site)Sizes European cybersecurity spend at ~$69.8 billion in 2026, growing ~10.6% a year to ~$115.7 billion by 2031 — with NIS2 and DORA named as the anchor drivers.
Money for building security tools, rather than buying them, also existed. The ECCC (the EU's cybersecurity competence centre) offered €56.2M from the HORIZON research programme to groups of firms and research bodies, Czech ones included. That call closed on 15 September 2026.ECCCcybersecurity-centre.europa.euHORIZON — ECCC cybersecurity calls (€56.2M) (another site)EU money for building security tooling itself — consortia, Czech firms eligible, deadline 15 Sep 2026. Funds the vendors, not the obligated buyers.
Per seat, monthly
One purchase
What one buyer pays
- 3 000 CZK a month
- An obligated Czech company nis2pruvodce.czNIS2 Průvodce — the Czech subscription (another site)An obligated Czech company pays 3,000 CZK a month for the Czech compliance platform, one subscription per company number, after a seven-day free trial.
- 91 000 CZK once
- Domov pro seniory Napajedla, in the smallest obligated tier Registr smluvsmlouvy.gov.czLexnova — the packaged order (another site)A care home paid about 91,000 CZK for a packaged cyber-security compliance order, and a second order of the same package followed within weeks.
- 121 000 CZK once
- Město Boskovice, a town applying for the EU cyber-security grant Registr smluvsmlouvy.gov.czBoskovice — a consultant paid to write the grant application (another site)A town paid a consultant about 121,000 CZK to write its EU cyber-security grant application, one piece of the job a single provider would take on.
- 9 000 000 CZK once
- Město Český Brod, a town of about 7,000 people Registr smluvsmlouvy.gov.czČeský Brod — a town of 7,000 buys the whole job (another site)A town of about 7,000 people signed roughly 9M CZK for municipal cyber security, the top end of what the smallest obligated buyers pay.
10 public contracts and tenders, plus 3 grant calls
Jun2026
Jul
Aug
Sep
Grants open
Hospitals, towns, state agencies and other public bodies that signed or tendered between Jun and Sep 2026. The grant calls can pay for this work.
- €12M
- The National Agency for Communication and Information Technologies is establishing a framework agreement for support services on the Arcsight security platform, valued at EUR 11,600,000. TEDted.europa.euCzech IT agency Arcsight support — CZ framework deal for security platform services (another site)The National Agency for Communication and Information Technologies is establishing a framework agreement for support services on the Arcsight security platform, valued at EUR 11,600,000. The contract is scored as a recurring service.In the source’s words“Czechia – Computer support services – Rámcová dohoda o poskytnutí služeb pro technologii Arcsight”
- €6.1M
- Prague's biggest hospitals bought cyber threat detection and response for about €6.1M in June 2026. TEDted.europa.euTED — Motol & Homolka award (~€6.1M) (another site)Prague's biggest hospitals bought cyber threat detection and response for ~€6.1M in June 2026 — the top of the public buying wave, with smaller hospital awards in the same window.
- €5.3M
- The city of Prague bought a SIEM across the city hall, city police and districts. TEDted.europa.euTED — Prague SIEM award (~€5.3M) (another site)The city of Prague bought a SIEM across the city hall, city police and districts — two security awards from one buyer in six weeks.
- €3.4M
- Nemocnice Milosrdných bratří is tendering a security software package as part of a cybersecurity technology upgrade. TEDted.europa.euMilosrdní bratři hospital cyber upgrade — CZ tender for security software (another site)Nemocnice Milosrdných bratří is tendering a security software package as part of a cybersecurity technology upgrade. The contract is worth EUR 3,356,679.In the source’s words“Czechia – Security software package – Zvýšení kyberbezpečnosti v NMB - technologie — 83916980 CZK”
- €1.8M
- ČEZ Distribuce is procuring a security-monitoring tool for its technological network, valued at about €1.82 million. TEDted.europa.euČEZ grid security monitoring — CZ tool procurement for technology-network safety (another site)ČEZ Distribuce is procuring a security-monitoring tool for its technological network, valued at about €1.82 million. It is cybersecurity-related infrastructure procurement in the energy sector.In the source’s words“Czechia – Network equipment – NÁSTROJ PRO BEZPEČNOSTNÍ MONITORING TECHNOLOGICKÉ SÍTĚ”
- €930k
- Czech Television is tendering network equipment for security monitoring and cyber-threat detection and response on its technology network, with the contract valued at about EUR 930,050. TEDted.europa.euCzech Television cybersecurity — network security monitoring and threat detection gear (another site)Czech Television is tendering network equipment for security monitoring and cyber-threat detection and response on its technology network, with the contract valued at about EUR 930,050. The listing carries a near-term deadline for this 2026 cybersecurity procurement.In the source’s words“Czechia – Network components – Dodávka zařízení pro bezpečnostní monitoring technologické sítě ČT, detekci a reakci kybernetických hrozeb 2026 — 930050 EUR”
- €367k
- A town of 7,000 signed about 9M CZK for municipal cyber security. Registr smluvsmlouvy.gov.czRegistr smluv — Český Brod (~9M CZK) (another site)A town of 7,000 signed ~9M CZK for municipal cyber security — one of 341 cyber contracts in the contract registry since June 2026.
- €216k
- The National Institute of Public Health tendered an endpoint-security system at EPP/EDR/XDR level, valued at approximately EUR 216,121. TEDted.europa.euNational Institute of Public Health endpoint security — EPP/EDR/XDR tender (another site)The National Institute of Public Health tendered an endpoint-security system at EPP/EDR/XDR level, valued at approximately EUR 216,121. The recurrence indicates an ongoing cybersecurity procurement.In the source’s words“Czechia – Security software package – Dodávka systému pro zabezpečení koncových zařízení na úrovni EPP/EDR/XDR — 5403031 CZK”
- €4k
- A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later. Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. TEDted.europa.euMendel University cybersecurity manager — repeat procurement procedure (another site)Mendel University in Brno is procuring cybersecurity manager services under a repeated tender procedure. The notice was posted to the EU's TED procurement portal on 26 August 2026 under the govtech sector.In the source’s words“Czechia – Safety consultancy services – Zajištění služeb manažera kybernetické bezpečnosti (MKB) – opakované řízení”
- €100M
- 2.44bn CZK (about €99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. IROPirop.gov.czIROP call 120 — Kybernetická bezpečnost II (another site)2.44bn CZK (~€99.6M) at a 50% support rate for municipalities, regions and hospitals regulated under Act 264/2025. Applications 30 Apr – 17 Dec 2026.
- €56M
- EU money for building security tooling itself. ECCCcybersecurity-centre.europa.euHORIZON — ECCC cybersecurity calls (€56.2M) (another site)EU money for building security tooling itself — consortia, Czech firms eligible, deadline 15 Sep 2026. Funds the vendors, not the obligated buyers.
- €5k
- Towns pay consultants just to write their IROP cyber-security subsidy applications. Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.
Validated abroad
3/3 · Proven in 2+ markets
Two funded European companies sell software that automates security compliance.2 sourcesVestbeevestbee.comSecfix (another site)Berlin, €10.2M Series A (Feb 2026) for AI-driven security-compliance automation for SMEs — the closest funded template for a productised NIS2 offer.Vestbeevestbee.comCopla (another site)Vilnius, €6M Series A (Feb 2026) for real-time compliance monitoring — a second funded compliance-automation player next door, covering NIS2, DORA and ISO 27001.
- Secfix (another site)Based in Germany
- Copla (another site)Based in Lithuania
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Validated abroad
About this section
- What this shows
- Companies abroad that already sell a solution, and how far along they are.
- Why it matters to a builder
- Established companies selling it in other markets show that buyers will pay, so you are not betting on an untested idea.
- How to read the score
- 3/3 means established in two or more markets, one of them near Czechia. 2/3 is one established company, 1/3 only early players.
Two funded European companies sell software that automates security compliance.2 sourcesVestbeevestbee.comSecfix (another site)Berlin, €10.2M Series A (Feb 2026) for AI-driven security-compliance automation for SMEs — the closest funded template for a productised NIS2 offer.Vestbeevestbee.comCopla (another site)Vilnius, €6M Series A (Feb 2026) for real-time compliance monitoring — a second funded compliance-automation player next door, covering NIS2, DORA and ISO 27001.
- Vestbeevestbee.comSecfix (another site)Berlin, €10.2M Series A (Feb 2026) for AI-driven security-compliance automation for SMEs — the closest funded template for a productised NIS2 offer.
Raised €10.2M in a Series A round, Feb 2026 (Vestbee); hundreds of small-business customers in 15+ European countries (Tech Funding News, 2026)
- Vestbeevestbee.comCopla (another site)Vilnius, €6M Series A (Feb 2026) for real-time compliance monitoring — a second funded compliance-automation player next door, covering NIS2, DORA and ISO 27001.
Raised €6M in a Series A round, Feb 2026, after a €2.5M seed round, Nov 2024 (Vestbee); software that automates compliance with EU security rules (NIS2, DORA) and the ISO 27001 standard, formerly called CyberUpgrade (EU-Startups, 2026)
Market gap
1/2 · Early rivals only
Four Czech sellers offer the paperwork the law requires, and none sells the security work itself.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
New, selling this: Lexnova Energy (since 2025), NIS2 Doku (since 2025), NIS2 Průvodce (since 2025), Compligen (since 2026). Established, selling this: nobody on file. New, selling something nearby: nobody on file. Established, selling something nearby: ICZ Risk*Guide (since 1997). No established player sells this here.
- EarlySells this · since 2025Lexnova Energy (another site)A ready-made "NIS 2 package" for public buyers, with repeat orders in the state contracts register.Sources and the full note are in Read more.
- EarlySells this · since 2025NIS2 Doku (another site)A pack of ready-made compliance documents.Sources and the full note are in Read more.
- EarlySells this · since 2025NIS2 Průvodce (another site)A Czech compliance platform, sold by monthly subscription per company.Sources and the full note are in Read more.
- EarlySells this · since 2026Compligen (another site)An online tool that generates the documents the law requires.Sources and the full note are in Read more.
The space is still open
- EstablishedSells something nearby · since 1997ICZ Risk*Guide (another site)A security and risk-management platform, bought as a large project.Sources and the full note are in Read more.
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Market gap
About this section
- What this shows
- Czech companies that already sell this, and firms nearby that sell something else.
- Why it matters to a builder
- A mature Czech seller means taking customers from an incumbent. Firms nearby still matter: the buyer may already pay them.
- How to read the score
- More points mean a more open field. 2/2 means no Czech company sells this, 1/2 only early ones do, 0/2 a mature one does.
Four Czech sellers offer the paperwork the law requires, and none sells the security work itself.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
New, selling this: Lexnova Energy (since 2025), NIS2 Doku (since 2025), NIS2 Průvodce (since 2025), Compligen (since 2026). Established, selling this: nobody on file. New, selling something nearby: nobody on file. Established, selling something nearby: ICZ Risk*Guide (since 1997). No established player sells this here.
- EarlySells this · since 2025Lexnova Energy (another site)A ready-made "NIS 2 package" for public buyers, with repeat orders in the state contracts register.Sources and the full note are in Read more.
- EarlySells this · since 2025NIS2 Doku (another site)A pack of ready-made compliance documents.Sources and the full note are in Read more.
- EarlySells this · since 2025NIS2 Průvodce (another site)A Czech compliance platform, sold by monthly subscription per company.Sources and the full note are in Read more.
- EarlySells this · since 2026Compligen (another site)An online tool that generates the documents the law requires.Sources and the full note are in Read more.
The space is still open
- EstablishedSells something nearby · since 1997ICZ Risk*Guide (another site)A security and risk-management platform, bought as a large project.Sources and the full note are in Read more.
Sells this 4
- Early: NIS2 Průvodce (another site)2 sourcesMarket checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.nis2pruvodce.czNIS2 Průvodce — the Czech subscription (another site)An obligated Czech company pays 3,000 CZK a month for the Czech compliance platform, one subscription per company number, after a seven-day free trial.
A Czech compliance platform, sold by monthly subscription per company. Twelve modules cover both decrees that set out the security measures (vyhláška 409/2025 and 410/2025): an asset register, a 52-item risk catalogue, a supplier register linked to the state business register, incident reports to the national cyber-security agency within its 24- and 72-hour deadlines, training, and an AI assistant that answers questions about the law. One person, Ondřej Šitler, runs it. He is not VAT-registered, the law it sells against only took effect in November 2025, and no buyer is named.
- Early: Compligen (another site)Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
An online tool that generates the documents the law requires. It produces 20+ documents for organisations under the lighter set of rules (vyhláška 410/2025), for 29,900 CZK one-off before VAT, and has a page aimed at towns. It claims more than 30 firms and towns as clients. But founder Lukáš Vencálek publishes no company number, no company of that trade name is in the state business register, and the product still shows a Q3 2026 roadmap.
Found by the register’s market check
- Early: NIS2 Doku (another site)Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
A pack of ready-made compliance documents. It holds 10+ documents for the lighter set of rules (vyhláška 410/2025), plus Excel tools for assets, incidents and suppliers, at 4,900 CZK (Start) or 11,900 CZK (Pro), one-off before VAT. It is sold by David Mikulec, and no buyer is named.
Found by the register’s market check
- 2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Registr smluvsmlouvy.gov.czLexnova — the packaged order (another site)A care home paid about 91,000 CZK for a packaged cyber-security compliance order, and a second order of the same package followed within weeks.
A ready-made "NIS 2 package" for public buyers, with repeat orders in the state contracts register. Lexnova Energy s.r.o. was founded in January 2025, and its sister company Lexnova Services s.r.o. in July 2026.
Sells something nearby 1
- Established: ICZ Risk*Guide (another site)Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies.
A security and risk-management platform, bought as a large project. It is deployed at the state digital agency, the police presidium and the Plzeň city IT authority. Ministries, regions, towns and large organisations buy it with one to three months of setup and a 24/7 advisory service, not as the fixed-price product a small organisation buys off a web page. ICZ a.s. has traded since July 1997, and the product is now sold by the group company ICZ.Services a.s. (IČO 22183809, founded October 2024).
Found by the register’s market check
None of the four puts the security measures in place, and that work is what the public contracts under Who pays buy.2 sourcesRegistr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies. They sell the documents as ready-made packs or online tools.Market checknis2pruvodce.czCzech NIS2 vendor scan (another site)Czech products now sell the obligation directly to the mid-market — NIS2 Průvodce at 3,000 CZK a month, Compligen at 29,900 CZK once, NIS2 Doku from 4,900 CZK — so the field is no longer only consultancies. Other firms sell single pieces of the job:
- Institut kybernetické bezpečnosti sells scope analysis: whether the law applies, and what is owed.Registr smluvsmlouvy.gov.czRegistr smluv — Lexnova 'NIS 2 package' (~91k CZK) (another site)A care home bought a productised NIS2 package off the shelf, with a repeat order weeks later — the smallest obligated tier pays ~91k CZK a time for packaged compliance.
- enovation writes the EU grant applications that towns pay for.Registr smluvsmlouvy.gov.czRegistr smluv — Boskovice grant application (~121k CZK) (another site)Towns pay consultants just to write their IROP cyber-security subsidy applications — a queue forms before the compliance work even starts.
Execution difficulty
1/3 · Hard
Makes it easier
- The law's deadlines push towns and firms to buy now.
- An EU grant pays half for towns.
- No licence is needed to do the work.
Makes it harder
- The buyers are public bodies.
- They want references a new provider does not have yet.
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Execution difficulty
About this section
- What this shows
- What stands between you and the first sale: who buys, what permission selling needs, what it must plug into, and whether it needs outside money.
- Why it matters to a builder
- It tells you whether a small team can start selling soon, or needs a licence, a certification or funding first.
- How to read the score
- More points mean easier to enter: 3/3 is easy, 0/3 very hard. It is not added to the Opportunity total, and local competition does not count here: that is Market gap.
Hard
Makes it easier
- The law's deadlines push towns and firms to buy now.
- An EU grant pays half for towns.
- No licence is needed to do the work.
Makes it harder
- The buyers are public bodies, so each sale goes through their slow purchasing rules and tenders.
- They want references a new provider does not have yet.
Local competition does not change this level. It is covered under Market gap.
Suggested first moves
- Build a simple, fixed-price check that tells a small town exactly what the new cybersecurity law requires of it and by when.
- Call the directors of care homes and small towns that are already paying for help with this law, and offer them the check.
- For each town that can get the EU grant, write its grant application, so the EU pays half of the security work that follows.
P-0008 · 6,000 Czech towns and firms have months left to meet a new cybersecurity law
Suggested first moves
About this section
- What this shows
- A few concrete steps to start with.
- Why it matters to a builder
- They are cheap ways to learn whether buyers will pay, before you build much.
- Build a simple, fixed-price check that tells a small town exactly what the new cybersecurity law requires of it and by when. The check answers three questions. First, does the new law cover the town at all? Second, has the town registered, meaning told the national cyber-security agency that it runs a covered service, which is the step that starts its one-year clock? Third, which security measures is it still missing? The measures are the concrete steps the law's decrees set out, such as a list of the town's computers and data, a risk assessment, supplier checks, staff training and reporting an attack quickly; they are listed under The opportunity. The town gets a short report: what is done, what is missing, and the date each missing piece is due, before its deadline. Give it one price agreed up front, because the smallest buyers already choose ready-made packages, as Willing to pay shows.
- Call the directors of care homes and small towns that are already paying for help with this law, and offer them the check. They are easy to find, because public bodies must publish their contracts in the state contracts register. Start with the care homes, social-care services and small towns listed under Willing to pay, which bought ready-made packages or paid just to learn whether the law applies to them. These people have already shown they will spend money on this, and their deadline is close, as Why now explains. Ask each one what they have done so far and what worries them, and use the answers to improve the check.
- For each town that can get the EU grant, write its grant application, so the EU pays half of the security work that follows. The grant is EU money for towns, regions and hospitals covered by the law, described under Willing to pay. Towns already pay consultants a fee just to write this application, as Why now shows. If you write it as part of your price, the town saves that fee and deals with one provider instead of two. Start early, because the grant stops taking applications on a fixed date, also under Why now.
- Do the security work the check found missing, rather than only writing the documents that describe it. The work means putting the measures in place for real: making the list of computers and data, setting up supplier checks, training the staff, and being ready to report an attack in time. Several Czech sellers already sell the documents, as ready-made packs or online tools, but none of them does the work itself; see Market gap. The public contracts pay for the work, and even a small town has signed a large contract for it; see Willing to pay. Hiring their own person is hard, too, since one university had to run its tender for an outside security manager again, as Why now tells. So one provider that does the check, the application and the work, at a fixed price, saves the buyer from buying three times.
- Once a town or care home trusts you, help it meet a second new law on critical infrastructure, which binds many of the same organisations. That law is the Czech version of the EU's rules for critical entities. It asks the organisations the state names to write resilience plans, meaning how they keep their essential services running through physical threats, and to report serious incidents. Its dates are under Why now. You already know these customers and their systems, so this is the natural next job to offer them.