Act on Critical Infrastructure
We'll help you work out whether the Act applies to you and get your organisation ready for the new obligations. We review your services, risks and critical dependencies. If you already know you're in scope, we'll prepare your risk assessment, your resilience plan and the processes that go with them. And we tie it all in with the Czech Cybersecurity Act or ISO 27001, so you never do the same work twice.
What the Act changes and who it affects
The Act on the Resilience of Critical Infrastructure Entities transposes the EU CER Directive (2022/2557) and takes a new approach to protecting critical infrastructure in the Czech Republic. Its focus is no longer on protecting buildings, facilities or networks, but on the organisations that provide services vital to the functioning of the state, the economy, security, public health or the environment. The Act has been in effect since 19 August 2025.
It may apply to organisations in sectors such as energy, transport, healthcare, banking, water supply, digital infrastructure, public administration or food. But operating in one of these sectors is not enough on its own. What matters is the specific service you provide, how significant it is and what impact an outage would have.
If the state designates you as a critical infrastructure entity, your main obligations will be to:
- assess the risks that threaten the provision of your essential service,
- draw up a resilience plan,
- appoint a critical infrastructure manager,
- put a process in place for reporting significant incidents.
The risk assessment must be completed 9 months of receiving the designation decision. You have 10 months for the resilience plan and for appointing a critical infrastructure manager. From that same point it also starts an obligation to report incidents.
How can we help
The Critical Infrastructure Act calls for more than a new set of documents. You need to know your essential services, critical dependencies, suppliers and the risks that could disrupt your operations. We turn the Act's requirements into concrete steps, build on the processes you already have and align them with the Czech Cybersecurity Act, business continuity management or ISO 27001.
Scope check
We go through your services, organisational structure and the available criteria. Then we help you assess whether you may qualify as an essential service provider and what you would need to demonstrate.
Risk assessment
We identify the threats, vulnerabilities and dependencies that could disrupt the provision of your essential service, taking operational, personnel, supply chain and cyber risks into account.
Documentation and resilience plan
We prepare a plan that sets out measures for preventing incidents, handling outages and restoring the service. We connect it with your business continuity, crisis management and existing processes.
A critical infrastructure manager
We help you define the role, fill it, or cover it long term through outsourcing. We set out clear responsibilities, the involvement of internal teams and how reporting to management works.
Critical suppliers and personnel
We help you determine which staff and suppliers are indispensable to providing your essential service. We then put the right records, risk management and contract terms in place for them.
Incident reporting process
We set up a process for identifying, escalating and reporting incidents. We align it with the procedures under the Cybersecurity Act, so your people know where and when to report an event.
TRUSTED BY ORGANISATIONS IN MANUFACTURING, IT, ENERGY AND BEYOND












How we work with you
First, we need to understand what services you provide, who depends on them and what a disruption would mean. From there, we propose the way forward, break the work down into concrete steps and guide you through preparing the necessary documentation and putting the changes into practice.
Your preparation for the Critical Infrastructure Act shouldn't sit in a silo next to everything you already have in place. We start by reviewing your current risk management, business continuity, crisis procedures and documentation. Then we link them to the new obligations and add only what the Act actually requires.
If you also fall under the Cybersecurity Act, we bring both regimes together into a single working system. No duplicate documentation, no unnecessary parallel processes.
- We get to know your operations first, and only then prepare the documentation.
- We build on what you already have. We don't start from scratch where what you already use can reasonably be put to work.
- We distinguish between what the Act requires, what makes sense to add and what would be wasted effort.
- We join up related obligations. We don't produce several documents covering the same risks and processes.
- We involve the people who will actually use the processes.
Frequently asked questions
How do we know whether the Act applies to us?
It depends on whether you provide one of the essential services in the sectors listed in the Act. Other factors are then assessed: the significance of the service, the number of users who depend on it, the impact of a potential outage, its geographical reach and the availability of alternatives. Simply operating in energy, transport, healthcare or another listed sector does not automatically make you a critical infrastructure entity. What counts is the specific service and whether it meets the significance criterion.
What is an essential service?
An essential service is a service that is important for maintaining the basic functions of the state, the economy, security, public health or the environment nebo životního prostředí. In practice, it is a service whose outage would affect not only your organisation, but also customers, the public, other businesses or other services that depend on it. Examples include electricity supply, hospital care, drinking water supply, rail transport operations, payment services, digital infrastructure or food distribution.
Who decides whether an organisation is designated as a critical infrastructure entity?
Inclusion on the non-public list of critical infrastructure entities is decided by the Czech Ministry of the Interior. The proposal comes from the relevant ministry, another central administrative authority or the Czech National Bank, depending on the sector. Before a decision is made, you may be asked to provide information about the service, its infrastructure and its significance.
When does each obligation start to apply?
The Act has been in effect since 19 August 2025. For the main obligations, though, the clock only starts once you receive the decision adding you to the list of critical infrastructure entities. From then, you have: 9 months to complete the risk assessment, and 10 months to prepare the resilience plan and appoint a critical infrastructure manager.
How does the Act relate to the Cybersecurity Act?
The two Acts can overlap in risk management, incidents, suppliers, responsibilities and business continuity. But the Critical Infrastructure Act does not focus on cyber risks alone. It addresses your organisation's overall ability to keep its essential service running. If both apply to you, we recommend implementing them together. You can reuse the same groundwork, roles and processes, and avoid doing the work twice.
Who can be a critical infrastructure manager?
A critical infrastructure manager is the person a critical infrastructure entity designates as its main contact and coordinator for everything the Act involves. They communicate with the competent authorities, monitor compliance with the obligations and link up management, security, operations and crisis management. The Act requires them to have professional competence and experience in security, crisis management or business continuity.
Need to check whether the Act applies to you, or get ready for the new obligations?
We'll go through your situation, the preparation you've done so far and the processes you already have in place. We'll propose next steps and help you with the risk assessment, the resilience plan and putting the obligations into practice.