
Following the adoption of Act No. 266/2025 Coll., on the Resilience of Critical Infrastructure Entities (hereinafter the “Critical Infrastructure Act“), an implementing decree regulating the details for ensuring the resilience of these entities comes into effect on 1 August 2026. Without the issuance of this implementing decree, it would be impossible to apply certain institutes of this Act that require a more detailed definition.
The decree regulates the requirements of the resilience plan, which replaces the existing crisis preparedness plans under the Critical Infrastructure Act. This document is to consist of an informational, an operational, and an auxiliary part. In the informational part, critical infrastructure entities will describe the procedures for identifying their critical infrastructure and functional links, provide a list of critical workers and suppliers, and register the resources necessary to ensure services. The operational part is to contain an overview of unacceptable risks, the method of their management, and communication plans in the event of incident resolution. The auxiliary part will summarize the principles of handling the document and provide an overview of the applied technical standards and legal regulations. The elaboration of the resilience plan is preceded by a risk assessment, which can be subsidiarily based on the ČSN ISO 31000 standard.
Furthermore, the decree specifies the content of measures that entities must adopt to ensure their resilience under Section 15 of the Critical Infrastructure Act. This primarily includes measures to ensure business continuity, which require maintaining or restoring the provision of an essential service. Attention is paid to physical security, which encompasses the definition of security perimeters and the implementation of adequate technical or procedural measures for the protection of facilities, such as alarm systems, video surveillance or access control systems. The management of personnel security is also regulated, including procedures for verifying the reliability of designated persons and developing their security awareness. Likewise, a set of actions is introduced for the management of supply chain security, within the framework of which entities are obliged to register critical suppliers and implement measures mitigating the risks associated with them.
The decree also sets parameters for situations where the provision of an essential service is disrupted. An adverse event is qualified as an incident the moment it reaches a threshold of 35% of the impact significance level. To calculate this value, a formula is used that takes into account criteria with an assigned weight, which are the estimated number of affected persons, the size of the affected territory, duration, cross-border influence, or economic impacts. Entities will be obliged to report these incidents to the Ministry of the Interior via the critical infrastructure portal. The reporting process is designed in phases, as such the entity is first obliged to submit an initial report with a description of the available information within 24 hours of recording the incident. For prolonged incidents exceeding a duration of 1 month, an obligation is introduced to periodically submit progress reports, which update information on the development of the resolution and newly discovered facts. The process is subsequently concluded by the submission of a final report with an overall evaluation, which must be sent no later than one month after the definitive resolution of the situation.
Legal Update 08/2026 download here.