Implementing Decree to the Critical Infrastructure Act

August 2026

LU 3

Following the adoption of Act No. 266/2025 Coll., on the Resilience of Critical Infrastructure Entities (hereinafter the “Critical Infrastructure Act“), an implementing decree regulating the details for ensuring the resilience of these entities comes into effect on 1 August 2026. Without the issuance of this implementing decree, it would be impossible to apply certain institutes of this Act that require a more detailed definition.

The decree regulates the requirements of the resilience plan, which replaces the existing crisis preparedness plans under the Critical Infrastructure Act. This document is to consist of an informational, an operational, and an auxiliary part. In the informational part, critical infrastructure entities will describe the procedures for identifying their critical infrastructure and functional links, provide a list of critical workers and suppliers, and register the resources necessary to ensure services. The operational part is to contain an overview of unacceptable risks, the method of their management, and communication plans in the event of incident resolution. The auxiliary part will summarize the principles of handling the document and provide an overview of the applied technical standards and legal regulations. The elaboration of the resilience plan is preceded by a risk assessment, which can be subsidiarily based on the ČSN ISO 31000 standard.

Furthermore, the decree specifies the content of measures that entities must adopt to ensure their resilience under Section 15 of the Critical Infrastructure Act. This primarily includes measures to ensure business continuity, which require maintaining or restoring the provision of an essential service. Attention is paid to physical security, which encompasses the definition of security perimeters and the implementation of adequate technical or procedural measures for the protection of facilities, such as alarm systems, video surveillance or access control systems. The management of personnel security is also regulated, including procedures for verifying the reliability of designated persons and developing their security awareness. Likewise, a set of actions is introduced for the management of supply chain security, within the framework of which entities are obliged to register critical suppliers and implement measures mitigating the risks associated with them.

The decree also sets parameters for situations where the provision of an essential service is disrupted. An adverse event is qualified as an incident the moment it reaches a threshold of 35% of the impact significance level. To calculate this value, a formula is used that takes into account criteria with an assigned weight, which are the estimated number of affected persons, the size of the affected territory, duration, cross-border influence, or economic impacts. Entities will be obliged to report these incidents to the Ministry of the Interior via the critical infrastructure portal. The reporting process is designed in phases, as such the entity is first obliged to submit an initial report with a description of the available information within 24 hours of recording the incident. For prolonged incidents exceeding a duration of 1 month, an obligation is introduced to periodically submit progress reports, which update information on the development of the resolution and newly discovered facts. The process is subsequently concluded by the submission of a final report with an overall evaluation, which must be sent no later than one month after the definitive resolution of the situation.

Legal Update 08/2026 download here.

The information contained in this bulletin is presented to the best of our knowledge and belief at the time of going to press. However, specific information related to the topics covered in this bulletin should be consulted before any decision is made. The information contained in this bulle-tin should not be construed as an exhaustive description of the relevant issues and any possible consequences, and should not be fully relied on in any decision-making processes or treated as a substitute for specific legal ad-vice, which would be relevant to particular circumstances. Neither Weinhold Legal, s.r.o. advokátní kancelář nor any individual lawyer listed as an author of the information accepts any responsibility for any detriment which may arise from reliance on information published here. Fur-thermore, it should be noted that there may be various legal opinions on some of the issues raised in this bulletin due to the ambiguity of the relevant provisions and an interpre-tation other than the one we give us may prevail in the future.

Automatic text and data mining, as well as reproduction or extraction of their content for the purposes of automated analysis from this information material, is prohibited pursuant to Article 4 of Directive (EU) 2019/790 and Section 39c of Act No. 121/2000 Coll., the Copyright Act, without the prior express written consent of Weinhold Legal, s.r.o., law firm, unless, in any such use, the authorship of Weinhold Legal, s.r.o., law firm is expressly acknowledged together with a reference to the location of such text and data.

© 2025 Weinhold Legal

All rights reserved.

Get in touch
with us

Office Prague 

View on Map

Office Brno

View on Map

Get in touch with us

Get the news from the world of law

How we handle personal data is described here.

Omlouváme se, ale pro tuhle stránku neexistuje překlad