Act No. 264/2025 Coll. on cybersecurity

Cybersecurity audit. And software that survives it.

The new Czech cybersecurity act covers an order of magnitude more organisations than the one before it. I go through your documentation, your controls and how they actually run, and you get a report with findings ranked by severity – not a list of products to buy. I build and run software too, just not for a client I audit.

Prague · CZ Reply within 48 h Decree No. 409/2025 Coll.

What I do

Cybersecurity audit

Security

I verify whether security measures actually work – not whether they are written down. Documentation, policies, technical controls, interviews with the people responsible. You get a report with findings ranked by severity.

  • Information security management system audit
  • Verification of technical and organisational measures
  • Readiness review ahead of a mandatory audit
  • Report with findings ranked by severity
Service detail

Custom software development

Engineering

Architecture, implementation, tests and technical consulting. I build systems that can be operated, handed over and extended safely long after our work together ends.

  • System architecture and technical design
  • Implementation and integration
  • Test strategy and automated tests
  • Review of existing tests and code review
Service detail

Deployment and operations

Operations

Infrastructure, deployment and day-to-day operations. The goal is an environment you can run without a full-time specialist and whose cost you can predict.

  • Infrastructure design and build
  • Automated deployment and CI/CD
  • Monitoring and operational oversight
  • Taking over and cleaning up an inherited setup

The independence line

For any one client I do either the audit or the development – never both.

The law requires the auditor to be separate from the people who design and operate security. If I built your solution first and then audited it myself, the audit would be worthless. When an audit turns up something to fix, I describe it and point you to someone who can fix it.

How it works

  1. 01

    Initial call or meeting

    Get in touch with what you need. We take it from there over a call or in person, whichever suits you, and pin down the brief. No commitment.

  2. 02

    Scope and deadline

    I confirm in writing what exactly I will do and by when. You know up front what you are getting.

  3. 03

    The work

    For an audit: reviewing documentation, verifying controls in live operation and interviewing the people responsible. For development: work against agreed milestones you can plan around.

  4. 04

    Handover

    For an audit you get a report with findings ranked by severity. For development the finished solution, documentation and credentials – all on your accounts, not mine.

FAQ

Does the audit even apply to us?

It is mandatory for entities in the higher-obligations regime. The list of regulated services and the regime each falls under is set out in Decree No. 408/2025 Coll. on regulated services. For everyone else it is optional, but it can still pay off – it surfaces weak spots before somebody else finds them. Outside the mandatory regime I follow your brief and audit the scope you set. Whether you fall under the mandatory regime is something we clear up on the first call.

What does it cost?

It depends on the size of the organisation and the scope being reviewed or built. A fixed price list for this kind of work means either an inflated price or a rushed job. The price is therefore always individual and follows the scope we agree on.

Who performs the audit and what are their qualifications?

A mandatory audit under the act is led by a qualified cybersecurity auditor, and I will provide proof of qualification on request.

Can you just fix the findings for us?

No, and that is deliberate. The auditor has to stay separate from the people who design and operate security. I describe the findings in plain terms and recommend who can remove them.

Can you take over software from a previous supplier?

Yes, that is a routine part of the job. I start by going through the code, dependencies, environments and credentials, then tell you what is worth keeping and what is worth rebuilding.

Contact

Send me a message

A few sentences about what you are dealing with is enough – audit, development, or just a question. I reply within 48 hours.

Or simply by email: tomas@tdoubek.com

How I handle personal data is described in the privacy policy.