Act No. 264/2025 Coll. on cybersecurity

Cybersecurity audit

An audit is an independent check of whether security measures actually work – not whether policies exist claiming they should. Here is what the audit covers, how it runs and what exactly you get.

Who the audit is for

The audit is mandatory for providers of a regulated service under the higher-obligation regime. Which services count as regulated, and under which regime, is set by Decree No. 408/2025 Coll. on regulated services. The measures assessed under the higher regime are set by Decree No. 409/2025 Coll. Nobody imposes an audit on anyone else, but it can still pay off – it surfaces weak spots before someone else finds them. Outside the mandatory regime I work to your brief and you set the scope. Whether the mandatory regime applies to you is something we settle on the first call.

  • Entities under the higher-obligation regime, where the act requires an audit
  • Organisations wanting to check readiness before the obligation kicks in
  • Voluntary audits in a scope you define
  • A status review after changes to the organisation or the environment

What the audit covers

I assess the information security management system as a whole: what the documentation describes, what is actually deployed, and how far the two agree. Both directions are findings: a measure described but never put in place, and a measure in place with nothing documenting it.

  • Documentation, policies and the roles of the people responsible
  • How technical measures are deployed and configured
  • Organisational measures and whether they are followed in practice
  • Interviews with the people who run those measures day to day
  • Risk, supplier and incident management

How it relates to ISO/IEC 27001

The act's requirements for an information security management system rest on the same logic as ISO/IEC 27001 and the rest of the 27000 series – risk management, assigned roles, documented controls and regular review. If you already manage security to the standard, that covers a large part of what the act asks for, and the records you keep along the way work as evidence for the audit. A certificate on its own does not prove compliance with the act, though – the wording of the standard and the requirements of the act part ways in the detail, and what gets assessed is what actually runs.

  • Assessment against the act's requirements, not certification to the standard
  • Working with your management system documentation where you keep it to the standard
  • Making use of evidence from your internal audits and reviews

What you get

A written report with findings ranked by severity, each one describing what I found and the evidence behind it. What the report deliberately does not contain is a remediation design. The law forbids an auditor from proposing measures they then assess. So I describe findings in a way you can hand on, and point you to someone who can fix them.

  • Findings ranked by severity
  • A description of what I found and the evidence behind it
  • A summary for management and the detail for engineers
  • Walking through the report in person and answering questions

The independence line

For any one client I do either the audit or the development – never both. If I built your solution first and then audited it myself, the audit would be worthless.

How it works

  1. 01

    Initial call

    You tell me which regime you are in and what needs checking. We settle whether it is a mandatory or voluntary audit and roughly what scope it covers. No commitment.

  2. 02

    Scope and evidence

    I confirm in writing what will be assessed. That includes the list of materials I will need from you, so you can plan for them.

  3. 03

    Evidence and verification

    Reading the documentation, verifying measures in the running environment, and interviews with the people responsible. I flag what I run into as I go – nothing waits for the end.

  4. 04

    Report and handover

    You get a report with findings ranked by severity and we walk through it together. I answer questions about the findings after handover too.

Facing a mandatory audit?

Send me a few lines about which regime you are in and what needs checking. I reply within 48 hours.

Get in touch