Show all

NIS2 Authorized Person

One-day course for persons responsible for cybersecurity in organizations falling under the regime of lower obligations according to Act No. 264/2025 Coll. (nZKB). You will receive a systematic overview of obligations, practical tools for their implementation, and the certainty that your organization will withstand the NÚKIB inspection.
Level
Designed for participants without knowledge and experience
basic
Course length
1 day
Language
 cz
Course code
PU00010035
NIS2
Category:
Do you want this tailor-made course to your company? Contact us

Courses with lecturer

Term
Language
Place
Form
?
How and where the course takes place.
Price without VAT
10. 7. 2026 09:00 - 17:00
Language
Place
Praha
Form
classroom
?
The course with an instructor in classroom.
Code of the course: PU00010035-0001
Price without VAT
8 900 Kč
10. 7. 2026 09:00 - 17:00
Language
Place
online
Form
classroom
?
The course with an instructor in classroom.
Code of the course: PU00010035-0002
Price without VAT
8 900 Kč
25. 9. 2026 09:00 - 17:00
Language
Place
online
Form
classroom
?
The course with an instructor in classroom.
Code of the course: PU00010035-0003
Price without VAT
8 900 Kč
25. 9. 2026 09:00 - 17:00
Language
Place
Praha
Form
classroom
?
The course with an instructor in classroom.
Code of the course: PU00010035-0004
Price without VAT
8 900 Kč
19. 11. 2026 09:00 - 17:00
Language
Place
online
Form
classroom
?
The course with an instructor in classroom.
Code of the course: PU00010035-0005
Price without VAT
8 900 Kč
19. 11. 2026 09:00 - 17:00
Language
Place
Praha
Form
classroom
?
The course with an instructor in classroom.
Code of the course: PU00010035-0006
Price without VAT
8 900 Kč

Course description

Act No. 264/2025 Coll. on Cybersecurity (nZKB), effective from November 1, 2025, introduces obligations for thousands of Czech organizations. For those in the regime of lower obligations (typically companies with 50+ employees or turnover over EUR 10 million), Decree No. 410/2025 Coll. applies - and each such organization must demonstrably appoint a person responsible for cybersecurity.

This course will prepare the person responsible for all key obligations: from registration with the National Cybersecurity Agency through the implementation of security measures to incident reporting and documentation for a possible audit. The course combines an explanation of the legislative framework with practical examples and checklists directly applicable in your organization.

Required knowledge

Basic orientation in the IT environment of your organization. Legal or technical specialization is not a requirement - the course is intended for managers and responsible persons, not IT specialists.

Target audience

  • For persons entrusted with cybersecurity (according to § 4 of Decree 410/2025 Coll.)
  • For managers and executives of small and medium-sized enterprises in regulated sectors
  • For directors and statutory representatives who want to understand their legal obligations
  • For consultants and advisors accompanying clients in the implementation of NIS2

Course content

Legislative framework
  • NIS2 Directive and its Czech transposition (Act No. 264/2025 Coll.)
  • Two regimes of obligations: Decree 409 vs. 410 – what applies to you
  • Who is a regulated entity and how to perform self-identification
  • Roles and responsibilities: authorized person vs. KB manager vs. statutory body

Block 2 – Registration and appointment
  • Obligation to register with NÚKIB (NÚKIB Portal, deadline 60 days)
  • Appointment of an authorized person: formal requirements and documentation
  • Contractual arrangements when outsourcing the function of an authorized person
Security measures 
  • Overview of 13 security measures in the lower obligation regime
  • Risk management: threat identification, probability × impact matrix
  • Asset management and supply chain: records, evaluation, contractual clauses
  • Technical measures: access, passwords, MFA, encryption, logging
  • Security policies and documentation
Training and security awareness
  • Legal requirements for employee training (Annex 3 and 6 of Decree 410)
  • Content of training for different groups: management, users, administrators, authorized person
  • How to document the training carried out
Incident reporting
  • Deadlines: 24 hours / 72 hours / 30 days
  • Reporting procedure via the NÚKIB Portal step by step
  • Incident Response Plan: how to compile and maintain it
Audit and control of the NÚKIB
  • What inspectors monitor and what documents you must have ready
  • The most common findings from audits
  • Action plan: how to prepare within 1 year of registration

Certification

Upon completion of the course, you will receive a Pumpedu certificate issued by an authorized training provider with accreditations from leading international organizations in IT, project management, and professional development.
Obrázek certifikátu

Materials

Study materials are included in the course price. You will receive practical Pumpedu materials summarizing the key principles, tools, and methods covered during the training, so you can easily apply them in practice even after the course.

Objectives

After completing the course, the participant will:
  • Understand the legislative framework of NIS2 and the Czech transposition (Act 264/2025 Coll. and Decree 410/2025 Coll.)
  • Know the scope of his/her duties as an authorized person in the organization
  • Can set up and document basic security measures
  • Know how to correctly report cyber incidents to the National Cyber ​​Security Agency within the legal deadlines
  • Is prepared for an inspection by the National Cyber ​​Security Agency and can demonstrate compliance with the requirements of the law

Frequently Asked Questions

Do I need to have a technical education?
No. The course is primarily intended for managers and authorized persons, not IT specialists. Technical terms are explained in a practical context.

What is the difference between "authorized person" and "KB manager"?
An authorized person is a role in the lower duties regime (Decree 410), KB manager is a formal qualification in the higher duties regime (Decree 409). For organizations in the lower regime, an authorized person is sufficient - this role does not have a legal requirement for certification, but completing the course is recommended practice and evidence for NÚKIB.

Will I receive a certificate recognized by NÚKIB after the course?
NÚKIB does not require certification of authorized persons. The course certificate serves as proof of training, which may be relevant during an inspection. For formally recognized certification in KB, see the Cybersecurity Manager course (NSK 18-015-T).

Can I outsource the function of an authorized person?
Yes, the law allows it. The course also covers the requirements for contractual arrangements when outsourcing.

Do you want this tailor-made course for your company?

Contact us

News with the course

Náhledový obrázek novinky
Cyber Security 4. 3. 2026
Cybersecurity Academy 

Cybersecurity as a strategic issue. Cybersecurity is no longer just a matter for IT departments. Today's attacks primarily target people, their decision-making, and their daily habits.

Náhledový obrázek novinky
CompTIA 20. 2. 2026
How the CompTIA Security+ exam works and types of questions

Those interested in CompTIA certification often ask us how the exam works and what the test questions look like.

Náhledový obrázek novinky
Cyber Security 1. 8. 2024
How to become a cybersecurity expert

If you want to be a cybersecurity expert and become a security architect, we have great news for you. We have prepared a series of courses that will help you fully master the issue of strategic design of the safety and security of the organization.

Previous courses

Follow-up courses

Do you want this tailor-made course for your company?

Contact us

News with the course

Náhledový obrázek novinky
Cyber Security 4. 3. 2026
Cybersecurity Academy 

Cybersecurity as a strategic issue. Cybersecurity is no longer just a matter for IT departments. Today's attacks primarily target people, their decision-making, and their daily habits.

Náhledový obrázek novinky
CompTIA 20. 2. 2026
How the CompTIA Security+ exam works and types of questions

Those interested in CompTIA certification often ask us how the exam works and what the test questions look like.

Náhledový obrázek novinky
Cyber Security 1. 8. 2024
How to become a cybersecurity expert

If you want to be a cybersecurity expert and become a security architect, we have great news for you. We have prepared a series of courses that will help you fully master the issue of strategic design of the safety and security of the organization.

Why with us