On 4. 8. 2025, a new Act No 266/2025 on the resilience of critical infrastructure entities and amending related acts (the ‘Critical Infrastructure Act’) was promulgated in the Collection of Laws. The effectiveness of this law was set at 19. 8. 2025. The Act lays down obligations for critical infrastructure entities aimed at strengthening their resilience and regulates the performance of the state administration in the area of increasing the resilience of critical infrastructure entities.

The Critical Infrastructure Act further defines a new type of sensitive activity: Performing the role of Critical Infrastructure Manager. The condition for the performance of this function is eligibility to perform sensitive activities pursuant to Act No. 412/2005 Coll., on the protection of classified information and on security eligibility, as amended. Provided that the current critical infrastructure manager does not meet the conditions for carrying out sensitive activities, he is obliged to prove their fulfilment no later than 3 years after the date of entry into force of the Critical Infrastructure Act. During that period, he shall be regarded as meeting those conditions unless, during that period or in the last 5 years prior to the date of entry into force of the Act on Critical Infrastructure, he has been issued with a decision not to issue a document proving the security capacity of a natural person; this provision shall also not apply if, in the last 5 years before the entry into force of the Critical Infrastructure Act, it has been issued with a decision revoking the validity of a certificate of security of a natural person or a decision revoking the validity of a certificate of a natural person.

The critical infrastructure manager must report to the head of the organisational unit of the State. Its task is to ensure compliance with the obligations under the Critical Infrastructure Act within the critical infrastructure entity and to provide cooperation to the Ministry of the Interior. The Ministry of the Interior is currently preparing further details on the identification of critical infrastructure entities and the consequent identification of the necessary roles.