Mechanism
Act No. 265/2025 Sb. is a "change-law" (změnový zákon) — a Czech parliamentary instrument that amends multiple statutes in a single text without creating independent operative provisions. Its central operative move is to modify §6 and §7 of Act No. 34/2021 Sb. on Foreign Investment Screening, inserting a new mandatory-screening trigger pegged to the Cybersecurity Act's designation architecture.
The NIS2 cross-reference trigger
The amendment makes Czech FDI-screening scope dynamically dependent on NÚKIB designations under Act No. 264/2025 Sb. (the simultaneously enacted Cybersecurity Act, which transposes NIS2 Directive 2022/2555). Specifically:
- Entities providing "regulated services" under the "regime of higher obligation" (essential services — the NIS2 "essential entities" category) designated by NÚKIB are automatically subject to the Act 34/2021 mandatory pre-closing consent regime.
- The operative effect is that when NÚKIB designates a new entity under the higher-obligation regime (which it must review periodically and can update without FDI-Act amendment), that entity simultaneously falls within mandatory FDI-screening scope. The screening perimeter thus widens automatically as the cybersecurity-regulatory perimeter expands — a "living" cross-statutory scope-extension mechanism not seen in the prior Czech FDI architecture.
Sectors newly captured
The NIS2 higher-obligation "regulated services" framework covers: energy (electricity, oil, gas), transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure (IXPs, DNS, TLD registries), ICT-managed-service-providers, public administration, space, food production-processing-distribution. The practical new entrants into mandatory FDI-screening scope include data-centre operators, cloud-service providers, electronic-communications-network operators, hospital groups, and certain healthcare-IT operators — all sectors previously addressable only via the residual 5-year ex-officio discretionary call-in, now subject to the pre-closing mandatory consent regime.
§20a confidentiality-sharing channel
The amendment adds a new §20a provision expanding the MPO-staff confidentiality exception to allow information sharing between MPO and NÚKIB specifically for supply-chain-security assessments under the Cybersecurity Act's high-risk-vendor designation regime. This operationalises coordinated FDI-screening / supply-chain-security review for vendors designated by NÚKIB as high-risk (analogous to the EU ENISA high-risk-vendor methodology under NIS2 Art. 26).
1 November 2025 trifecta
Act 265/2025 (FDI-screening amendment) was promulgated in tandem with Act 264/2025 (new Cybersecurity Act / NIS2 transposition) and Act 266/2025 (new Critical Infrastructure Act / CER Directive 2022/2557 transposition — filed separately), all entering into force on 1 November 2025. This coordinated legislative package represents the most significant overhaul of the Czech critical-technology regulatory architecture since 2021.
Why severity 3
- First material FDI-screening scope extension since 2021: shifts the mandatory regime from a static perimeter (military, dual-use, critical-infrastructure operators already designated) to a dynamically-expanding perimeter driven by NÚKIB cybersecurity designations.
- Broadens reach to digital/technology/healthcare M&A flows that previously required only the permissive ex-officio review, now subject to pre-closing mandatory consent plus the 90-day review clock.
- Framework statute, not a transaction-specific prohibition: Act 265/2025 restructures scope rules, not a single deal outcome. Severity 4 reserved for the parent Act 34/2021 (horizontal FDI statute with full cross-sector mandatory + discretionary limbs at enactment). This amendment extends scope incrementally via cross-reference rather than replacing the architecture.
- NÚKIB designation cadence is paced: entity designations under the NIS2 higher-obligation regime are periodic and process-bound, so the practical scope expansion is phased over the NIS2 registration and designation cycle (initial registration deadline 30 December 2025; full designation process runs into 2026).
Downstream implications
- Czech digital / tech M&A: data-centre operators (CRA Digital, Sitel Czech), cloud-service providers (T-Systems CZ, O2 Czech Republic), ICT-MSPs and major ERP/CRM/HR-software operators serving Czech public administration are newly in scope. Foreign private-equity or strategic acquisition of these targets now requires MPO pre-closing notification and Government decision — adding 90+ days minimum to deal timelines.
- CEZ digital subsidiaries: ČEZ Group's digital-services arm (ČEZ Zákaznické Služby, ČEZ ICT Services) and potential new-build digital infrastructure SPVs are exposed via both the existing critical-infrastructure limb (nuclear and electricity grid) and the new NIS2 energy-sector designation.
- Healthcare M&A: hospital-group acquisitions (Agel, Penta Health, PPF-Group's hospital assets) and healthcare-IT operators designated under the NIS2 health-sector perimeter are newly subject to mandatory pre-closing screening.
- Financial-services technology: Komerční banka / Société Générale digital-services entities, Erste Group Czech banking-tech subsidiaries, and digital-infrastructure providers to Czech financial-market infrastructure may fall within the NIS2 financial-sector higher-obligation regime triggering FDI-screening scope.
- NIS2 registration-deadline pressure: covered entities must register with NÚKIB by 30 December 2025 — a tight compliance deadline running in parallel with the 1 November 2025 FDI-Act scope extension.
EU FDI-screening peer context
This is the third Czech filing in the IPTM register's Central European FDI-screening cluster:
2021-05-01-czechia-act-34-2021-fdi-screening-act — foundational horizontal statute (parent, responds_to chain anchor)2025-08-04-czechia-act-265-2025-fdi-screening-amendment — NIS2 cross-reference scope extension (this action)- The 2025-12-11-eu-fdi-screening-regulation-revision-political-agreement (filed) will impose additional EU-level mandatory-screening minimum standards that will require further Czech FDI-Act implementation, likely producing a third amendment round in 2026-2027.
Structurally, the NIS2-cross-reference architecture is the same approach adopted in AT (NIS2 transposition + FDI-screening alignment), BE (cooperation-agreement FDI-screening reform), DE (Außenwirtschaftsverordnung post-2024 §55a-§55b amendments cross-referencing KRITIS-Dachgesetz), and LV (National Security Law 2023 NIS2-alignment). Czech Act 265/2025 adds CZ to this EU-member-state architecture cluster.
Open questions
- NÚKIB designation cadence: the practical scope of the new mandatory FDI trigger is a function of how many entities NÚKIB designates under the higher-obligation regime in 2025-2026. Monitor the NÚKIB entity registry for the initial designation cohort.
- MPO enforcement statistics 2026: first full-year MPO report under the expanded mandatory perimeter (expected mid-2026) will reveal how many new mandatory notifications result from the NIS2 extension.
- EU FDI Regulation 2025 implementation: once the 2025-12-11 EU FDI Regulation political agreement converts into a Regulation, Czech Act 34/2021 will need further amendment to meet the EU-level mandatory-screening minimum standards — a third CZ FDI-screening amendment wave expected 2026-2027.