Are you in scope for NIS2 / ZoKB?
Most Czech and EU SMEs aren't sure. Answer three questions for an instant, indicative read on your likely status, and what it puts on the line.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Cyber compliance has outpaced most organizations’ playbooks
Maximum NIS2 fines for essential entities, or 2% of global turnover
Mandatory early-warning window for significant incidents
Sectors now in scope, from healthcare to digital infrastructure
If you’re in scope, that means overlapping obligations, hard deadlines, and, for the first time, personal liability landing on your management. Spreadsheets and good intentions won’t survive an inspection
Every framework you're accountable to
Five steps from scoping to audit-ready
A clear path, with a concrete deliverable in your hands at every stage
Regulatory scoping
Are you in scope, and at which obligation tier?
Gap analysis
Your posture benchmarked against NIS2 and ZoKB
Solution plan
A roadmap to close every gap, scoped and costed
Deployment
ISMS, controls, incident response and continuity, live
Audit readiness
Ready for NÚKIB inspection, audits and ISO 27001
Eight services, one partner
NIS2 Gap Analysis
Readiness mapped to the directive, with a prioritized remediation roadmap
Risk, Governance and Compliance
Operable policies and controls, aligned to ISO 27001, NIS2, DORA, GDPR
SOC-as-a-Service (24/7)
Analyst-led monitoring and triage across endpoint, network, cloud and identity
IR, Detection and Threat Hunting
Incident response, custom detections, threat hunting and purple teaming
Virtual CISO (vCISO)
Fractional security leadership, from board reporting to team mentoring
Penetration Testing
Real-world attack simulation with proof, impact rating and free retest
SIEM Engineering and Maintenance
Sentinel, Splunk or Elastic, architected, tuned and cost-optimized
XDR Service
Correlated detection and response across endpoint, identity, cloud and email
No internal team? We become yours
A fractional Cybersecurity Manager who owns governance, risk, and NIS2 oversight on your behalf: accountable, embedded, and reporting to your board
Practitioner-led consulting
AVA Cyber was founded in 2026 by cybersecurity professionals with deep experience across security operations, incident response, compliance, and governance. Working alongside organizations navigating complex security requirements, we kept seeing the same gap: regulatory guidance on one side, practical implementation on the other, and very little bridging the two.
Our approach is built on operational experience. We have worked inside Security Operations Centres, managed real-world incidents, and supported organizations through audits and compliance assessments. That grounding lets us give advice that is not only aligned with NIS2, ISO 27001, and related frameworks, but also practical, proportionate, and tied to business objectives.
Today, AVA Cyber helps organizations strengthen their cyber resilience by combining technical expertise with regulatory knowledge. We believe compliance should be the outcome of effective security, not the objective itself.
The company is led by Ivanka Židková and Valentina Klemperová. As one of the few women-led cybersecurity consultancies in the Czech Republic, we are proud to contribute to a more diverse industry while holding to the highest standards of technical excellence.
.jpeg)
Ivanka Židková
Leads AVA Cyber’s strategy and client engagements, keeping compliance work grounded in real business outcomes.
LinkedIn →
Ing. Valentina Klemperová, MBA
People-focused GRC leader who builds and scales governance, risk, and information-security functions, pairing strategic leadership with hands-on execution.
LinkedIn →Specialist consultant network
A trusted bench of consultants across incident response, SOC, penetration testing, and governance, brought in to match each engagement.
Questions buyers ask first
It depends on your sector, headcount, and turnover. Our 30-second scope check tells you if you are likely in scope as an essential or important entity. To see where you stand across governance, risk, and incident handling, try our NIS2 Readiness Check for a full score and area breakdown.
NIS2 is transposed into Czech law through the new Cybersecurity Act (ZoKB). In-scope organizations have registration duties and then phased deadlines to put security measures and incident reporting in place. We map your specific obligations and dates to your situation, so you know exactly what is due when.
For a typical SME, 3-6 months from scoping to audit-ready, depending on your starting maturity. The free readiness consultation gives you an organization-specific timeline and budget before you commit to anything.
Yes. Through Cybersecurity Manager as a Service we act as your fractional CISO, owning governance, risk, and NIS2 oversight on your behalf and reporting to your management. Many SMEs use us instead of hiring a full-time security lead.
Concrete artifacts at every stage: a scope statement, a gap report, a costed remediation roadmap, implemented controls with evidence, and inspection-ready documentation, not a slide deck.
Yes, audit readiness is core to what we do. We prepare your evidence, governance, and people for regulatory inspections, external audits, and certification, and we stay with you through them.
Start with a NIS2 Readiness Consultation
A short engagement with no commitment. Leave with a clear view of your regulatory exposure, immediate risks, and a realistic timeline.
Book a consultationInterested in how we can help your business?
Drop us a note, and we will be in touch.