Blog · Safety & Compliance

NIS2 obligations for hotels:
What you must do in 2026

4 April 2026 · 8 min read

The NIS2 Directive (implemented in the Czech Republic by Act No. 264/2025 Coll.) has entered into force and introduced new obligations in the field of cybersecurity. Large hotels and hotel chains cannot pretend it does not concern them, fines for ignoring these requirements can reach up to 10 million EUR.

⚠️ Does this concern your hotel?

NIS2 applies to hotels that are part of a group with 50+ employees or an annual turnover exceeding 10 million EUR, or to those operating digital platforms (own booking system, loyalty programme). Smaller independent hotels usually fall below these thresholds, but GDPR applies to all.

Why hotels are more affected by NIS2 than other sectors

Hotels are particularly vulnerable to cyber security threats for several reasons:

6 specific obligations for hotels under NIS2

1. Cybersecurity risk management

The hotel must have a risk management system documented in writing: not just guessing what might happen, but having specific assets (PMS server, payment terminals, booking system), threats and ways to mitigate them mapped out.

Practically: what you need IT asset inventory, risk assessment and treatment plan. An antivirus and firewall are not enough. It must be a system.

2. Supply chain security

The hotel is also responsible for the security of its suppliers, PMS systems (Mews, Opera, Cloudbeds), channel managers and payment gateways. NIS2 requires you to demand security guarantees from suppliers and regularly check them.

What to do specifically:

  • Request a security certification (ISO 27001, SOC 2) from the PMS provider.
  • Check your contracts: do they include an SLA for security incidents?
  • Verify where guest data is physically stored (within the EU or outside?).

3. Incident Response Plan

A serious cyber incident must be reported to the competent authority within 24 hours from the finding. To 72 hours You must submit a detailed report. A serious incident includes, for example, a ransomware attack, a guest data breach or an outage of the reservation system.

The response plan must be in place before an incident occurs, not improvised on the fly. It must clearly state who does what, who is informed and how quickly.

4. Access control and identity

Multi-factor authentication (MFA) for access to critical systems is mandatory. Receptionists logging into the PMS with a password only represent a security vulnerability, especially given high staff turnover.

5. Staff training

NIS2 explicitly requires regular employee training in cybersecurity. Receptionists who click on phishing emails or share passwords are the weakest link.

Practically: annual training (ideally quarterly), simulated phishing tests, clear rules for reporting suspicious activity.

6. Personal liability of management

This is a new requirement that many hoteliers overlook: NIS2 allows personal liability of statutory bodies. The managing director or executive officer may be personally fined if it is proven that they ignored safety risks.

What are the fines?

Basic entities

up to 7 million EUR

or 1.4% of annual turnover

Key stakeholders

up to 10 million EUR

or 2% of global turnover

Large hotel chains with a global turnover of 500 million EUR could face fines of up to 10 million EUR. That is motivation for action.

How to get started: a practical plan for hotels

1

Find out if you fall under NIS2

Number of employees, turnover, type of digital services provided: this can be verified in an hour.

2

Take stock of your IT assets

PMS server, payment terminals, WiFi infrastructure, reservation system, email, where they are located, who manages them, and who has access.

3

Identify the biggest gaps

Typically these include: weak access controls (without MFA), network segmentation (guest WiFi vs internal), backups, and staff training.

4

Prepare the documentation

Cybersecurity policy, incident response plan, risk analysis, in the event of an inspection you must present these documents. The HotelIT tool will help you generate and manage this documentation. NIS2 Manager.

5

Register with NÚKIB

If you fall under NIS2, you must register with the National Office for Cyber and Information Security. The deadline is set for autumn 2025.

Do you need help with NIS2 compliance for your hotel?

HotelIT provides hotels in Prague with comprehensive IT management including preparation for NIS2. We know how hotel systems work and can prepare your infrastructure and documentation.

Book a free consultation

Frequently Asked Questions (FAQ)

Does the NIS2 Directive apply to small boutique hotels?

Usually not, if the hotel employs fewer than 50 people and its annual turnover does not exceed EUR 10 million, it falls outside NIS2. However, GDPR applies to all regardless of size, bringing similar requirements for protecting guest data.

Do we need to replace our entire PMS system due to NIS2?

Not necessarily. The key is that your PMS provider meets security standards (ISO 27001 or SOC 2) and that liability for security incidents is contractually covered. Changing the system is usually a last resort, not the first step.

What to do if we are hacked?

Do you have 24 hours Report the incident to NÚKIB (if you fall under NIS2). Immediately isolate affected systems, activate the incident response plan, and contact an IT security specialist. Do not erase traces, logs are crucial for investigation and insurance claims.

Other articles on hotel safety