NIS2 and the Supply Chain: Why Czech Partners Are Asking About Your Security

Published: 19 July 2026 | Author: Vít Vomáčko | NIS2OK.cz

If a Czech customer or partner has recently started asking pointed questions about your information security - a questionnaire, a request for a written attestation, a new clause in a contract renewal - there's a specific reason, and it isn't paranoia. It's very likely your Czech counterpart is itself a regulated entity under the Czech Act on Cybersecurity, and its own compliance now depends partly on you.

Why this is happening now

The Czech Act on Cybersecurity - Act 264/2025 Sb., which transposes the EU's NIS2 directive (Directive (EU) 2022/2555) into national law - took effect on 1 November 2025 and is enforced by NĂšKIB, the Czech national cyber security agency. Regulated Czech organisations, whether they sit in the higher- or lower-obligation regime, are expected to manage risk not only inside their own walls but across their supply chain.

In practice, that means a Czech company with NIS2 obligations now has to be able to show that its suppliers and service providers - including international ones - meet a reasonable security bar. If you supply software, IT services, logistics, or any operationally connected service to a regulated Czech organisation, you're now part of their compliance story, whether or not the Act applies to your own entity directly.

What Czech partners are actually asking for

The specifics vary by customer and by how mature their own compliance programme is, but the pattern is consistent. Expect some combination of:

None of this means your Czech customer thinks you're insecure. It means their own regulatory obligations now require them to ask, and to keep evidence that they asked.

How to respond well

The worst response is silence or a generic brush-off - fairly or not, it reads as having nothing to show. A better approach:

The minimum worth having in place

Even without a formal compliance programme, a small set of baseline measures covers most of what Czech partners tend to ask about: access control and multi-factor authentication on anything that matters, backups that are actually tested for restore, a written (even brief) incident response plan, basic patching discipline, and a clear owner for security decisions. None of this is exotic, and most organisations already have pieces of it in place - the value is in writing it down coherently enough to hand to a customer.

Get oriented in 10 minutes

Understand how a Czech partner's NIS2 obligations are likely to shape what they ask of you - or whether your own Czech operations are directly in scope - with our free online NIS2 check.

Start the free check →

The check is currently in Czech - contact us for a guided English-language walkthrough.