NIS2 and the Supply Chain: Why Czech Partners Are Asking About Your Security
Published: 19 July 2026 | Author: VĂt Vomáčko | NIS2OK.cz
If a Czech customer or partner has recently started asking pointed questions about your information security - a questionnaire, a request for a written attestation, a new clause in a contract renewal - there's a specific reason, and it isn't paranoia. It's very likely your Czech counterpart is itself a regulated entity under the Czech Act on Cybersecurity, and its own compliance now depends partly on you.
Why this is happening now
The Czech Act on Cybersecurity - Act 264/2025 Sb., which transposes the EU's NIS2 directive (Directive (EU) 2022/2555) into national law - took effect on 1 November 2025 and is enforced by NĂšKIB, the Czech national cyber security agency. Regulated Czech organisations, whether they sit in the higher- or lower-obligation regime, are expected to manage risk not only inside their own walls but across their supply chain.
In practice, that means a Czech company with NIS2 obligations now has to be able to show that its suppliers and service providers - including international ones - meet a reasonable security bar. If you supply software, IT services, logistics, or any operationally connected service to a regulated Czech organisation, you're now part of their compliance story, whether or not the Act applies to your own entity directly.
What Czech partners are actually asking for
The specifics vary by customer and by how mature their own compliance programme is, but the pattern is consistent. Expect some combination of:
- •A security questionnaire or self-assessment, often surfacing at contract renewal rather than at first signature.
- •A written attestation summarising your security measures, sometimes shaped to match what the Czech partner needs to show NÚKIB or its own auditors.
- •Contractual language committing you to notify them if you suffer a security incident that could affect the service you provide.
- •Occasionally, a request for a specific certification or independent audit - this tends to appear mainly with larger or more exposed customers.
None of this means your Czech customer thinks you're insecure. It means their own regulatory obligations now require them to ask, and to keep evidence that they asked.
How to respond well
The worst response is silence or a generic brush-off - fairly or not, it reads as having nothing to show. A better approach:
- ✓Take the request seriously and respond promptly - a regulated Czech customer likely has an internal deadline of their own.
- ✓Be honest about your current state. Overstating your posture in a written attestation puts you in a worse position later than admitting a gap and describing your plan to close it.
- ✓Put your existing measures in writing, even informally, so you're not improvising every time a new customer asks. A short, reusable security summary saves everyone time.
- ✓Don't assume this is irrelevant just because you have no Czech legal entity yourself - your customer's obligations are what's driving the conversation, and that isn't going away.
The minimum worth having in place
Even without a formal compliance programme, a small set of baseline measures covers most of what Czech partners tend to ask about: access control and multi-factor authentication on anything that matters, backups that are actually tested for restore, a written (even brief) incident response plan, basic patching discipline, and a clear owner for security decisions. None of this is exotic, and most organisations already have pieces of it in place - the value is in writing it down coherently enough to hand to a customer.
Related reading
Get oriented in 10 minutes
Understand how a Czech partner's NIS2 obligations are likely to shape what they ask of you - or whether your own Czech operations are directly in scope - with our free online NIS2 check.
Start the free check →The check is currently in Czech - contact us for a guided English-language walkthrough.