Registration with the National Security Authority is only the beginning for an essential service operator. Within twelve months, it must adopt security measures extending well beyond its own infrastructure. Cybersecurity Act No. 69/2018 Z. z. expressly requires security to reach supplier contracts. Does NIS2 apply to us? addresses scope; this article covers what follows registration.
A supplier agreement is mandatory
A supplier carrying out activities affecting the operator’s networks and information systems needs a specific agreement.
Unofficial English translation:
Where an essential service operator carries out through a third party an activity directly related to the availability, confidentiality and integrity of its networks and information systems, it must conclude an agreement ensuring compliance with security measures and notification obligations under this Act throughout that activity; a risk analysis is performed when concluding the agreement.
The exception applies only if the supplier is itself an essential service operator or the activity’s risk is low, demonstrated by risk analysis rather than intuition. Supply chain security is also a mandatory measure under § 20(2). Decree No. 227/2025 Z. z., § 7(2), specifies minimum content: a commitment to comply with and expressly accept the operator’s security policies, the scope and method of controls and audits, and incident reporting and response cooperation. The National Security Authority publishes a model agreement. Older agreements concluded by the end of August 2025 cannot be extended unless compliant.
Flowing obligations down to subcontractors
The contractual chain does not stop at the first supplier. If subcontractors access your systems or data, obligations must reach them too. Supplier contracts should therefore cover:
- Incident reporting: recipient, channel and deadline. Under § 24(3), the operator must send an early warning within 24 hours and a notification within 72 hours of becoming aware of an incident. Supplier deadlines must therefore be materially shorter, with “awareness” clearly defined.
- Controls and audits: the operator’s right to verify supplier compliance, including scope, method and cost allocation.
- Remediation SLAs: response times for vulnerabilities and incidents, round-the-clock escalation contacts and recovery assistance.
- Termination and continuity: exit plans, data and configuration handover, and continuation of licences needed after termination. The Act also says the agreement must not restrict competition, including by creating dependence on a single supplier.
The supplier’s perspective
If you provide IT services to an essential service operator, such an agreement will eventually arrive, drafted from the customer’s perspective. Watch four areas. First, incident reporting deadlines materially stricter than statutory periods without defining when an incident is discovered. Second, result-based liability potentially excluding relief under § 374 of the Commercial Code. Third, uncapped contractual penalties: courts may reduce them under § 301, but relying on that is no strategy; put a cap in the contract. Finally, unilaterally changeable security policies: if the customer can tighten them at any time, the supplier needs a corresponding right to adjust pricing or refuse changes materially increasing costs.
Putting the arrangements in place
Our NIS2 and cybersecurity service covers obligations and supplier agreements. We incorporate requirements into service agreements with SLAs and implementation agreements. For multiple suppliers, contract oversight keeps the chain aligned. Review supplier contracts before the first incident.
This article provides general legal information as at 5 September 2026. It does not constitute legal services or advice on your specific matter. Laws change and the details of your situation may differ. Check the appropriate course of action or contact us before making a decision.