Act No. 69/2018 Z. z. · Compliance, Registers & Licences

NIS2 does not end at registration: cybersecurity belongs in supplier contracts

The Cybersecurity Act requires essential service operators to conclude specific agreements with suppliers affecting their networks and systems, covering security policies, audits and incident reporting. What the agreement needs, what to ask IT suppliers for and what to watch when you are the supplier.

Registration with the National Security Authority is only the beginning for an essential service operator. Within twelve months, it must adopt security measures extending well beyond its own infrastructure. Cybersecurity Act No. 69/2018 Z. z. expressly requires security to reach supplier contracts. Does NIS2 apply to us? addresses scope; this article covers what follows registration.

A supplier agreement is mandatory

A supplier carrying out activities affecting the operator’s networks and information systems needs a specific agreement.

Unofficial English translation:

Where an essential service operator carries out through a third party an activity directly related to the availability, confidentiality and integrity of its networks and information systems, it must conclude an agreement ensuring compliance with security measures and notification obligations under this Act throughout that activity; a risk analysis is performed when concluding the agreement.

§ 19(2) of Act No. 69/2018 Z. z.

The exception applies only if the supplier is itself an essential service operator or the activity’s risk is low, demonstrated by risk analysis rather than intuition. Supply chain security is also a mandatory measure under § 20(2). Decree No. 227/2025 Z. z., § 7(2), specifies minimum content: a commitment to comply with and expressly accept the operator’s security policies, the scope and method of controls and audits, and incident reporting and response cooperation. The National Security Authority publishes a model agreement. Older agreements concluded by the end of August 2025 cannot be extended unless compliant.

Flowing obligations down to subcontractors

The contractual chain does not stop at the first supplier. If subcontractors access your systems or data, obligations must reach them too. Supplier contracts should therefore cover:

  • Incident reporting: recipient, channel and deadline. Under § 24(3), the operator must send an early warning within 24 hours and a notification within 72 hours of becoming aware of an incident. Supplier deadlines must therefore be materially shorter, with “awareness” clearly defined.
  • Controls and audits: the operator’s right to verify supplier compliance, including scope, method and cost allocation.
  • Remediation SLAs: response times for vulnerabilities and incidents, round-the-clock escalation contacts and recovery assistance.
  • Termination and continuity: exit plans, data and configuration handover, and continuation of licences needed after termination. The Act also says the agreement must not restrict competition, including by creating dependence on a single supplier.

The supplier’s perspective

If you provide IT services to an essential service operator, such an agreement will eventually arrive, drafted from the customer’s perspective. Watch four areas. First, incident reporting deadlines materially stricter than statutory periods without defining when an incident is discovered. Second, result-based liability potentially excluding relief under § 374 of the Commercial Code. Third, uncapped contractual penalties: courts may reduce them under § 301, but relying on that is no strategy; put a cap in the contract. Finally, unilaterally changeable security policies: if the customer can tighten them at any time, the supplier needs a corresponding right to adjust pricing or refuse changes materially increasing costs.

Putting the arrangements in place

Our NIS2 and cybersecurity service covers obligations and supplier agreements. We incorporate requirements into service agreements with SLAs and implementation agreements. For multiple suppliers, contract oversight keeps the chain aligned. Review supplier contracts before the first incident.

This article provides general legal information as at 5 September 2026. It does not constitute legal services or advice on your specific matter. Laws change and the details of your situation may differ. Check the appropriate course of action or contact us before making a decision.

Facing a similar situation?

Tell us what you need help with.

Describe your situation. We will review it and tell you within 24 hours whether and how we can help, including an indicative fee.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.

Contact a lawyer