NIS2 and the apps your company builds itself
This concerns you if your company falls under the Czech Cyber Security Act (No. 264/2025 Coll., the Czech implementation of NIS2), or if you supply a company that does. The apps your people build count as development and maintenance under Decree 410/2025 Coll., Section 3(6). If they relate to the regulated service, you have to set security requirements for them and enforce them, even in the lower regime.
This guide is for IT managers and leadership at mid-sized companies. We go through what the act and the decrees ask for, what of it Fabrika handles and what stays with you. Other EU countries implement NIS2 through their own laws; this page covers the Czech one.
Updated 28 September 2026
Supplier contracts and rules for development are part of the mandatory minimum.
Annex 2 of Decree 410/2025 Coll. The contract covers the ones that are relevant.
For the initial report of an incident, counted from when you detect it (Section 16 of the act).
Does this apply to us?
It depends on what your company does and how big it is. And even if you don't fall under the act yourself, its requirements can reach you through your customers.
Who falls under the act
Two conditions, and both must hold (Section 4(1) of the act). The company provides a service in one of 15 sectors, among them manufacturing, food and chemical industry, energy, transport, healthcare, and digital infrastructure and services. And it is a medium-sized or large enterprise under Commission Recommendation 2003/361/EC. The exact list of services is set by a decree of NÚKIB, the Czech cyber security agency.
A company that meets the conditions has to notify the service within 60 days (Section 6(1)). NÚKIB can also register a provider regardless of size, for example the only provider of an essential service in the country or an entity of critical infrastructure (Section 5).
Lower or higher regime?
The higher-obligation regime is for providers that are highly significant for the Czech Republic economically, socially or for security (Section 8). NÚKIB sets the split by decree. Everyone else is in the lower regime.
Decree 410/2025 Coll. applies to the lower regime, Decree 409/2025 Coll. to the higher one. This guide follows the lower regime and points out what the higher one adds. Security measures and incident reporting start no later than one year after the registration decision is delivered (Sections 13(4) and 15(4)).
You're not covered, but you supply someone who is
A regulated company has to choose suppliers in line with its security measures and put the requirements into its contracts (Section 13(5) of the act). In the lower regime that means the relevant points of Annex 2 of Decree 410, including contracts already signed (explanatory memorandum to Section 3(5)).
In the higher regime, the company keeps a register of significant suppliers, tells them so in writing, and their contracts must cover the points of Annex 5 of Decree 409 (Section 9). If apps you build yourself are part of what you deliver, expect questions about who changes them and how.
Which apps count
The act covers the assets related to the regulated service. The company has to identify them, assess them and keep a record of them (Section 12 of the act). Until you have assessed an asset, it counts as in scope (Section 12(4)). That's why it pays to know which apps your people have actually built.
What does the law ask of the apps you build?
Decree 410/2025 Coll. splits the measures into two groups. The mandatory minimum you always put in place (Section 3(1)(b)). For the others you can decide not to put them in place yet, but you have to justify that in your overview of security measures, with a date, a priority and a responsible person (Section 3(2) and the explanatory memorandum).
The mandatory minimum
Security requirements for development and maintenance
The apps your people build are development. You need rules for how they are made and changed, and you have to enforce them. On Fabrika the platform enforces them: apps can't get around sign-in, permissions, keys or deployment, and every change goes through our review.
Supplier contracts
Contracts with whoever builds or runs your apps must cover the relevant points of Annex 2. The breakdown for Fabrika is below.
Rules for using technical assets
How technical assets are used and handled. The apps are among them.
Business continuity and backups
The priority and order of recovery, who is responsible for what, and regular backups of data and configuration. More on that below.
Handling incidents
People report unusual behaviour, the company has a method for assessing incidents and reports those with significant impact.
Leadership, policy and training
Top management names a person responsible for cyber security and gets trained. Add the overview of security measures, the security policy and training for people.
Measures you either put in place or justify leaving out
Sections 7–9 and 11–13. Below are the ones that concern apps.
| Measure | What the decree asks | On Fabrika |
|---|---|---|
| Section 7 Access control | What the decree asks Only the permissions needed for the job. Remove or change access without delay when someone changes role or leaves. | On Fabrika Roles per app, and you decide who gets which. People sign in with their company account, so for them you remove access in one place. |
| Section 8 Identity management | What the decree asks Multi-factor authentication. Until then keys or certificates, and only after that a password with rules: at least 12 characters for users, 17 for administrators. | On Fabrika With a company account (Google, Microsoft, Okta), multi-factor authentication applies as your company has it set up. |
| Section 9 Event logging | What the decree asks A record with date and time including the time zone, the type of activity, the asset and the account, and whether it succeeded. You set the retention period yourself. | On Fabrika Sign-ins are recorded, changes to access and roles are kept, and every deployment has its own record. Whether that covers your needs we go through together. |
| Section 11 Network security | What the decree asks Network segmentation and limiting traffic at the perimeter to what the service needs. | On Fabrika Apps have no public address; the only way in leads through the platform. Test and production environments each have their own network. |
| Section 12 Application security | What the decree asks Apply security updates without delay, keep a record of unsupported assets, scan for vulnerabilities regularly. | On Fabrika We patch the platform continuously. Fabrika doesn't promise regular vulnerability scanning on its own; if you run it, include the apps. |
What the higher regime adds
Under Decree 409/2025 Coll. there is, among other things, change management with testing before going live and the option to return to the original state (Section 11(2)), separated production, backup, development and test environments (Section 12(1)(e)), and penetration tests based on the risk assessment (Section 24(5)).
What has to be in the contract with a supplier?
Annex 2 of Decree 410/2025 Coll. lists 14 areas a supplier contract should address. The contract includes the ones that are relevant to the relationship (Section 3(5)). Here is how it works with Fabrika. Where only the contract gives the answer, we say so.
| Annex 2 point | What it means | How it works on Fabrika |
|---|---|---|
| a) Information security | What it means Confidentiality including non-disclosure, integrity and availability of data. | How it works on Fabrika Your own installation, one gate, sign-in with your company account, roles per app, keys held by the cloud provider. Non-disclosure is in the contract. |
| b) Supplier audit | What it means The right to check how the supplier fulfils the contract. | How it works on Fabrika We agree the scope of an audit in the contract. We don't promise it in advance here. |
| c) Chain of suppliers | What it means Who else takes part in delivering the service. | How it works on Fabrika For Fabrika you have one supplier: us. The cloud account with Cloudflare, Zerops or AWS is registered to your company, so you have that relationship directly. The AI runs on your own plan. If a developer or agency builds for you, you hire them yourself. |
| d) Exit strategy | What it means What happens to the data and the system when the cooperation ends. | How it works on Fabrika The apps' code is yours, the data and the domains are in your account. The system keeps running without us, and the next person picks it up from Git. |
| e) Penalties | What it means What the supplier faces for breaching the contract. | How it works on Fabrika Set in the contract. |
| f) Right to use data | What it means What the supplier may do with your data. | How it works on Fabrika The data sits in your account. We access it to the extent we need for review, deployment and patches. Nothing is trained on your data. |
| g) Code authorship and licences | What it means Who owns the code and what you hold a licence to. | How it works on Fabrika The apps' code belongs to you. The terms for using the platform itself are set in the contract. |
| h) Confidentiality of the relationship | What it means What either side may say about working together. | How it works on Fabrika Set in the contract. |
| i) Your security policies | What it means The supplier follows your rules, or you approve theirs. | How it works on Fabrika Send us your rules for suppliers before signing. We'll tell you which of them we meet and agree how they go into the contract. |
| j) Change management | What it means How the system changes and who approves it. | How it works on Fabrika Every change goes through Git with an author, a time and a description. A person on our side reviews it before deployment, the deployment is recorded, and you get a report on what changed. |
| k) Incidents related to the contract | What it means Who informs whom, and how both sides work together. | How it works on Fabrika The platform collects errors and alerts on new ones or on a sudden spike. We help find out what happened, fix it and put together the documents for your report. The deadline for informing you is set in the contract. |
| l) Business continuity | What it means How the supplier contributes to recovery after an outage. | How it works on Fabrika We set up backups and recovery with you, to the extent you need. It's our service, not something the platform does on its own. |
| m) SLA and level of security measures | What it means Which service parameters the supplier keeps. | How it works on Fabrika Operations and change review come with an SLA. The specific parameters are in the contract. |
| n) Secure development | What it means How the supplier prevents flaws while building. | How it works on Fabrika Building with AI goes in phases, on the brief and the code, not on live data. Every change goes through our review. If your developer or agency builds, the same path applies to them. |
In the higher regime
For significant suppliers, Annex 5 of Decree 409/2025 Coll. applies, with 18 points. It adds, for example, informing you about a change of ownership of the supplier, about a foreign authority requesting data, or about the people who come into contact with your confidential information. We go through those points one by one with your lawyer.
Who backs up the apps' data?
The company “makes regular backups of the information, data, configurations and settings of technical assets needed in particular to restore the regulated service in the event of a cyber security incident.”
What we do
We set up backups and recovery with you, to the extent you need: what gets backed up, how often, how long backups are kept and how quickly the data has to be back. It's our service, not something the platform does on its own, so we agree on the scope when we set up Fabrika.
What's up to you
Deciding which apps take priority, in what order they are restored and who is responsible for it (Section 6(a) and (b), Section 4(f)).
In the higher regime
You also set a recovery time and a recovery point for data, and test your recovery plans regularly (Decree 409/2025 Coll., Section 15). Bring those numbers along and we'll set up the backups to match.
When and to whom do you report an incident?
In the lower regime you report to the National CERT an incident that showed up within the scope of the regulated service, originated in cyberspace, has a significant impact, and where intent can't be ruled out (Section 15(2) of the act). In the higher regime you report to NÚKIB even incidents without significant impact (Section 15(1)).
Significant impact means serious operational disruption or financial loss, or considerable harm to others (Section 15(3)). In the lower regime you set yourself the level of harm you can still bear, and assess incidents against it (Decree 410/2025 Coll., Section 14).
- 24 h
Initial report
Without undue delay, no later than 24 hours after you detect the incident (Section 16(1)).
- 72 h
Notification
For an incident with significant impact: an initial assessment, the impact and indicators of compromise if you have them (Section 16(3)(a)).
- 30 days
Final report
No later than 30 days after the notification. If the incident is still ongoing by then, a progress report, and the final one within 30 days of resolving it (Section 16(3)(c)).
Reports go through the NÚKIB portal (Section 16(4)).
What Fabrika does
The platform collects errors from all apps in one place and alerts on a new error or a sudden spike. We help find out what happened in the app, fix it, and put together the documents for the report. Assessing the impact and filing the report is up to you (Section 10 of Decree 410).
What stays with you?
Fabrika won't make you compliant with the act. The platform enforces the rules for apps and we review every change. The legal duties belong to your company, and nobody else can do these for you:
- Sections 6, 9, 11 of the act Notify the service and report changes to NÚKIB.
- Section 12 of the act Identify, assess and keep a record of your assets, including the apps.
- Section 3(2) Keep an overview of security measures and update it at least once a year.
- Section 3(3) and (6) Set the security policy and the rules for development, and enforce them.
- Sections 4 and 5 Name a person responsible for cyber security, and train leadership and staff.
- Section 4(f), Section 6 Decide the recovery priority and who is responsible for recovery.
- Section 7 Decide who gets which role in which app.
- Section 10, Section 16 of the act Assess an incident and file the report.
What we give you for it
For the part that concerns the apps, we give you the technical groundwork: how sign-in, roles, records, change management and backups work. You can use it in your overview of security measures. We're happy to fill in your own security questionnaire too.
When is Fabrika not for you?
From the NIS2 point of view, honestly:
You want a supplier to make you compliant
We won't. Compliance is your company's duty. A cyber security consultant or an auditor will help you with the documentation and the overview of measures; we supply the groundwork for the apps.
A supplier certification is a condition
If a certificate such as ISO 27001 or SOC 2 is a condition for choosing a supplier, ask about it right at the start of the first call, so nobody wastes time.
You need penetration tests and rollback as part of the service
Neither penetration tests (Decree 409, Section 24) nor returning a deployment to its original state (Section 11) is something Fabrika promises today. In the higher regime, factor that in.
What people ask about NIS2 and apps
Does NIS2 cover internal apps too?
Yes, if they relate to the regulated service. The act covers assets within the defined scope (Section 12), and an app you haven't assessed yet counts as in scope (Section 12(4)). The decree then asks for security requirements for development and maintenance (Decree 410, Section 3(6)).
What are the fines?
In the lower regime up to CZK 175 million or 1.4 % of worldwide annual turnover, whichever is higher. In the higher regime up to CZK 250 million or 2 %. This covers, among other things, not putting security measures in place and supplier contracts without the security requirements (Section 59 of the act). NÚKIB can also first order corrective measures (Section 56).
Can leadership be banned from office?
Only in the higher regime. NÚKIB can ban a member of the statutory body from office, for at least six months, if they repeatedly or seriously breached their duties while the company was carrying out a corrective measure and thereby frustrated it (Section 58). The act doesn't allow this in the lower regime. The duties of leadership (training, resources, keeping up with the measures) apply there too (Decree 410, Section 4).
We supply a regulated company. What can they ask of us?
The points of Annex 2 of Decree 410 that are relevant to your relationship, including in contracts you already have. If your customer is in the higher regime and you are a significant supplier for them, they tell you so in writing and the contract has to cover the points of Annex 5 of Decree 409 (Section 9).
Do we have to use multi-factor authentication?
The decree asks for it (Section 8(2)), but in the lower regime it's among the measures you can leave out with a justification. Until you have it, fallback rules apply: keys or certificates, and only then a password of at least 12 characters for users and 17 for administrators (Section 8(3) and (4)). On Fabrika people sign in with their company account (Google, Microsoft, Okta), and multi-factor authentication applies as your company has it set up.
How long do we have to keep records?
You set the period yourself, based on your security needs (Section 9(3)). The decree sets what a record contains: date and time with the time zone, type of activity, the asset and the account, and whether it succeeded (Section 9(2)). On Fabrika sign-ins are recorded, changes to access and roles are kept, and every deployment has a record. How that fits your requirements we go through together.
Where does the data live?
In your company's cloud account, with Cloudflare or Zerops, or AWS if you prefer. Each company has its own installation and shares it with no one. Zerops is a Czech company with a data centre in Prague. With Cloudflare, we go through the region and the terms against your requirements. On AWS, we pick the region to match them.
Will you make us NIS2 compliant?
No. Compliance is your company's duty and Fabrika won't take it over. For the apps we enforce the rules on the platform, review every change and give you the technical groundwork for your overview of security measures.
Go through it with our engineer.
Bring your overview of security measures or your questionnaire for suppliers. In half an hour we'll go through what in it concerns the apps, what Fabrika handles and what stays with you.
Sources
This isn't legal advice. The guide summarises the act and the decrees as they stood on 28 September 2026. Whether and how they apply to you is best assessed with your lawyer or auditor; we'll gladly give them the technical details.