---
title: NIS2 and the apps your company builds itself | Contember Fabrika
description: "What the Czech Cyber Security Act (NIS2) asks of the apps your company builds itself: the mandatory minimum, supplier contracts, backups and incidents."
url: "https://www.contember.com/security/nis2"
type: static
generatedAt: "2026-09-28T14:08:32.966Z"
---

# NIS2 and the apps your company builds itself

This concerns you if your company falls under the Czech Cyber Security Act (No. 264/2025 Coll., the Czech implementation of NIS2), or if you supply a company that does. The apps your people build count as development and maintenance under Decree 410/2025 Coll., Section 3(6). If they relate to the regulated service, you have to set security requirements for them and enforce them, even in the lower regime.

This guide is for IT managers and leadership at mid-sized companies. We go through what the act and the decrees ask for, what of it Fabrika handles and what stays with you. Other EU countries implement NIS2 through their own laws; this page covers the Czech one.

Updated 28 September 2026
  [Go through it with our engineer →](https://cal.com/contember/demo) [What the supplier contract needs ↓](#contract)    ![](/illustrations/machine-inspection.webp)       Lower regime  Section 3(5) and (6)
Supplier contracts and rules for development are part of the mandatory minimum.
    Contracts  14 points
Annex 2 of Decree 410/2025 Coll. The contract covers the ones that are relevant.
    Incident  24 hours
For the initial report of an incident, counted from when you detect it (Section 16 of the act).

## Does this apply to us?

It depends on what your company does and how big it is. And even if you don't fall under the act yourself, its requirements can reach you through your customers.

### Who falls under the act

Two conditions, and both must hold (Section 4(1) of the act). The company provides a service in one of 15 sectors, among them manufacturing, food and chemical industry, energy, transport, healthcare, and digital infrastructure and services. And it is a medium-sized or large enterprise under Commission Recommendation 2003/361/EC. The exact list of services is set by a decree of NÚKIB, the Czech cyber security agency.

A company that meets the conditions has to notify the service within 60 days (Section 6(1)). NÚKIB can also register a provider regardless of size, for example the only provider of an essential service in the country or an entity of critical infrastructure (Section 5).

### Lower or higher regime?

The higher-obligation regime is for providers that are highly significant for the Czech Republic economically, socially or for security (Section 8). NÚKIB sets the split by decree. Everyone else is in the lower regime.

Decree 410/2025 Coll. applies to the lower regime, Decree 409/2025 Coll. to the higher one. This guide follows the lower regime and points out what the higher one adds. Security measures and incident reporting start no later than one year after the registration decision is delivered (Sections 13(4) and 15(4)).

### You're not covered, but you supply someone who is

A regulated company has to choose suppliers in line with its security measures and put the requirements into its contracts (Section 13(5) of the act). In the lower regime that means the relevant points of Annex 2 of Decree 410, including contracts already signed (explanatory memorandum to Section 3(5)).

In the higher regime, the company keeps a register of significant suppliers, tells them so in writing, and their contracts must cover the points of Annex 5 of Decree 409 (Section 9). If apps you build yourself are part of what you deliver, expect questions about who changes them and how.

### Which apps count

The act covers the assets related to the regulated service. The company has to identify them, assess them and keep a record of them (Section 12 of the act). Until you have assessed an asset, it counts as in scope (Section 12(4)). That's why it pays to know which apps your people have actually built.

## What does the law ask of the apps you build?

Decree 410/2025 Coll. splits the measures into two groups. The mandatory minimum you always put in place (Section 3(1)(b)). For the others you can decide not to put them in place yet, but you have to justify that in your overview of security measures, with a date, a priority and a responsible person (Section 3(2) and the explanatory memorandum).

### The mandatory minimum
   Section 3(6)
#### Security requirements for development and maintenance

The apps your people build are development. You need rules for how they are made and changed, and you have to enforce them. On Fabrika the platform enforces them: apps can't get around sign-in, permissions, keys or deployment, and every change goes through our review.
  Section 3(5)
#### Supplier contracts

Contracts with whoever builds or runs your apps must cover the relevant points of Annex 2. The breakdown for Fabrika is below.
  Section 3(4)
#### Rules for using technical assets

How technical assets are used and handled. The apps are among them.
  Section 6
#### Business continuity and backups

The priority and order of recovery, who is responsible for what, and regular backups of data and configuration. More on that below.
  Section 10
#### Handling incidents

People report unusual behaviour, the company has a method for assessing incidents and reports those with significant impact.
  Sections 3–5
#### Leadership, policy and training

Top management names a person responsible for cyber security and gets trained. Add the overview of security measures, the security policy and training for people.

### Measures you either put in place or justify leaving out

Sections 7–9 and 11–13. Below are the ones that concern apps.

| Measure | What the decree asks | On Fabrika |
| --- | --- | --- |
| Section 7 Access control | What the decree asks
Only the permissions needed for the job. Remove or change access without delay when someone changes role or leaves. | On Fabrika
Roles per app, and you decide who gets which. People sign in with their company account, so for them you remove access in one place. |
| Section 8 Identity management | What the decree asks
Multi-factor authentication. Until then keys or certificates, and only after that a password with rules: at least 12 characters for users, 17 for administrators. | On Fabrika
With a company account (Google, Microsoft, Okta), multi-factor authentication applies as your company has it set up. |
| Section 9 Event logging | What the decree asks
A record with date and time including the time zone, the type of activity, the asset and the account, and whether it succeeded. You set the retention period yourself. | On Fabrika
Sign-ins are recorded, changes to access and roles are kept, and every deployment has its own record. Whether that covers your needs we go through together. |
| Section 11 Network security | What the decree asks
Network segmentation and limiting traffic at the perimeter to what the service needs. | On Fabrika
Apps have no public address; the only way in leads through the platform. Test and production environments each have their own network. |
| Section 12 Application security | What the decree asks
Apply security updates without delay, keep a record of unsupported assets, scan for vulnerabilities regularly. | On Fabrika
We patch the platform continuously. Fabrika doesn't promise regular vulnerability scanning on its own; if you run it, include the apps. |

### What the higher regime adds

Under Decree 409/2025 Coll. there is, among other things, change management with testing before going live and the option to return to the original state (Section 11(2)), separated production, backup, development and test environments (Section 12(1)(e)), and penetration tests based on the risk assessment (Section 24(5)).

## What has to be in the contract with a supplier?

Annex 2 of Decree 410/2025 Coll. lists 14 areas a supplier contract should address. The contract includes the ones that are relevant to the relationship (Section 3(5)). Here is how it works with Fabrika. Where only the contract gives the answer, we say so.

| Annex 2 point | What it means | How it works on Fabrika |
| --- | --- | --- |
| a) Information security | What it means
Confidentiality including non-disclosure, integrity and availability of data. | How it works on Fabrika
Your own installation, one gate, sign-in with your company account, roles per app, keys held by the cloud provider. Non-disclosure is in the contract. |
| b) Supplier audit | What it means
The right to check how the supplier fulfils the contract. | How it works on Fabrika
We agree the scope of an audit in the contract. We don't promise it in advance here. |
| c) Chain of suppliers | What it means
Who else takes part in delivering the service. | How it works on Fabrika
For Fabrika you have one supplier: us. The cloud account with Cloudflare, Zerops or AWS is registered to your company, so you have that relationship directly. The AI runs on your own plan. If a developer or agency builds for you, you hire them yourself. |
| d) Exit strategy | What it means
What happens to the data and the system when the cooperation ends. | How it works on Fabrika
The apps' code is yours, the data and the domains are in your account. The system keeps running without us, and the next person picks it up from Git. |
| e) Penalties | What it means
What the supplier faces for breaching the contract. | How it works on Fabrika
Set in the contract. |
| f) Right to use data | What it means
What the supplier may do with your data. | How it works on Fabrika
The data sits in your account. We access it to the extent we need for review, deployment and patches. Nothing is trained on your data. |
| g) Code authorship and licences | What it means
Who owns the code and what you hold a licence to. | How it works on Fabrika
The apps' code belongs to you. The terms for using the platform itself are set in the contract. |
| h) Confidentiality of the relationship | What it means
What either side may say about working together. | How it works on Fabrika
Set in the contract. |
| i) Your security policies | What it means
The supplier follows your rules, or you approve theirs. | How it works on Fabrika
Send us your rules for suppliers before signing. We'll tell you which of them we meet and agree how they go into the contract. |
| j) Change management | What it means
How the system changes and who approves it. | How it works on Fabrika
Every change goes through Git with an author, a time and a description. A person on our side reviews it before deployment, the deployment is recorded, and you get a report on what changed. |
| k) Incidents related to the contract | What it means
Who informs whom, and how both sides work together. | How it works on Fabrika
The platform collects errors and alerts on new ones or on a sudden spike. We help find out what happened, fix it and put together the documents for your report. The deadline for informing you is set in the contract. |
| l) Business continuity | What it means
How the supplier contributes to recovery after an outage. | How it works on Fabrika
We set up backups and recovery with you, to the extent you need. It's our service, not something the platform does on its own. |
| m) SLA and level of security measures | What it means
Which service parameters the supplier keeps. | How it works on Fabrika
Operations and change review come with an SLA. The specific parameters are in the contract. |
| n) Secure development | What it means
How the supplier prevents flaws while building. | How it works on Fabrika
Building with AI goes in phases, on the brief and the code, not on live data. Every change goes through our review. If your developer or agency builds, the same path applies to them. |

### In the higher regime

For significant suppliers, Annex 5 of Decree 409/2025 Coll. applies, with 18 points. It adds, for example, informing you about a change of ownership of the supplier, about a foreign authority requesting data, or about the people who come into contact with your confidential information. We go through those points one by one with your lawyer.

## Who backs up the apps' data?


> The company “makes regular backups of the information, data, configurations and settings of technical assets needed in particular to restore the regulated service in the event of a cyber security incident.”

*Decree 410/2025 Coll., Section 6(c) Backups are part of the mandatory minimum. They can't be left out with a justification.*
    ![](/illustrations/machine-warehouse.webp)
### What we do

We set up backups and recovery with you, to the extent you need: what gets backed up, how often, how long backups are kept and how quickly the data has to be back. It's our service, not something the platform does on its own, so we agree on the scope when we set up Fabrika.

### What's up to you

Deciding which apps take priority, in what order they are restored and who is responsible for it (Section 6(a) and (b), Section 4(f)).

### In the higher regime

You also set a recovery time and a recovery point for data, and test your recovery plans regularly (Decree 409/2025 Coll., Section 15). Bring those numbers along and we'll set up the backups to match.

## When and to whom do you report an incident?

In the lower regime you report to the National CERT an incident that showed up within the scope of the regulated service, originated in cyberspace, has a significant impact, and where intent can't be ruled out (Section 15(2) of the act). In the higher regime you report to NÚKIB even incidents without significant impact (Section 15(1)).

Significant impact means serious operational disruption or financial loss, or considerable harm to others (Section 15(3)). In the lower regime you set yourself the level of harm you can still bear, and assess incidents against it (Decree 410/2025 Coll., Section 14).
    ![](/illustrations/machine-timeclock.webp)
 1. 24 h
### Initial report

Without undue delay, no later than 24 hours after you detect the incident (Section 16(1)).
1. 72 h
### Notification

For an incident with significant impact: an initial assessment, the impact and indicators of compromise if you have them (Section 16(3)(a)).
1. 30 days
### Final report

No later than 30 days after the notification. If the incident is still ongoing by then, a progress report, and the final one within 30 days of resolving it (Section 16(3)(c)).

Reports go through the NÚKIB portal (Section 16(4)).

### What Fabrika does

The platform collects errors from all apps in one place and alerts on a new error or a sudden spike. We help find out what happened in the app, fix it, and put together the documents for the report. Assessing the impact and filing the report is up to you (Section 10 of Decree 410).

## What stays with you?

Fabrika won't make you compliant with the act. The platform enforces the rules for apps and we review every change. The legal duties belong to your company, and nobody else can do these for you:

 - Sections 6, 9, 11 of the act Notify the service and report changes to NÚKIB.
- Section 12 of the act Identify, assess and keep a record of your assets, including the apps.
- Section 3(2) Keep an overview of security measures and update it at least once a year.
- Section 3(3) and (6) Set the security policy and the rules for development, and enforce them.
- Sections 4 and 5 Name a person responsible for cyber security, and train leadership and staff.
- Section 4(f), Section 6 Decide the recovery priority and who is responsible for recovery.
- Section 7 Decide who gets which role in which app.
- Section 10, Section 16 of the act Assess an incident and file the report.

### What we give you for it

For the part that concerns the apps, we give you the technical groundwork: how sign-in, roles, records, change management and backups work. You can use it in your overview of security measures. We're happy to fill in your own security questionnaire too.

## When is Fabrika not for you?

From the NIS2 point of view, honestly:
  ![](/illustrations/spot-exit.webp)
### You want a supplier to make you compliant

We won't. Compliance is your company's duty. A cyber security consultant or an auditor will help you with the documentation and the overview of measures; we supply the groundwork for the apps.

### A supplier certification is a condition

If a certificate such as ISO 27001 or SOC 2 is a condition for choosing a supplier, ask about it right at the start of the first call, so nobody wastes time.

### You need penetration tests and rollback as part of the service

Neither penetration tests (Decree 409, Section 24) nor returning a deployment to its original state (Section 11) is something Fabrika promises today. In the higher regime, factor that in.

## What people ask about NIS2 and apps

### Does NIS2 cover internal apps too?

Yes, if they relate to the regulated service. The act covers assets within the defined scope (Section 12), and an app you haven't assessed yet counts as in scope (Section 12(4)). The decree then asks for security requirements for development and maintenance (Decree 410, Section 3(6)).

### What are the fines?

In the lower regime up to CZK 175 million or 1.4 % of worldwide annual turnover, whichever is higher. In the higher regime up to CZK 250 million or 2 %. This covers, among other things, not putting security measures in place and supplier contracts without the security requirements (Section 59 of the act). NÚKIB can also first order corrective measures (Section 56).

### Can leadership be banned from office?

Only in the higher regime. NÚKIB can ban a member of the statutory body from office, for at least six months, if they repeatedly or seriously breached their duties while the company was carrying out a corrective measure and thereby frustrated it (Section 58). The act doesn't allow this in the lower regime. The duties of leadership (training, resources, keeping up with the measures) apply there too (Decree 410, Section 4).

### We supply a regulated company. What can they ask of us?

The points of Annex 2 of Decree 410 that are relevant to your relationship, including in contracts you already have. If your customer is in the higher regime and you are a significant supplier for them, they tell you so in writing and the contract has to cover the points of Annex 5 of Decree 409 (Section 9).

### Do we have to use multi-factor authentication?

The decree asks for it (Section 8(2)), but in the lower regime it's among the measures you can leave out with a justification. Until you have it, fallback rules apply: keys or certificates, and only then a password of at least 12 characters for users and 17 for administrators (Section 8(3) and (4)). On Fabrika people sign in with their company account (Google, Microsoft, Okta), and multi-factor authentication applies as your company has it set up.

### How long do we have to keep records?

You set the period yourself, based on your security needs (Section 9(3)). The decree sets what a record contains: date and time with the time zone, type of activity, the asset and the account, and whether it succeeded (Section 9(2)). On Fabrika sign-ins are recorded, changes to access and roles are kept, and every deployment has a record. How that fits your requirements we go through together.

### Where does the data live?

In your company's cloud account, with Cloudflare or Zerops, or AWS if you prefer. Each company has its own installation and shares it with no one. Zerops is a Czech company with a data centre in Prague. With Cloudflare, we go through the region and the terms against your requirements. On AWS, we pick the region to match them.

### Will you make us NIS2 compliant?

No. Compliance is your company's duty and Fabrika won't take it over. For the apps we enforce the rules on the platform, review every change and give you the technical groundwork for your overview of security measures.
          ![](/illustrations/cta-crane.webp)
## Go through it with *our engineer*.

Bring your overview of security measures or your questionnaire for suppliers. In half an hour we'll go through what in it concerns the apps, what Fabrika handles and what stays with you.
  [Book a 30-min call →](https://cal.com/contember/demo) [Security on Fabrika →](/security) [For leadership →](/for-leadership)
### Sources

 - [Act No. 264/2025 Coll., on cyber security (Czech) ↗](https://www.zakonyprolidi.cz/cs/2025-264)
- [Decree No. 410/2025 Coll., lower regime (Czech) ↗](https://www.zakonyprolidi.cz/cs/2025-410)
- [Decree No. 409/2025 Coll., higher regime (Czech) ↗](https://www.zakonyprolidi.cz/cs/2025-409)
- [Explanatory memorandum to Decree 410, NÚKIB (Czech, PDF) ↗](https://portal.nukib.gov.cz/storage/uploads/2025/12/03/duvodova-zprava-vyhlaska-nizsi-rezim_uid_693039f42250d.pdf)

This isn't legal advice. The guide summarises the act and the decrees as they stood on 28 September 2026. Whether and how they apply to you is best assessed with your lawyer or auditor; we'll gladly give them the technical details.