Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

XRENN Labs s.r.o.

NIS2 / ZKB / ISO 27001

Clear obligations. Security in practice.

Understand what applies to your organisation. We connect NIS2 / ZKB and ISO 27001 requirements with risk management, implemented controls and evidence you can present at an audit.

For businesses, nonprofits and public administration.

Evidence of implementation

Know what you can demonstrate.

The outputs we build with your team.

  • Risks & priorities

    A risk register and a prioritised remediation plan.

  • Policies & responsibilities

    Documented processes, clear roles and control owners.

  • People & operations

    Training records and evidence that controls are in place.

  • Review & improvement

    Internal audit findings and reporting for management.

One coordinated programme

Obligations meet operations.

We coordinate regulatory readiness and information security management around the same risks, people and evidence.

NIS2 & ZKB

Understand your obligations. Implement the measures.

Applicability assessment
We assess your services and organisation to identify applicable requirements.
Risk and incident management
Security policies, continuity plans, reporting workflows and supplier requirements.
Readiness for inspection
Training, internal reviews and organised evidence of implemented measures.

ISO 27001 & ISMS

Build a system your organisation can maintain.

Gap analysis
We review documentation, risks and implemented Annex A controls.
ISMS implementation
Policies, risk treatment, responsibilities and processes adapted to your operations.
Preparation for certification
Internal and pre-certification audits, corrective actions and management review.
From assessment to evidence

A clear process. Concrete outputs.

We begin with your current situation. The findings determine the scope, priorities and implementation schedule.

Entry audit & gap analysis

An applicability assessment, risk profile and remediation roadmap, presented to your management.

9 900 Kčexcl. VAT · one-time delivery
Delivery10–15 business days
  1. 01

    Assess the starting point

    Interviews, documentation review and an assessment of existing controls.

    Audit report, gaps and risk priorities.

  2. 02

    Agree on the plan

    We define the scope, owners, budget and milestones with your team.

    A remediation roadmap and implementation schedule.

  3. 03

    Implement and train

    We prepare policies, establish processes and support technical controls.

    Documentation, training records and implementation evidence.

  4. 04

    Verify and hand over

    We review effectiveness, identify remaining gaps and agree on follow-up support.

    Audit findings, corrective actions and management reporting.

Implementation packages

Choose the depth of support.

From core documentation to technical integration. We confirm the right package and any individual adjustments after the entry audit.

Core Documentation

START

49 000 Kč

one-time implementation · excl. VAT

Core security policy, risk management plan, BCP/DR, NÚKIB/CSIRT incident reporting workflow and leadership (4h) & IT (8h) training.

Select START
Recommended for SMB

BUSINESS

129 000 Kč

one-time implementation · excl. VAT

Everything in START + operational SOPs (patching, PAM, change mgmt), quarterly internal audits, simulated NÚKIB regulatory audit, SIEM integration and annual phishing training.

Select BUSINESS
Maximum Protection

COMPLETE

249 000 Kč

one-time implementation · excl. VAT

Everything in BUSINESS + XRENN™ EdgeGuardian NIS2 offline AI hardware appliance, continuous network anomaly detection, automated audit logging and monthly executive dashboard.

Select COMPLETE
Ongoing compliance

Keep your readiness current.

Your organisation, suppliers and threats change. Monthly support keeps documentation, priorities and management decisions connected to those changes.

Connect the programme with penetration testing, staff training or EdgeGuardian integration as your needs grow.

BASIC Retainer

2 900 Kč / month · excl. VAT

Legislative monitoring (NIS2, ZKB, ISO 27001), email support with 1-business-day SLA, and quarterly priority summary.

PRO Retainer

7 900 Kč / month · excl. VAT

Everything in BASIC + monthly 1-on-1 consultations (1h/mo), continuous policy revisions, risk adaptation and active OSINT monitoring and reporting (up to 10 domains included).

ELITE Retainer

19 900 Kč / month · excl. VAT

Everything in PRO + weekly executive steering (30m/week), guaranteed 4-hour SLA, full outsourced compliance governance and regulator representation.

Active service

Add an outside view with OSINT.

Regular domain monitoring and reporting for up to 10 domains is included in PRO and ELITE. For the entry audit and BASIC, it is available as an optional monthly add-on.

Optional add-on: 500 Kč / month · excl. VAT

Monitoring for up to 100 assets is planned and cannot be ordered yet.

Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.