3) analyses the trends of improvement of cyber security assurance, delivers conclusions
and proposals with regard to cyber incident management to Cyber Security Actors;
4) provides recommendations to the Cyber Security Actors with regard to enhancement
of cyber security.
Article 8. National Cyber Security Centre
1. The National Cyber Security Centre is an institution, which is subordinate to the
Ministry of National Defence.
2. When implementing the cyber security policy, the National Cyber Security Centre:
1) conducts the supervision of compliance of the cyber security entities and
communications and information systems managed by them with organisational and technical
cyber security requirements imposed on cyber security entities as well as carries out survey on
the cyber security situation;
2) gives orders to cyber security entities to provide information necessary for the
compliance of the cyber security entities and communications and information systems managed
by them with organisational and technical cyber security requirements imposed on cyber security
entities, and to conduct the assessment of the cyber security situation;
3) applies technical measures so as to measure the resistance of the state’s information
resources and critical information infrastructures to cyber incidents;
4) gives orders in relation to assurance of cyber security and removal of identified cyber
security defects, sets the deadline for the fulfilment of orders by the entities which control and/or
manage the state’s information resources, by managers of critical information infrastructure,
providers of public communications networks and/or public electronic relations services and
digital information hosting service providers;
5) gives directions to cyber security entities, excluding digital service providers, to
conduct an independent communications and information systems or services provided using
such systems at their own expense and deliver the results of such audit, if they fail to provide
technical information necessary for the assessment of the cyber security situation with regard to
communications and information systems or services provided using such systems as set forth in
the description of organisation and technical cyber security requirements imposed on cyber
security entities;
6) upon receipt of evidence from a cyber security entity, a user of digital service or any
other EU Member State in which digital services are provided, from a competent authority which
supervises the activities of digital service providers in the field of cyber security which states
that digital service providers fail to meet the requirements laid down in this law, gives directions