CYBERSECURITY LEGISLATION: DRAFTING THE
NEW CYBERSECURITY LAW
Identification and Review of Critical Information Infrastructure, Critical Information Systems,
and Essential Services Information Systems
Identification of CII has been carried out by the NÚKIB since 2015 on the basis of the authorization
specified in the Cybersecurity Act and the Crisis Act, in accordance with Government Regulation No.
432/2010, on criteria for determining an element of critical infrastructure, as amended. The Cybersecurity
Act also requires the NÚKIB every two years to verify that the identification of CII elements is up to date.
A CII element is defined as any information or communication system meeting the criteria provided in
the above-mentioned regulation, which determine its importance for maintaining the vital functions of
the state. The administrators of CII elements are both public and private entities.
The NÚKIB identified new and reviewed existing CII elements in 2022, during which 14 new
CII administrators were appointed in both private and public sectors and elements of 19 CII
administrators appointed in previous years were reviewed. As of December 31, 2022, the
NÚKIB registered a total of 66 entities managing 128 CII elements (see Graph 30).
CII Subjects
150
50
50
45
113
112
110
100
49
120
116
50
CII Elements
131
128
66
61
52
0
2016
2017
2018
2019
2020
2021
2022
Graph 30: CII Subjects and Elements from 2016 to 2022
The process of identifying Basic Service Providers (PZS) and their Basic Service Information
Systems (ISZS) also continued. In 2022, 31 new operators of basic service were identified, while
9 administrative proceedings concluded with the decision not to make this designation. Thus,
the NÚKIB currently recognizes a total of 155 basic service operators, which together manage
192 basic service information systems (see Graph 31).
PZS Operators
ISZS Elements
192
200
150
124
100
50
30 30
38 42
2018
2019
147
155
56 61
0
2020
2021
Graph 31: PSZ and ISZS Entities and Elements from 2018 to 2022
33
2022