INTERNATIONAL COOPERATION: CZ PRES AND THE NIS 2 DIRECTIVE Developments in the field of cybersecurity in the Czech Republic is largely connected to developments abroad and decisions made not only at the EU level, but also by international entities. The Czech Republic actively represented a number of international organizations and integration groups, especially in the EU, UN, NATO, OECD, OSCE, and ITU. European Union In the area of international cooperation, the year 2022 was particularly influenced by CZ PRES, which the Czech Republic took over for the second time in its history on July 1, 2022 for a period of six months. Therefore, the first half of 2022 was primarily dedicated to intensive preparations both in terms of content and organization and included a number of negotiations with partners at the national and EU level. Starting with the beginning of the Presidency, the Czech Republic worked on a number of legislative and non-legislative documents in the area of cybersecurity. A general approach of the EU Council was reached (a common position of all member states) on the proposal for a Regulation laying down measures to ensure a high common level of cybersecurity in the institutions, bodies, offices, and agencies of the Union. The draft regulation aims to increase the level of cybersecurity of EU entities, and thereby strengthen security across the EU. Negotiations have also begun on a draft of the Cyber Resilience Act8 which sets out cybersecurity requirements for a wide range of products with digital elements to ensure their cybersecurity throughout their lifecycle. National partners within the government as well as representatives of the private sector from areas which will be most affected by the regulation were consulted in autumn because the regulation will have a significant impact on the market for products containing digital elements. In addition to these legislative proposals, the Czech Republic also focused on strengthening the security of the information and communication technology (ICT) supply chain. The main success in this area was the adoption of the Council’s conclusions on the security of the ICT supply chain, which were initiated and negotiated at the EU Council by Czech representatives. By adopting these conclusions, all 27 member states confirmed the importance of ICT supply chain security and the need to strengthen it across the EU through the proposed steps. This is an important milestone for cybersecurity. However, several other issues were addressed at the EU Council, including, for example, a number of initiatives in the field of cyber diplomacy, where the NÚKIB worked closely with the Ministry of Foreign Affairs. The adoption of the NIS 2 directive was of fundamental importance for cybersecurity at the EU level and for the future design of national regulation. The contents of the Directive were negotiated in the first half of 2022, during the French Presidency of the EU Council. The final text of the NIS 2 Directive following language revisions was then adopted during the CZ PRES, at the end of 2022. The Directive is to become part of EU law within 21 months of coming into effect, meaning no later than October 2024. 8 Cyber Resilience Act 40

Select target paragraph3