ANNEX 1: EVALUATION OF THE ACTION PLAN
FOR THE NATIONAL CYBER SECURITY STRATEGY
OF THE CZECH REPUBLIC FOR 2022
Year 2022 was the second year of evaluation of the Action Plan for the National Cyber Security
Strategy of the Czech Republic for the period 2021 to 2025 (hereinafter referred to as the
“Action Plan”). The NÚKIB not only coordinates the evaluation of the entire Action Plan, but
also participates as a managing and co-operating entity in the implementation of 101 out of
105 tasks. In 2022, 88 tasks were subject to evaluation. 73 of these tasks are being completed
continuously.
In 2022, 77 of the evaluated tasks were met or are being continuously reached. 9 tasks were met
partially, and only 2 tasks were assessed as unfulfilled. Compared to 2021 (8 partially completed,
0 uncompleted tasks), this means a slight decrease in the success rate of the Action Plan. An
example of a task scheduled and completed in 2022 is to develop a methodological document
on supplier security management and provide it to authorities and persons obligated under the
Cybersecurity Act. In consultation with the Ministry of Finance, the Ministry of the Interior, and
the Ministry of Industry and Trade, the NÚKIB prepared a methodological document, which also
took into account the supporting materials of the Ministry of Regional Development concerning
public procurement. This resulted in a document dealing with the management of suppliers
throughout the entire life cycle of the supply, taking into account the specifics of supplier
relationships under Act No. 134/2016 Coll., on public procurement, as amended. In December
2022, the document was sent to relevant entities, and will be published on the NÚKIB website
during 2023. On the other hand, an example of a task not yet completed was the creation and
organization of exercises in the field of cybersecurity for foreign partners of the Czech Republic
in coordination and synergy with other Czech international activities. Although the NÚKIB
participated in international exercises in the field of cybersecurity in the past year, no specific
exercises designed for foreign partners took place.
The main reason negatively influencing the implementation of the Action Plan were the
Russian invasion of Ukraine and the resulting deterioration of the security situation, which
depleted personnel and other capacities for more immediate and urgent tasks. The preparation
and implementation of the historically second CZ PRES was the second factor, which, especially
in the second half of the year, occupied a significant part of the staff capacity, especially in the
area of international cooperation. An example of a task which was delayed due to CZ PRES was
to create an overview of the implementation of non-binding norms of responsible behaviour of
states in cyberspace and actively participate in the promotion of their compliance, preventing
their dilution and weakening, including in the area of respect for human rights among others.
Although cooperation with relevant institutions took place at the national level under the
coordination of the Ministry of Foreign Affairs, a comprehensive overview of non-binding
standards was not created by the end of the year. Partially fulfilled and unfulfilled tasks will
continue to be worked on in 2023 so that they are fully completed.
45