Coordinated vulnerability disclosures
⁶ Directive
(EU) 2022/2555 of the European
Parliament and of the Council of December
14, 2022, on measures for a common high
level of cybersecurity across the Union, amen-
NÚKIB finalised its draft of the national coordinated vulnerability disclosure policy
(CVD), including a detailed legal analysis of its relevant legal aspects. The NIS 2
Directive, which came into force at the end of 2022, introduced specific CVD obligations for EU member states.⁶
ding Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive
(EU) 2016/1148.
These were taken into account in NÚKIB’s draft of the new Act on Cybersecurity,
designating the Government CERT as the CVD coordinator, allowing any person to
anonymously report vulnerabilities in ICT products.
Legislative anchoring:
The new Act on Cybersecurity
The NIS 2 Directive, published at the end of 2022, expands the degree of harmonisation of cybersecurity regulation in the European Union, necessitating significant
revisions to the Czech Republic’s current statutory framework for cybersecurity.
Due to the extensive changes introduced by NIS 2 that must be transposed into
national law, a decision was made to draft a new Act rather than amend the existing one. This new legislation, initiated by NÚKIB, integrates insights gained from
the application of Act No. 181/2014 Coll. and feedback from entities governed by
its provisions.
As in the previous year, the main themes in 2023 were negotiations and drafting of
the new law, consultations with stakeholders (regulated entities and administrators
of regulated sectors) and the public, and the launch of the formal legislative process.
NÚKIB also continued a comprehensive information campaign on the draft law
through dedicated websites, lectures and responses to numerous enquiries.
European cybersecurity
certification schemes
The introduction of European cybersecurity certification schemes represents a step towards unifying and
strengthening security standards in
the European Union’s digital space.
Three certification schemes are being developed: EUCC (European Union Common
Cybersecurity Certification Scheme on Common Criteria), EUCS (European Cybersecurity Cloud Certification Scheme) and EU5G (EU 5G Cybersecurity Certification Scheme).
Steady progress was made throughout 2023, culminating in the publication of the
EUCC Implementation Act (IA EUCC) at the end of January 2024. Discussions regarding the draft candidate EUCS are ongoing at the ECCG (European Cybersecurity
Certification Group) level, and the 5G candidate scheme is expected to be presented during 2024.
41