Coordinated vulnerability disclosures ⁶ Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022, on measures for a common high level of cybersecurity across the Union, amen- NÚKIB finalised its draft of the national coordinated vulnerability disclosure policy (CVD), including a detailed legal analysis of its relevant legal aspects. The NIS 2 Directive, which came into force at the end of 2022, introduced specific CVD obligations for EU member states.⁶ ding Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148. These were taken into account in NÚKIB’s draft of the new Act on Cybersecurity, designating the Government CERT as the CVD coordinator, allowing any person to anonymously report vulnerabilities in ICT products. Legislative anchoring: The new Act on Cybersecurity The NIS 2 Directive, published at the end of 2022, expands the degree of harmonisation of cybersecurity regulation in the European Union, necessitating significant revisions to the Czech Republic’s current statutory framework for cybersecurity. Due to the extensive changes introduced by NIS 2 that must be transposed into national law, a decision was made to draft a new Act rather than amend the existing one. This new legislation, initiated by NÚKIB, integrates insights gained from the application of Act No. 181/2014 Coll. and feedback from entities governed by its provisions. As in the previous year, the main themes in 2023 were negotiations and drafting of the new law, consultations with stakeholders (regulated entities and administrators of regulated sectors) and the public, and the launch of the formal legislative process. NÚKIB also continued a comprehensive information campaign on the draft law through dedicated websites, lectures and responses to numerous enquiries. European cybersecurity certification schemes The introduction of European cybersecurity certification schemes represents a step towards unifying and strengthening security standards in the European Union’s digital space. Three certification schemes are being developed: EUCC (European Union Common Cybersecurity Certification Scheme on Common Criteria), EUCS (European Cybersecurity Cloud Certification Scheme) and EU5G (EU 5G Cybersecurity Certification Scheme). Steady progress was made throughout 2023, culminating in the publication of the EUCC Implementation Act (IA EUCC) at the end of January 2024. Discussions regarding the draft candidate EUCS are ongoing at the ECCG (European Cybersecurity Certification Group) level, and the 5G candidate scheme is expected to be presented during 2024. 41

Select target paragraph3