b) Start fulfilling their obligation specified in Section 8, paragraphs 1 and 4 at the latest within 1 year from the day on which their information or communications system was identified as a critical information infrastructure c) Introduce security measures according to Section 4, paragraph 2 at the latest within 1 year from the day on which their information or communications system was identified as a critical information infrastructure. Section 31 Public authorities and legal or natural persons specified in Section 3, letter e) shall: a) Send a notification of contact details according to Section 16 at the latest within 30 days from the day on which their information system fulfilled the determination criteria to be identified as a critical information infrastructure b) Start fulfilling their obligation specified in Section 8, paragraphs 1 and 4 at the latest within 1 year from the day on which the determination criteria of an important information system were fulfilled c) Introduce a security measure according to Section 4, paragraph 2 at the latest within 1 year from the day on which the determination criteria of an important information system were fulfilled Section 32 The activity of the national CERT shall be performed by the public authority or natural or legal person that performed the activity which is performed by the national CERT according to this Act until the public-law contract concluded according to Section 19 comes into effect, but no longer than within 2 years from the effective date of this Act. Section 33 Common provisions (1) This Act shall only apply to such information or communication systems of intelligence services that fulfil the requirements for determining a critical information infrastructure in the extent of Sections 12 and 16; the provisions of Section 4 shall be applied to these systems adequately and the Agency shall not propose these to be critical infrastructure elements according to Section 22, paragraph 2, letter m). (2) This Act shall be applied to the information system of the Police of the Czech Republic and the General Inspection of Security Forces for analytical activities in criminal proceedings only in the extent of Sections 12 and 16; the provisions of Section 4 shall be applied to this system adequately. This does not apply if the system is a critical information infrastructure. (3) This Act shall only be applied to digital service providers that are legal persons and not a microenterprise or a small enterprise16. (4) This Act shall not be applied for digital service providers with registered offices in another Member State.

Select target paragraph3