an incident concerning the provision of digital services in this Member State, without disclosing
the identification details of the reportee, and while maintaining the security and commercial
interests of the reportee
l)
Receives reports of cyber security incidents from public authorities and legal or natural persons
that are not specified in Section 3; governmental CERT processes the reports, and if its capabilities
allow it and is the report concerns a cyber security incident with a significant impact,
governmental CERT provides public authorities or legal or natural persons affected by a cyber
security incident with methodical support, help and cooperation
m) Fulfils the role of a CSIRT team according to relevant European Union legislation12)
n) Cooperates with CSIRT teams of other Member States.
CHAPTER III
State of cyber emergency
Section 21
(1) A state of cyber emergency is a state in which there is a high measure of threat to the security of
information of information systems or electronic communication network services or to the
security and integrity of electronic communication networks1), and this could lead to breaches or
threats to the interests of the Czech Republic in line with the meaning of the Act on the Protection
of Classified Information.
(2) The director of the Agency shall decide on the declaration of a state of cyber emergency. The
decision about the declaration of a state of cyber emergency is published on the official notice
board of the Agency. Information about the declaration of a state of cyber emergency is
announced in broadcast on national radio and television. The operator of the national television
or radio is obliged to immediately broadcast the information about the declaration of a state of
cyber emergency based on the request of the Agency without adjusting the content and without
reimbursement of incurred costs.
(3) The decision of the declaration of a state of cyber emergency comes into effect at the moment
set out in this decision. The state of cyber emergency is announced for a necessary period of time,
7 days at the longest. This period of time can be extended by the director of the Agency; the total
period of time for which the state of cyber emergency is declared shall not exceed 30 days.
(4) During the time in which the state of cyber emergency is declared, the director of the Agency shall
inform the government of remedial procedures adopted under the state of cyber emergency and
of the current status of threats which led to the declaration of the state of cyber emergency.
Under a state of cyber emergency and under a state of emergency4) in cases according to
paragraph 6, the Agency is entitled to issue a decision or a measure of general nature according
to Section 13 also to public authorities and legal or natural persons specified in Section 3, letters
a) and b).
(5) A state of cyber emergency cannot be declared when a threat to the security of information of
information systems or electronic communication network services or to the security and integrity