f) Withdrawal notice period and reasons for the withdrawal g) Ban on the misuse of data acquired while performing activities specified in Section 17, paragraph 2 h) Definition of the conditions for the performance of the national CERT activities according to Section 17, paragraph 3 and i) Method for the data transfer and the extent of the data transferred to the Agency in the case of contract termination (3) The contract concluded according to paragraph 1 shall be published in the Official Journal of the Agency, except for the parts of the contract the publishing of which is not allowed by another legal regulation. (4) If the contract according to paragraph 1 is not concluded, or if the contract is terminated, the activity of the national CERT shall be performed by the Agency. Section 20 Governmental CERT Governmental CERT as a part of the Agency: a) Receives notices of contact details from public authorities and legal or natural persons specified in Section 3, letters c) to g) b) Receives reports on cyber security incidents from public authorities and legal or natural persons specified in Section 3, letters c) to g) c) Evaluates data on cyber security events and cyber security incidents from a critical information infrastructure, information system of essential service, important information systems and other information systems of public administration d) Provides public authorities and legal or natural persons specified in Section 3, letters c) to g) with methodical support and help e) Cooperates with public authorities and legal or natural persons specified in Section 3, letters c) to g) when a cyber security incident or a cyber security event occurs f) Receives suggestions and data from public authorities and legal or natural persons specified in Section 3, and from other authorities and legal or natural persons, and evaluates these suggestions and data g) Receives data from the operator of the national CERT and evaluates this data h) Receives data from public authorities that operate in the field of cyber security abroad and evaluates this data i) Provides data from the incident record according to Section 9, paragraph 4 to the operator of the national CERT, to public authorities operating in the field of cyber security abroad and to other legal or natural persons operating in the field of cyber security j) Carries out vulnerability analyses in the field of cyber security k) Informs the relevant public authority of another Member State of a cyber security incident with a significant impact on the continuity of the provision of essential services in this Member State, or

Select target paragraph3