b) Start fulfilling their obligation specified in Section 8, paragraphs 1 and 4 at the latest within 1 year
from the day on which their information or communications system was identified as a critical
information infrastructure
c) Introduce security measures according to Section 4, paragraph 2 at the latest within 1 year from
the day on which their information or communications system was identified as a critical
information infrastructure.
Section 31
Public authorities and legal or natural persons specified in Section 3, letter e) shall:
a) Send a notification of contact details according to Section 16 at the latest within 30 days from the
day on which their information system fulfilled the determination criteria to be identified as a
critical information infrastructure
b) Start fulfilling their obligation specified in Section 8, paragraphs 1 and 4 at the latest within 1 year
from the day on which the determination criteria of an important information system were
fulfilled
c) Introduce a security measure according to Section 4, paragraph 2 at the latest within 1 year from
the day on which the determination criteria of an important information system were fulfilled
Section 32
The activity of the national CERT shall be performed by the public authority or natural or legal person
that performed the activity which is performed by the national CERT according to this Act until the
public-law contract concluded according to Section 19 comes into effect, but no longer than within 2
years from the effective date of this Act.
Section 33
Common provisions
(1) This Act shall only apply to such information or communication systems of intelligence services
that fulfil the requirements for determining a critical information infrastructure in the extent of
Sections 12 and 16; the provisions of Section 4 shall be applied to these systems adequately and
the Agency shall not propose these to be critical infrastructure elements according to Section 22,
paragraph 2, letter m).
(2) This Act shall be applied to the information system of the Police of the Czech Republic and the
General Inspection of Security Forces for analytical activities in criminal proceedings only in the
extent of Sections 12 and 16; the provisions of Section 4 shall be applied to this system adequately.
This does not apply if the system is a critical information infrastructure.
(3) This Act shall only be applied to digital service providers that are legal persons and not a microenterprise or a small enterprise16.
(4) This Act shall not be applied for digital service providers with registered offices in another Member
State.