In 2022, another part of the Decree for Significant information systems came into effect and adding two new types of information systems to national regulation that are present in the majority of state organisations: information systems ensuring the performance of the filing service and the management of the electronic notice board. Thus, the number of significant information systems (SIS) grew from 372 (in 162 entities) to 588 significant information systems (in 193 entities). For 2023, the NÚKIB estimates an increase in the number of significant information systems to a total of 690 (see Graph 32). Significant Information Systems 800 Number of SIS Operators 690 600 588 400 200 372 176 72 0 2020 193 193 162 2021 2022 2023 Graph 32: Numbers of SIS from 2020 to 2022 and Projection for 2023 New Cybersecurity Act The NÚKIB’s most fundamental activity in the regulatory field was its work on the draft of the new Cybersecurity Law and implementing regulations in connection with Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). As part of preparations for this fundamental legislative change, which is expected to take effect in autumn 2024, five internal expert groups were established in which over 40 NÚKIB employees prepared drafts of the new Cybersecurity Act and its implementing regulations. In addition, first rounds of consultations with the experts were launched. Moreover, 25 chambers, associations, and unions representing entities that are or will be affected by this cybersecurity regulation were addressed. Every union or association was given an introduction to the future regulation and the option to participate the first round of comments. Additional negotiations and publication of complete drafts of the legislation text will took place in 2023. In connection with the upcoming legislative changes, a specialized website focused on the NIS 2 directive and its impact on national regulation was also launched (see Nová směrnice EU o bezpečnosti sítí a informací). 34

Select target paragraph3