In 2022, another part of the Decree for Significant information systems came into effect and
adding two new types of information systems to national regulation that are present in the
majority of state organisations: information systems ensuring the performance of the filing
service and the management of the electronic notice board. Thus, the number of significant
information systems (SIS) grew from 372 (in 162 entities) to 588 significant information systems
(in 193 entities). For 2023, the NÚKIB estimates an increase in the number of significant
information systems to a total of 690 (see Graph 32).
Significant Information Systems
800
Number of SIS Operators
690
600
588
400
200
372
176
72
0
2020
193
193
162
2021
2022
2023
Graph 32: Numbers of SIS from 2020 to 2022 and Projection for 2023
New Cybersecurity Act
The NÚKIB’s most fundamental activity in the regulatory field was its work on the draft of
the new Cybersecurity Law and implementing regulations in connection with Directive
(EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on
measures for a high common level of cybersecurity across the Union, amending Regulation
(EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS
2 Directive).
As part of preparations for this fundamental legislative change, which is expected to take effect
in autumn 2024, five internal expert groups were established in which over 40 NÚKIB employees
prepared drafts of the new Cybersecurity Act and its implementing regulations. In addition, first
rounds of consultations with the experts were launched. Moreover, 25 chambers, associations,
and unions representing entities that are or will be affected by this cybersecurity regulation were
addressed. Every union or association was given an introduction to the future regulation and the
option to participate the first round of comments. Additional negotiations and publication of
complete drafts of the legislation text will took place in 2023.
In connection with the upcoming legislative changes, a specialized website focused on the NIS
2 directive and its impact on national regulation was also launched (see Nová směrnice EU
o bezpečnosti sítí a informací).
34