European Cybersecurity Certification
In 2022, within the sector of European cybersecurity certifications based on Regulation (EU)
2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (“European
Union Agency for Cybersecurity”), on the certification of cybersecurity of information and
communication technologies and repealing the Regulation (EU) No. 526/2013 (“Cybersecurity
Act”), the NÚKIB was established as a national cybersecurity certification body, namely by
Act No. 226/2022 Coll., which amends Act No. 181/2014 Coll., on cybersecurity and on the
amendment of related laws (Cybersecurity Law), as amended. In addition, the Law regulates
certain aspects of the administrative procedure for so-called authorization and establishes the
facts of offences consisting of violations of the obligations set out in the Cybersecurity Act.
In autumn, a strategy for securing European cybersecurity certifications was developed, focusing
not only on fulfilling the tasks arising from Article 58 of the Cybersecurity Act, but also on
facilitating the establishment of certification bodies and testing laboratories in accordance with
the NÚKIB Development Concept. A micro website for European cybersecurity certifications
was created at the turn of 2022 and 2023 (EU Certifikace). The contents of the micro website
is designed to provide basic information about European cybersecurity certifications, but also
resources with more detailed information.
Legislative Changes in Cloud Computing and Assessment of Security
Compliance
Ministry of the Interior of the Czech Republic has been assessing cloud computing providers and
cloud computing services since August 2020. The NÚKIB performs an assessment of security
criteria that cloud computing providers must meet in order to be allowed to provide services for
the public sector.
In 2022, the NÚKIB carried out 43 assessments in accordance with the transitional stipulations
of the legal status valid until September 1, 2021. According to the legislation effective from
September 1, 2021, it also carried out 46 assessments of cloud computing providers on their
ability to ensure the basic level of protection of confidentiality, integrity, and availability of
information in the public sector institutions. Finally, 27 assessments evaluating the aspects
such as public order, security, and compliance with the rights of third-party persons were also
completed.
35