ANNEX 1: EVALUATION OF THE ACTION PLAN FOR THE NATIONAL CYBER SECURITY STRATEGY OF THE CZECH REPUBLIC FOR 2022 Year 2022 was the second year of evaluation of the Action Plan for the National Cyber Security Strategy of the Czech Republic for the period 2021 to 2025 (hereinafter referred to as the “Action Plan”). The NÚKIB not only coordinates the evaluation of the entire Action Plan, but also participates as a managing and co-operating entity in the implementation of 101 out of 105 tasks. In 2022, 88 tasks were subject to evaluation. 73 of these tasks are being completed continuously. In 2022, 77 of the evaluated tasks were met or are being continuously reached. 9 tasks were met partially, and only 2 tasks were assessed as unfulfilled. Compared to 2021 (8 partially completed, 0 uncompleted tasks), this means a slight decrease in the success rate of the Action Plan. An example of a task scheduled and completed in 2022 is to develop a methodological document on supplier security management and provide it to authorities and persons obligated under the Cybersecurity Act. In consultation with the Ministry of Finance, the Ministry of the Interior, and the Ministry of Industry and Trade, the NÚKIB prepared a methodological document, which also took into account the supporting materials of the Ministry of Regional Development concerning public procurement. This resulted in a document dealing with the management of suppliers throughout the entire life cycle of the supply, taking into account the specifics of supplier relationships under Act No. 134/2016 Coll., on public procurement, as amended. In December 2022, the document was sent to relevant entities, and will be published on the NÚKIB website during 2023. On the other hand, an example of a task not yet completed was the creation and organization of exercises in the field of cybersecurity for foreign partners of the Czech Republic in coordination and synergy with other Czech international activities. Although the NÚKIB participated in international exercises in the field of cybersecurity in the past year, no specific exercises designed for foreign partners took place. The main reason negatively influencing the implementation of the Action Plan were the Russian invasion of Ukraine and the resulting deterioration of the security situation, which depleted personnel and other capacities for more immediate and urgent tasks. The preparation and implementation of the historically second CZ PRES was the second factor, which, especially in the second half of the year, occupied a significant part of the staff capacity, especially in the area of international cooperation. An example of a task which was delayed due to CZ PRES was to create an overview of the implementation of non-binding norms of responsible behaviour of states in cyberspace and actively participate in the promotion of their compliance, preventing their dilution and weakening, including in the area of respect for human rights among others. Although cooperation with relevant institutions took place at the national level under the coordination of the Ministry of Foreign Affairs, a comprehensive overview of non-binding standards was not created by the end of the year. Partially fulfilled and unfulfilled tasks will continue to be worked on in 2023 so that they are fully completed. 45

Select target paragraph3