system of critical information infrastructure, in their information system of essential service or in
their important information system.
Section 8
Cyber security incident reporting
(1) Public authorities and legal or natural persons specified in Section 3, letters b) to f) are obliged to
report cyber security incidents in their important network, in their information or communication
system of critical information infrastructure, or in their important information system
immediately after their detection; this shall not affect their obligation to provide information
according to another legal regulation3) or directly applicable European Union regulation governing
personal data protection11). If the cyber security incident has a significant impact on the continuity
of the provision of an essential service, the essential service operator shall inform the Agency of
this fact.
(2) A digital service provider is obliged to report a cyber security incident with a significant impact on
the provision of their services without undue delay if they have access to the information for the
assessment of the importance of the incident.
(3) Public authorities and legal or natural persons specified in 3, letters b) and h) shall report cyber
security incidents to the operator of the national CERT.
(4) Public authorities and legal or natural persons specified in Section 3, letters c) to g) shall report
cyber security incidents to the Agency.
(5) The obligation according to paragraph 1 is also fulfilled by the operator of an information or
communication system of a critical information infrastructure, or the operator of an important
information system, when a cyber security incident is reported by the administrator of this
system. The administrator of the information or communication system of a critical information
infrastructure or the administrator of an important information system shall inform the operators
of this system of the reported cyber security incidents without undue delay.
(6) Public authorities and legal or natural persons not specified in Section 3 may report cyber security
incidents to the operator of the national CERT or to the Agency.
(7) The implementing legal regulation shall set out the following:
a) The type, category and assessment of the importance of a cyber security incident
b) Requirements and the method of cyber security incident reporting
(8) If a cyber security incident that affected a digital service provider has a significant impact on the
continuity of an essential service provision, the operator of the essential service is obliged to
inform the Agency of this fact.
Record keeping
Section 9
(1) The Agency keeps a cyber security incident record (hereinafter “the incident record”) which
contains:
a) A cyber security incident report