Act No. 412/2005 Coll., on the protection of classified information and on security capability shall be stored in § 34 the obligation to use information systems certified by the National Cyber and Information Security Authority for handling classified information. Certification of information systems is carried out according to § 46 a § 48 the said Act and pursuant to § 24, § 25 and § 26 of the Decree No. 523/2005 Coll., on the security of information and communication systems and other electronic equipment handling classified information and on the certification of shielding chambers.

An application for certification of an information system shall contain:

  • Applicant identification
  • the name and surname of the applicant’s liaison officer and contact details;
  • a brief description of the purpose and scope of the information system,
  • the classification level of the classified information to be handled by the information system;
  • the determination of the security operating mode of the information system; and
  • identification of the supplier of the information system or its components affecting the security of the information system.

In order to carry out the certification of the information system, the applicant shall submit the following documents:

  • the security policy of the information system and the results of the risk analysis,
  • a proposal for the security of the information system,
  • set of information system security tests, their description and description of test results,
  • information system security operational documentation,
  • a description of the safety of the development environment; and
  • other documents necessary for the certification of the information system, resulting from the specification of the information system.

The National Cyber and Information Security Authority shall evaluate the appropriateness of the set of measures proposed to achieve the security of the information system, the correctness and completeness of the information system security documentation and the correctness of the implementation of the proposed set of measures. The evaluation shall be carried out on the basis of the documentation submitted by the applicant and security tests in the operational environment of the evaluated information system.

Where the National Cyber and Information Security Authority ascertains the capability of an information system to protect classified information, it shall issue an information system certificate for that system. Otherwise, it will decide not to issue a certificate. An appeal shall not be admissible against a decision not to issue an information system certificate.

The validity of an information system certificate shall be limited to Top Secret and Secret 2 years, Confidential 3 years and Reserved 5 years.

If the information system is to be used immediately after the expiry of its certificate, the applicant is obliged to apply to the Office for certification of the information system at least 6 months before the expiry of the original certificate of the information system.

An information system certificate issued pursuant to Act No. 148/1998 Coll. shall be considered as an information system certificate pursuant to the Act for the period of validity specified therein. No. 412/2005 Coll.

The certificate of the information system, which was issued before 1.8.2017 by the National Security Authority, remains valid for the period of validity specified therein.

Certification of the information system started before 1.8.2017 by the National Security Authority will be completed by the National Cyber and Information Security Authority.