Article 25 requires the Commission to evaluate the Regulation by 5 February 2027 (initial early assessment focused on Hub deployment and Reserve operationalisation), and to carry out a comprehensive evaluation every four years thereafter. The evaluation considers cyber-threat-landscape evolution, Reserve utilisation, Member-State capability gains, and the case for scope or budget adjustments.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.