Article 1 establishes the subject matter: NCCS lays down sector-specific rules for cybersecurity aspects of cross-border electricity flows, including rules on common minimum cybersecurity requirements + planning + monitoring + reporting + crisis management. Article 2 sets the scope: applies to in-scope electricity entities including ENTSO-E, EU DSO Entity, transmission system operators (TSOs), distribution system operators (DSOs), nominated electricity market operators (NEMOs), regional coordination centres (RCCs), and the providers of essential services and ICT services for those entities. NCCS does NOT apply to entities falling exclusively within the scope of the NIS2 Directive (Directive (EU) 2022/2555) without cross-border flow dimension, but applies CUMULATIVELY for entities subject to both NIS2 + NCCS. Article 3 contains the key definitions including: 'high-impact entity', 'critical-impact entity', 'cross-border electricity flow', 'cybersecurity risk assessment', 'cybersecurity controls', 'incident', 'cyber-attack', 'crisis', 'electricity cybersecurity competent authority', 'information protection level'.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.