Article 17 establishes the UNION-WIDE cybersecurity risk assessment - the first level of the four-level cascade. The Union-wide risk assessment is conducted by ENTSO-E and the EU DSO Entity in coordination with ACER + ENISA + the EECCG + Member State competent authorities. The assessment identifies: (a) significant cybersecurity threats to cross-border electricity flows at Union level; (b) cybersecurity scenarios + their potential cross-border impact; (c) prioritised risk-treatment recommendations. The first Union-wide cybersecurity risk assessment must be conducted by 13 December 2026 (within 30 months of NCCS entry into force) + updated at least every 3 years thereafter OR after a major Union-wide cyber-incident. Article 18 sets the methodology + data-source requirements for the Union-wide assessment. Article 19 establishes the publication + dissemination regime for the Union-wide assessment results to the Member State competent authorities + the EECCG.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.