EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Four-Level Cybersecurity Risk Assessment Cascade

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.23_24: Regional cybersecurity risk assessment (NCCS Articles 23-24) - second level of the cascade

Article 23 establishes the REGIONAL cybersecurity risk assessment - the second level of the four-level cascade. Regional assessments are conducted by the Regional Coordination Centres (RCCs) per regulation 2019/943 in coordination with ENTSO-E + the EU DSO Entity + regional Member State competent authorities. The regional assessment addresses cross-border interconnection risks + regional electricity market coupling risks + sub-Union cyber-incident scenarios. Article 24 establishes the methodology + data-source requirements for regional assessments, building on the Union-wide assessment outcomes. Regional assessments must be conducted at least every 3 years AND on the same cycle as the Union-wide assessment + updated after material regional events (new interconnections + significant market-coupling changes).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in NCCS: Four-Level Cybersecurity Risk Assessment Cascade

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.