EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Four-Level Cybersecurity Risk Assessment Cascade

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.25_26: Member State cybersecurity risk assessment (NCCS Articles 25-26) - third level of the cascade

Article 25 establishes the MEMBER STATE cybersecurity risk assessment - the third level of the four-level cascade. Member State competent authorities conduct national cybersecurity risk assessments for their in-scope electricity entities, building on the Union-wide + regional assessment outcomes. The Member State assessment addresses national-level cyber-threat landscape + national entity-classification + national cross-cutting cybersecurity risk-treatment priorities. Article 26 sets the methodology + data-source requirements, including coordination with national cybersecurity authorities (typically the NIS2 single point of contact + the national CSIRT). Member State assessments must be conducted at least every 3 years + updated after material national events.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in NCCS: Four-Level Cybersecurity Risk Assessment Cascade

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.