Article 25 establishes the MEMBER STATE cybersecurity risk assessment - the third level of the four-level cascade. Member State competent authorities conduct national cybersecurity risk assessments for their in-scope electricity entities, building on the Union-wide + regional assessment outcomes. The Member State assessment addresses national-level cyber-threat landscape + national entity-classification + national cross-cutting cybersecurity risk-treatment priorities. Article 26 sets the methodology + data-source requirements, including coordination with national cybersecurity authorities (typically the NIS2 single point of contact + the national CSIRT). Member State assessments must be conducted at least every 3 years + updated after material national events.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.