Article 27 establishes the ENTITY-LEVEL cybersecurity risk assessment - the fourth and most granular level of the four-level cascade. Each high-impact + critical-impact entity must conduct its own entity-level cybersecurity risk assessment, addressing: (a) entity-specific cybersecurity threats + attack scenarios; (b) entity-specific asset inventory + criticality assessment; (c) cybersecurity controls implementation + maturity; (d) supply-chain cybersecurity exposure; (e) cross-border interconnection-related risks. Article 28 sets the methodology + content requirements: entity-level assessments must build on the Union-wide + regional + Member State assessments above + use the Article 8 joint methodology. Entity-level assessments must be conducted ANNUALLY + updated after major incidents + significant changes to the entity's infrastructure + cyber-attack surface. The results feed back upward into the Member State + regional + Union-wide assessments.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.