EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Four-Level Cybersecurity Risk Assessment Cascade

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.27_28: Entity-level cybersecurity risk assessment (NCCS Articles 27-28) - fourth level of the cascade

Article 27 establishes the ENTITY-LEVEL cybersecurity risk assessment - the fourth and most granular level of the four-level cascade. Each high-impact + critical-impact entity must conduct its own entity-level cybersecurity risk assessment, addressing: (a) entity-specific cybersecurity threats + attack scenarios; (b) entity-specific asset inventory + criticality assessment; (c) cybersecurity controls implementation + maturity; (d) supply-chain cybersecurity exposure; (e) cross-border interconnection-related risks. Article 28 sets the methodology + content requirements: entity-level assessments must build on the Union-wide + regional + Member State assessments above + use the Article 8 joint methodology. Entity-level assessments must be conducted ANNUALLY + updated after major incidents + significant changes to the entity's infrastructure + cyber-attack surface. The results feed back upward into the Member State + regional + Union-wide assessments.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in NCCS: Four-Level Cybersecurity Risk Assessment Cascade

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.