EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Common Electricity Cybersecurity Framework and Minimum/Advanced Controls

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.29_30_31: Common electricity cybersecurity framework and minimum cybersecurity controls (NCCS Articles 29-31) - for high-impact entities

Article 29 establishes the COMMON ELECTRICITY CYBERSECURITY FRAMEWORK - a sector-specific set of cybersecurity controls building on horizontal frameworks (NIS2 Article 21(2) + ISO/IEC 27001 + IEC 62443) but adapted to the electricity sector + cross-border flows + OT (operational technology) systems. Article 30 sets the MINIMUM CYBERSECURITY CONTROLS that all high-impact entities must implement, covering: (a) cybersecurity governance + organisational structure including a dedicated CISO function; (b) information security policy + standards; (c) risk management + asset management + change management; (d) human resources security + cybersecurity training; (e) identity + access management + privileged-access management; (f) cryptography + key management; (g) physical + environmental security; (h) communications + operations security; (i) supplier + supply-chain security; (j) incident management + business continuity; (k) audit + assurance + compliance monitoring. Article 31 establishes the implementation timeline: minimum controls must be in place within 24 months of entity-classification + reviewed + revised at least annually.

Other controls in NCCS: Common Electricity Cybersecurity Framework and Minimum/Advanced Controls

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.