EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Common Electricity Cybersecurity Framework and Minimum/Advanced Controls

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.32_33_34: Advanced cybersecurity controls (NCCS Articles 32-34) - for critical-impact entities

Article 32 establishes the ADVANCED CYBERSECURITY CONTROLS that critical-impact entities must implement IN ADDITION TO the Article 30 minimum controls. Advanced controls cover: (a) advanced threat-detection + threat-hunting + cyber-threat intelligence integration; (b) red-teaming + advanced penetration testing including TIBER-EU-style threat-led penetration testing for the electricity sector; (c) advanced supply-chain cybersecurity including coordinated vulnerability disclosure + software bill of materials (SBOM); (d) advanced OT cybersecurity including network segmentation + cyber-physical-system integrity verification + safety-instrumented-system (SIS) hardening; (e) advanced incident response including 24/7 SOC + automated incident-response playbooks + cross-border-incident coordination protocols; (f) advanced resilience including business continuity + disaster recovery with annual cyber-physical exercises. Article 33 establishes the implementation timeline: advanced controls must be in place within 36 months of critical-impact classification + reviewed + revised at least annually + tested via Article 36 exercises. Article 34 establishes the linkage to TIBER-EU framework + ECB's TIBER-EU methodology for advanced threat-led penetration testing.

Other controls in NCCS: Common Electricity Cybersecurity Framework and Minimum/Advanced Controls

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.