Article 37 establishes a cross-border VERIFICATION REGIME for NCCS compliance: independent verification of high-impact entity compliance with Article 30 minimum controls + critical-impact entity compliance with Article 32 advanced controls. Verification is performed by independent cybersecurity audit bodies accredited under the Article 38 accreditation scheme; verification reports cover the implementation status + maturity rating + identified gaps + remediation plans. Article 38 establishes the MUTUAL RECOGNITION SCHEME: a verification performed in one Member State must be recognised by competent authorities in other Member States, avoiding duplicate verification for cross-border entities. The scheme leverages the European cybersecurity certification framework under Regulation (EU) 2019/881 (Cybersecurity Act). Article 39 sets the verification cycle: at least every 3 years for high-impact entities + at least every 2 years for critical-impact entities + ad-hoc verification after major incidents OR significant changes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.