Article 4 establishes the entity-classification regime. Each in-scope entity is classified as: (a) high-impact entity - where the entity's cyber-attack would result in significant impact on cross-border electricity flows based on quantified criteria in Annex I; or (b) critical-impact entity - where the entity's cyber-attack would result in critical impact on cross-border electricity flows or on the security of supply at Union or regional level. The classification is established by the ENTSO-E + EU DSO Entity joint methodology (Article 8) submitted to ACER for approval and uses Annex I quantitative thresholds covering: installed power generation capacity, transmission capacity, distribution serving population, market-coupling volume, and other connectivity-based metrics. Article 5 establishes the entity-level classification process: each Member State competent authority designates which entities under its jurisdiction qualify as high-impact / critical-impact in coordination with ENTSO-E + EU DSO Entity. The classification is reviewed at least every 3 years OR upon material changes (new generation capacity + new interconnections + significant entity reorganisation).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.