EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Subject Matter, Scope, Definitions and Entity Classification

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.4_5: Entity classification - high-impact and critical-impact entities (NCCS Articles 4-5)

Article 4 establishes the entity-classification regime. Each in-scope entity is classified as: (a) high-impact entity - where the entity's cyber-attack would result in significant impact on cross-border electricity flows based on quantified criteria in Annex I; or (b) critical-impact entity - where the entity's cyber-attack would result in critical impact on cross-border electricity flows or on the security of supply at Union or regional level. The classification is established by the ENTSO-E + EU DSO Entity joint methodology (Article 8) submitted to ACER for approval and uses Annex I quantitative thresholds covering: installed power generation capacity, transmission capacity, distribution serving population, market-coupling volume, and other connectivity-based metrics. Article 5 establishes the entity-level classification process: each Member State competent authority designates which entities under its jurisdiction qualify as high-impact / critical-impact in coordination with ENTSO-E + EU DSO Entity. The classification is reviewed at least every 3 years OR upon material changes (new generation capacity + new interconnections + significant entity reorganisation).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in NCCS: Subject Matter, Scope, Definitions and Entity Classification

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.