EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Governance, Competent Authorities and Coordination with NIS2 / CER / CSA

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.59_60: Penalties, audits and entry into force (NCCS Articles 59-60)

Article 59 requires Member States to lay down PENALTIES applicable to infringements of NCCS by entities within their jurisdiction. The penalties must be EFFECTIVE + PROPORTIONATE + DISSUASIVE. National transposition may align NCCS penalties with the parallel NIS2 Article 34 administrative-fines ceiling (EUR 10 million or 2% of worldwide turnover for Essential Entities) or set its own scheme. Article 59 also requires periodic AUDITS by Member State competent authorities + the EECCG of high-impact + critical-impact entities. Article 60 establishes the ENTRY INTO FORCE: 13 June 2024 (20th day after publication in OJEU on 24 May 2024) + direct application from that date. The first Union-wide cybersecurity risk assessment + the first joint methodology must be finalised by 13 December 2025 + 13 December 2026 respectively. Future amendments to NCCS are anticipated as the joint methodology is operationalised + early-implementation experience is gathered.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in NCCS: Governance, Competent Authorities and Coordination with NIS2 / CER / CSA

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.