EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Governance, Competent Authorities and Coordination with NIS2 / CER / CSA

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.8: ENTSO-E and EU DSO Entity joint methodology (NCCS Article 8)

Article 8 mandates that ENTSO-E and the EU DSO Entity, in coordination with the EECCG and supported by ACER, develop a JOINT METHODOLOGY for the implementation of NCCS. The methodology must address: (a) detailed criteria for entity classification (high-impact + critical-impact - operationalising Annex I); (b) procedures for the four-level cybersecurity risk assessment cascade (Articles 17-28); (c) the common electricity cybersecurity framework + minimum + advanced controls (Articles 29-36); (d) cross-border verification + mutual-recognition procedures (Articles 37-43); (e) cybersecurity incident-reporting templates + classification thresholds (Articles 44-47); (f) information protection requirements + classification (Articles 48-53); (g) supply-chain cybersecurity requirements (Articles 54-56); (h) governance + audit + assurance procedures (Articles 57-60). The joint methodology must be submitted to ACER within 18 months of NCCS entry into force (by 13 December 2025) + reviewed + amended where necessary every 2 years.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in NCCS: Governance, Competent Authorities and Coordination with NIS2 / CER / CSA

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.