Article 8 mandates that ENTSO-E and the EU DSO Entity, in coordination with the EECCG and supported by ACER, develop a JOINT METHODOLOGY for the implementation of NCCS. The methodology must address: (a) detailed criteria for entity classification (high-impact + critical-impact - operationalising Annex I); (b) procedures for the four-level cybersecurity risk assessment cascade (Articles 17-28); (c) the common electricity cybersecurity framework + minimum + advanced controls (Articles 29-36); (d) cross-border verification + mutual-recognition procedures (Articles 37-43); (e) cybersecurity incident-reporting templates + classification thresholds (Articles 44-47); (f) information protection requirements + classification (Articles 48-53); (g) supply-chain cybersecurity requirements (Articles 54-56); (h) governance + audit + assurance procedures (Articles 57-60). The joint methodology must be submitted to ACER within 18 months of NCCS entry into force (by 13 December 2025) + reviewed + amended where necessary every 2 years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.