Skip to content

Evidence request lists

EU Network Code on Cybersecurity for the Electricity Sector

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

NCCS: Common Electricity Cybersecurity Framework and Minimum/Advanced Controls

NCCS-Art.29_30_31
Common electricity cybersecurity framework and minimum cybersecurity controls (NCCS Articles 29-31) - for high-impact entities

Article 29 establishes the COMMON ELECTRICITY CYBERSECURITY FRAMEWORK - a sector-specific set of cybersecurity controls building on horizontal frameworks (NIS2 Article 21(2) + ISO/IEC 27001 + IEC 62443) but adapted to the electricity sector + cross-border flows + OT (operational technology) systems. Article 30 sets the MINIMUM CYBERSECURITY CONTROLS that all high-impact entities must implement, covering: (a) cybersecurity governance + organisational structure including a dedicated CISO function; (b) information security policy + standards; (c) risk management + asset management + change management; (d) human resources security + cybersecurity training; (e) identity + access management + privileged-access management; (f) cryptography + key management; (g) physical + environmental security; (h) communications + operations security; (i) supplier + supply-chain security; (j) incident managem

Artefacts an auditor will ask for
  • Common framework gap analysis
  • Minimum-controls implementation evidence
  • 24-month implementation milestones
  • Annual minimum-controls review report
Where this commonly fails
  • Minimum controls not implemented within the 24-month window
  • Implementation evidence not auditable
  • Annual review not conducted or not documented
  • Reliance on horizontal frameworks (NIS2 / ISO 27001) without the sector-specific NCCS adaptations
NCCS-Art.32_33_34
Advanced cybersecurity controls (NCCS Articles 32-34) - for critical-impact entities

Article 32 establishes the ADVANCED CYBERSECURITY CONTROLS that critical-impact entities must implement IN ADDITION TO the Article 30 minimum controls. Advanced controls cover: (a) advanced threat-detection + threat-hunting + cyber-threat intelligence integration; (b) red-teaming + advanced penetration testing including TIBER-EU-style threat-led penetration testing for the electricity sector; (c) advanced supply-chain cybersecurity including coordinated vulnerability disclosure + software bill of materials (SBOM); (d) advanced OT cybersecurity including network segmentation + cyber-physical-system integrity verification + safety-instrumented-system (SIS) hardening; (e) advanced incident response including 24/7 SOC + automated incident-response playbooks + cross-border-incident coordination protocols; (f) advanced resilience including business continuity + disaster recovery with annual cy

Artefacts an auditor will ask for
  • Advanced-controls implementation evidence
  • 36-month implementation milestones
  • TIBER-EU-style red-teaming reports
  • 24/7 SOC + automated playbooks
  • Annual cyber-physical exercise reports
Where this commonly fails
  • Advanced controls overdue (36-month window missed)
  • No TIBER-EU-style threat-led penetration testing
  • SOC operating less than 24/7
  • No cyber-physical exercises

NCCS: Cross-Border Risk Management and Verification + Mutual Recognition

NCCS-Art.37_38_39
Cross-border verification and mutual recognition (NCCS Articles 37-39)

Article 37 establishes a cross-border VERIFICATION REGIME for NCCS compliance: independent verification of high-impact entity compliance with Article 30 minimum controls + critical-impact entity compliance with Article 32 advanced controls. Verification is performed by independent cybersecurity audit bodies accredited under the Article 38 accreditation scheme; verification reports cover the implementation status + maturity rating + identified gaps + remediation plans. Article 38 establishes the MUTUAL RECOGNITION SCHEME: a verification performed in one Member State must be recognised by competent authorities in other Member States, avoiding duplicate verification for cross-border entities. The scheme leverages the European cybersecurity certification framework under Regulation (EU) 2019/881 (Cybersecurity Act). Article 39 sets the verification cycle: at least every 3 years for high-impac

Artefacts an auditor will ask for
  • Independent verification reports per entity classification
  • Accredited audit body engagement records
  • Mutual-recognition evidence for cross-border entities
  • Tracking of verification cycle (2-year critical + 3-year high-impact)
Where this commonly fails
  • Verification overdue beyond mandated cycle
  • Multiple Member State verifications without mutual-recognition coordination
  • Verification not conducted by accredited audit body

NCCS: Four-Level Cybersecurity Risk Assessment Cascade

NCCS-Art.17
Union-wide cybersecurity risk assessment (NCCS Articles 17-19) - first level of the cascade

Article 17 establishes the UNION-WIDE cybersecurity risk assessment - the first level of the four-level cascade. The Union-wide risk assessment is conducted by ENTSO-E and the EU DSO Entity in coordination with ACER + ENISA + the EECCG + Member State competent authorities. The assessment identifies: (a) significant cybersecurity threats to cross-border electricity flows at Union level; (b) cybersecurity scenarios + their potential cross-border impact; (c) prioritised risk-treatment recommendations. The first Union-wide cybersecurity risk assessment must be conducted by 13 December 2026 (within 30 months of NCCS entry into force) + updated at least every 3 years thereafter OR after a major Union-wide cyber-incident. Article 18 sets the methodology + data-source requirements for the Union-wide assessment. Article 19 establishes the publication + dissemination regime for the Union-wide asse

Artefacts an auditor will ask for
  • Entity contribution to the Union-wide assessment data collection
  • Tracking of the 2026-2027 first Union-wide assessment results + integration into entity-level risk management
  • Cross-reference to the joint methodology Article 8 data requirements
Where this commonly fails
  • No entity-level contribution to the Union-wide assessment data
  • Union-wide assessment results not integrated into the entity-level risk register
NCCS-Art.23_24
Regional cybersecurity risk assessment (NCCS Articles 23-24) - second level of the cascade

Article 23 establishes the REGIONAL cybersecurity risk assessment - the second level of the four-level cascade. Regional assessments are conducted by the Regional Coordination Centres (RCCs) per regulation 2019/943 in coordination with ENTSO-E + the EU DSO Entity + regional Member State competent authorities. The regional assessment addresses cross-border interconnection risks + regional electricity market coupling risks + sub-Union cyber-incident scenarios. Article 24 establishes the methodology + data-source requirements for regional assessments, building on the Union-wide assessment outcomes. Regional assessments must be conducted at least every 3 years AND on the same cycle as the Union-wide assessment + updated after material regional events (new interconnections + significant market-coupling changes).

Artefacts an auditor will ask for
  • Entity contribution to the regional risk assessment data collection
  • Cross-reference between Union-wide + regional assessments
  • RCC engagement records
Where this commonly fails
  • Regional assessment treated as substitute for Union-wide assessment
  • No integration of regional assessment results into entity-level risk register
  • Material regional events not triggering regional assessment update
NCCS-Art.25_26
Member State cybersecurity risk assessment (NCCS Articles 25-26) - third level of the cascade

Article 25 establishes the MEMBER STATE cybersecurity risk assessment - the third level of the four-level cascade. Member State competent authorities conduct national cybersecurity risk assessments for their in-scope electricity entities, building on the Union-wide + regional assessment outcomes. The Member State assessment addresses national-level cyber-threat landscape + national entity-classification + national cross-cutting cybersecurity risk-treatment priorities. Article 26 sets the methodology + data-source requirements, including coordination with national cybersecurity authorities (typically the NIS2 single point of contact + the national CSIRT). Member State assessments must be conducted at least every 3 years + updated after material national events.

Artefacts an auditor will ask for
  • Entity contribution to the Member State assessment data collection
  • Cross-reference between Member State + regional + Union-wide assessments
Where this commonly fails
  • Member State assessment not coordinated with national NIS2 SPOC + CSIRT
  • No entity-level contribution to the Member State assessment
NCCS-Art.27_28
Entity-level cybersecurity risk assessment (NCCS Articles 27-28) - fourth level of the cascade

Article 27 establishes the ENTITY-LEVEL cybersecurity risk assessment - the fourth and most granular level of the four-level cascade. Each high-impact + critical-impact entity must conduct its own entity-level cybersecurity risk assessment, addressing: (a) entity-specific cybersecurity threats + attack scenarios; (b) entity-specific asset inventory + criticality assessment; (c) cybersecurity controls implementation + maturity; (d) supply-chain cybersecurity exposure; (e) cross-border interconnection-related risks. Article 28 sets the methodology + content requirements: entity-level assessments must build on the Union-wide + regional + Member State assessments above + use the Article 8 joint methodology. Entity-level assessments must be conducted ANNUALLY + updated after major incidents + significant changes to the entity's infrastructure + cyber-attack surface. The results feed back upwa

Artefacts an auditor will ask for
  • Entity-level cybersecurity risk assessment report
  • Annual update cycle evidence
  • Cross-reference to higher cascade levels + the Article 8 joint methodology
  • Asset inventory + criticality assessment
Where this commonly fails
  • Entity-level assessment overdue (no annual review)
  • Asset inventory missing or incomplete
  • Bottom-up reporting to Member State authority not occurring

NCCS: Governance, Competent Authorities and Coordination with NIS2 / CER / CSA

NCCS-Art.57_58
Coordination with NIS2 + CER Directive + horizontal cybersecurity regimes (NCCS Articles 57-58)

Article 57 establishes the COORDINATION REGIME with horizontal cybersecurity instruments: NIS2 Directive (Directive (EU) 2022/2555) - electricity entities are NIS2 'Essential Entities' (Annex I Sector 1 Energy) and apply NIS2 Article 21(2) baseline AND NCCS sector-specific controls cumulatively; CER Directive (Directive (EU) 2022/2557) - same entities may be designated critical entities under CER + apply CER physical-resilience measures cumulatively with NCCS cyber-resilience measures; EU Cyber Solidarity Act (CSA, Regulation (EU) 2025/38) - NCCS crisis-management activates CSA mechanisms; Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) - NCCS supply-chain requirements coordinate with CRA essential cybersecurity requirements for products with digital elements used by electricity entities; DORA (Regulation (EU) 2022/2554) for financial sector aspects of electricity market participan

Artefacts an auditor will ask for
  • Horizontal-NCCS overlap matrix (NIS2 + CER + CSA + CRA + DORA)
  • Lex specialis application notes for cross-cutting obligations
  • Single-point-of-contact for NIS2 + NCCS + CER + CSA cross-reporting
Where this commonly fails
  • Compliance program treating regimes as substitutes
  • No cross-regime gap analysis
  • Multiple uncoordinated compliance trails creating audit-fatigue + inefficiency
NCCS-Art.59_60
Penalties, audits and entry into force (NCCS Articles 59-60)

Article 59 requires Member States to lay down PENALTIES applicable to infringements of NCCS by entities within their jurisdiction. The penalties must be EFFECTIVE + PROPORTIONATE + DISSUASIVE. National transposition may align NCCS penalties with the parallel NIS2 Article 34 administrative-fines ceiling (EUR 10 million or 2% of worldwide turnover for Essential Entities) or set its own scheme. Article 59 also requires periodic AUDITS by Member State competent authorities + the EECCG of high-impact + critical-impact entities. Article 60 establishes the ENTRY INTO FORCE: 13 June 2024 (20th day after publication in OJEU on 24 May 2024) + direct application from that date. The first Union-wide cybersecurity risk assessment + the first joint methodology must be finalised by 13 December 2025 + 13 December 2026 respectively. Future amendments to NCCS are anticipated as the joint methodology is op

Artefacts an auditor will ask for
  • Article 59 penalty exposure in compliance risk register
  • Audit-readiness file
  • Tracking of NCCS amendments + joint methodology updates
  • First Union-wide assessment results integration (expected 2026-2027)
Where this commonly fails
  • NCCS penalty exposure not mapped
  • Audit-readiness file absent
  • No tracking of joint methodology + amendments + Union-wide assessment outcomes
NCCS-Art.6_7
Competent authorities + coordination (NCCS Articles 6-7)

Article 6 designates the electricity cybersecurity competent authority (ECCA) for each Member State, which may be the NIS2 competent authority or a separate sector-specific authority. The ECCA must: (a) supervise implementation of NCCS within its jurisdiction; (b) coordinate with NIS2 + CER Directive competent authorities; (c) participate in cross-border supervisory cooperation under Article 19; (d) impose proportionate measures + penalties under national transposition. Article 7 establishes the European Electricity Cybersecurity Coordination Group (EECCG) - a multi-stakeholder cooperation body coordinating ENTSO-E + EU DSO Entity + Member State competent authorities + ACER + ENISA + the Commission. The EECCG meets at least 4 times per year + supervises the Article 8 joint methodology + reviews the Article 17 Union-wide cybersecurity risk assessment + provides recommendations to ACER + t

Artefacts an auditor will ask for
  • ECCA point-of-contact records
  • Participation in EECCG processes
  • Cross-border cooperation evidence with NIS2 + CER + NCCS authorities
Where this commonly fails
  • ECCA not designated or unclear
  • No participation in EECCG
  • Cross-border cooperation limited to email-based information exchange without structured framework
NCCS-Art.8
ENTSO-E and EU DSO Entity joint methodology (NCCS Article 8)

Article 8 mandates that ENTSO-E and the EU DSO Entity, in coordination with the EECCG and supported by ACER, develop a JOINT METHODOLOGY for the implementation of NCCS. The methodology must address: (a) detailed criteria for entity classification (high-impact + critical-impact - operationalising Annex I); (b) procedures for the four-level cybersecurity risk assessment cascade (Articles 17-28); (c) the common electricity cybersecurity framework + minimum + advanced controls (Articles 29-36); (d) cross-border verification + mutual-recognition procedures (Articles 37-43); (e) cybersecurity incident-reporting templates + classification thresholds (Articles 44-47); (f) information protection requirements + classification (Articles 48-53); (g) supply-chain cybersecurity requirements (Articles 54-56); (h) governance + audit + assurance procedures (Articles 57-60). The joint methodology must be

Artefacts an auditor will ask for
  • Joint methodology compliance evidence
  • ACER approval references
  • Tracking of joint methodology amendments + 2-year review cycle
Where this commonly fails
  • Compliance based on the high-level NCCS text without reference to the operationalising joint methodology
  • Joint methodology updates not reflected in the entity's internal compliance program

NCCS: Information Protection, Supply Chain and Audits

NCCS-Art.48_49_50
Information protection and classification (NCCS Articles 48-50)

Article 48 establishes the INFORMATION PROTECTION regime for sensitive electricity-grid + cybersecurity information shared under NCCS. Information is classified at one of four levels: (1) PUBLIC; (2) RESTRICTED; (3) CONFIDENTIAL; (4) HIGHLY CONFIDENTIAL. Each level has specific handling + storage + transmission + access-control requirements. Article 49 establishes the access-rights regime: only persons with a documented 'need-to-know' + appropriate security clearance (where applicable) may access classified NCCS information. Article 50 sets the security-clearance requirements for personnel handling CONFIDENTIAL + HIGHLY CONFIDENTIAL information including TS or equivalent national clearance. Information-protection requirements apply to both transit + at-rest + cross-border sharing scenarios.

Artefacts an auditor will ask for
  • Information classification policy + handling guide
  • Need-to-know access control + personnel security records
  • Security clearance trail for relevant personnel
  • At-rest + in-transit encryption evidence
Where this commonly fails
  • Information classification not implemented
  • Need-to-know not operationalised + access controls based on role only
  • Security clearances overdue or missing
NCCS-Art.54_55_56
Supply chain cybersecurity (NCCS Articles 54-56)

Article 54 establishes SUPPLY CHAIN CYBERSECURITY requirements for high-impact + critical-impact entities. Suppliers + service providers + software vendors providing components or services with cyber-physical-system implications must: (a) meet the Article 30 minimum + Article 32 advanced cybersecurity controls (proportionate to supplier role); (b) provide vulnerability disclosure + coordinated patching capabilities; (c) provide a software bill of materials (SBOM) for critical software components; (d) accept contractual cybersecurity audit + verification rights. Article 55 establishes the supplier risk-assessment regime + the obligation to maintain a supplier cybersecurity register. Article 56 establishes the cross-border + cross-jurisdictional supplier-management rules including treatment of third-country suppliers + alignment with the Article 22 NIS2 Cooperation Group coordinated supply

Artefacts an auditor will ask for
  • Supplier cybersecurity register
  • SBOM repository for critical components
  • Contractual cybersecurity clauses + audit rights
  • Cross-reference to Article 22 NIS2 coordinated supply-chain risk assessments
Where this commonly fails
  • Supplier cybersecurity register absent
  • SBOMs not collected for critical components
  • Contractual audit rights weak or absent
  • Third-country supplier risk not assessed

NCCS: Information Sharing, Incident Reporting and Crisis Management

NCCS-Art.44_45_46
Cybersecurity incident reporting (NCCS Articles 44-46)

Article 44 establishes the CYBERSECURITY INCIDENT REPORTING regime for NCCS in-scope entities. Significant cybersecurity incidents (defined in Article 44(2) by reference to impact on cross-border electricity flows) must be reported to the ECCA + the EECCG within strict deadlines paralleling NIS2 Article 23: 24-hour early warning + 72-hour notification + 1-month final report. The reporting templates + classification thresholds are operationalised through the Article 8 joint methodology. Article 45 sets the cross-border-incident reporting protocols + cooperation between Member State competent authorities + ENTSO-E + the EU DSO Entity + ENISA. Article 46 establishes the EARLY WARNING SYSTEM for cross-border cyber-attacks affecting cross-border electricity flows: the EECCG coordinates real-time information sharing + threat intelligence + cross-border response activation. NCCS reporting appli

Artefacts an auditor will ask for
  • Article 44 incident reporting workflow with 24h/72h/1-month deadlines
  • Cross-border incident coordination procedure
  • EECCG engagement records
  • Cumulative-reporting cross-reference with NIS2 Article 23
Where this commonly fails
  • Incident reporting not meeting Article 44 deadlines
  • No cross-border incident coordination procedure
  • Reporting only to NIS2 authority without the parallel NCCS reporting
  • No automated incident-detection + classification capability
NCCS-Art.47_48
Crisis management and Cyber Solidarity Act coordination (NCCS Articles 47-48)

Article 47 establishes the CRISIS MANAGEMENT framework for cross-border electricity cyber-incidents that escalate beyond entity-level + Member-State-level response capacity. The EECCG activates a coordinated EU-level crisis-response procedure including: (a) immediate cross-border information sharing + situational awareness; (b) coordination with EU-CyCLONe (European cyber crisis liaison organisation network) under the EU Cyber Solidarity Act (Regulation (EU) 2025/38) Article 10-11; (c) coordinated public communication + reassurance; (d) coordinated mutual assistance + recovery support. Article 48 establishes the linkage to the EU Cyber Solidarity Act (CSA) Cyber Emergency Mechanism: where a Union-wide cyber-attack on cross-border electricity flows qualifies as a 'large-scale cybersecurity incident' under the CSA, NCCS authorities cooperate with the CSA Cyber Reserve + the EU Cybersecurit

Artefacts an auditor will ask for
  • Crisis management plan + exercises
  • Cross-reference to EU-CyCLONe activation procedures
  • CSA Cyber Reserve eligibility + activation records
  • Annual crisis exercise reports
Where this commonly fails
  • No crisis management plan addressing cross-border electricity cyber-incidents
  • No coordination with EU-CyCLONe
  • CSA Cyber Reserve eligibility unknown or unverified

NCCS: Subject Matter, Scope, Definitions and Entity Classification

NCCS-Art.1_2_3
Subject matter, scope and definitions (NCCS Articles 1-3)

Article 1 establishes the subject matter: NCCS lays down sector-specific rules for cybersecurity aspects of cross-border electricity flows, including rules on common minimum cybersecurity requirements + planning + monitoring + reporting + crisis management. Article 2 sets the scope: applies to in-scope electricity entities including ENTSO-E, EU DSO Entity, transmission system operators (TSOs), distribution system operators (DSOs), nominated electricity market operators (NEMOs), regional coordination centres (RCCs), and the providers of essential services and ICT services for those entities. NCCS does NOT apply to entities falling exclusively within the scope of the NIS2 Directive (Directive (EU) 2022/2555) without cross-border flow dimension, but applies CUMULATIVELY for entities subject to both NIS2 + NCCS. Article 3 contains the key definitions including: 'high-impact entity', 'critica

Artefacts an auditor will ask for
  • Internal scope determination identifying NCCS in-scope status (TSO / DSO / NEMO / RCC / essential-service provider)
  • Cumulative-application analysis for entities subject to both NIS2 and NCCS
  • Cross-border flow contribution quantification (Annex impact criteria)
Where this commonly fails
  • Entity treating NIS2 compliance as a substitute for NCCS where the entity also contributes to cross-border flows
  • No formal NCCS scope determination memo
  • Cross-border flow contribution not quantified for entity-classification purposes
NCCS-Art.4_5
Entity classification - high-impact and critical-impact entities (NCCS Articles 4-5)

Article 4 establishes the entity-classification regime. Each in-scope entity is classified as: (a) high-impact entity - where the entity's cyber-attack would result in significant impact on cross-border electricity flows based on quantified criteria in Annex I; or (b) critical-impact entity - where the entity's cyber-attack would result in critical impact on cross-border electricity flows or on the security of supply at Union or regional level. The classification is established by the ENTSO-E + EU DSO Entity joint methodology (Article 8) submitted to ACER for approval and uses Annex I quantitative thresholds covering: installed power generation capacity, transmission capacity, distribution serving population, market-coupling volume, and other connectivity-based metrics. Article 5 establishes the entity-level classification process: each Member State competent authority designates which e

Artefacts an auditor will ask for
  • Article 4 classification determination per entity
  • Annex I threshold calculation evidence
  • 3-year classification review + material-change update process
  • Joint methodology compliance
Where this commonly fails
  • Entity classification not based on Annex I quantitative thresholds
  • No 3-year review cycle
  • Material changes (new interconnections + capacity additions) not triggering reclassification
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Network Code on Cybersecurity for the Electricity Sector framework page.