Commission Delegated Regulation (EU) 2024/1366, Cybersecurity Network Code for Cross-Border Electricity Flows: Entity Risk Management, Controls and Management System
Commission Delegated Regulation (EU) 2024/1366, Arts. 2 and 24 to 32
In force since .
A sector security regimes rule binding public and private bodies.
- Obligation class
- Security, Governance
As of .
What it requires
- This duty reaches you if you declare that you operate an essential service, as an essential or important entity under Directive (EU) 2022/2555 or as an entity a competent authority has identified under Article 24 of Commission Delegated Regulation (EU) 2024/1366 as a high-impact or critical-impact entity for cross-border electricity flows. Article 2(1) lists the entities that can be identified: electricity undertakings, nominated electricity market operators, organized market places that arrange transactions on products relevant to cross-border electricity flows, critical ICT service providers, the ENTSO for Electricity, the EU DSO entity, balancing responsible parties, operators of recharging points, regional coordination centers and managed security service providers. Each competent authority notifies the entities on its list no later than (Article 24(6)). The periods in the lines below run from that notification unless a line says otherwise.
- Perform cybersecurity risk management for all assets in your high-impact and critical-impact perimeters every three years, in four phases: context establishment, cybersecurity risk assessment at entity level, cybersecurity risk treatment and cybersecurity risk acceptance (Article 26(1) and (2)).
- Register the assets in your high-impact and critical-impact perimeters in an asset inventory that is kept apart from the risk assessment report (Article 26(7)).
- Within 12 months after your Article 24(6) notification, and every three years thereafter, give your competent authority a report listing the controls selected for your entity-level risk mitigation plan with the implementation status of each, an estimate of the risk to each Union-wide high-impact or critical-impact process, and your critical ICT service providers for critical-impact processes (Article 27).
- If you are a high-impact entity, apply the minimum cybersecurity controls within your high-impact perimeter, and if you are a critical-impact entity, apply the advanced cybersecurity controls within your critical-impact perimeter, within 12 months after the controls are approved or updated (Articles 28(2) and (3) and 29(6)).
- Within 24 months after your Article 24(6) notification, establish a cybersecurity management system that covers the assets in your high-impact and critical-impact perimeters, with a documented cybersecurity policy, assigned cybersecurity roles and responsibilities, entity-level risk management and internal audits at planned intervals, and review it every three years (Article 32).
- If you are a critical-impact entity, be able to demonstrate compliance with the cybersecurity management system and the controls at your competent authority's request, no later than 24 months after the controls are adopted and the management system is established, by independent third-party security audits or a national verification scheme, and repeat the verification at the latest 36 months after the first and every 3 years thereafter (Article 31).
Who enforces it
Enforcement body
The competent authority each Member State designates under Article 4(1) of the Regulation, a national governmental or regulatory authority responsible for carrying out the tasks the Regulation assigns.
What this law does
Article 2(1) applies the Regulation to the activities of the listed entities if they are identified as high-impact or critical-impact entities in accordance with Article 24, among them electricity undertakings, nominated electricity market operators, organized market places that arrange transactions on products relevant to cross-border electricity flows, critical ICT service providers, balancing responsible parties, operators of recharging points, regional coordination centers and managed security service providers.
Article 1 establishes a network code that lays down sector-specific rules for cybersecurity aspects of cross-border electricity flows, including rules on common minimum requirements, planning, monitoring, reporting and crisis management.
Recital 7 notes that many of these entities will be identified both as essential entities under Article 3 of Directive (EU) 2022/2555 and as high-impact or critical-impact entities, while the Regulation's own criteria refer only to their role and impact in the electricity processes affecting cross-border flows.
Article 24(1) has each competent authority identify the high-impact and critical-impact entities in its Member State, using the electricity cybersecurity impact index and the thresholds in the Union-wide cybersecurity risk assessment report. Article 24(6) has each competent authority notify the entities on its list that they have been identified, within nine months after it is notified of the Union-wide cybersecurity risk assessment report and in any case no later than .
Article 48(3) provides that the entities on a provisional list may voluntarily fulfill their obligations on a precautionary basis, and that the competent authorities notify them by . The Regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.
Article 26 requires each high-impact and critical-impact entity to perform cybersecurity risk management for all its assets in its high-impact and critical-impact perimeters every three years. The risk management comprises four phases: context establishment, cybersecurity risk assessment at entity level, cybersecurity risk treatment and cybersecurity risk acceptance. Article 26(7) requires the entity to register the assets in an asset inventory that is not part of the risk assessment report.
Article 27 requires the entity, within 12 months after the Article 24(6) notification and every three years thereafter, to give the competent authority a report listing the controls selected for its risk mitigation plan with their implementation status, an estimate of the risk to each Union-wide high-impact or critical-impact process, and its critical ICT service providers for critical-impact processes.
Article 28 requires high-impact entities to apply the minimum cybersecurity controls within their high-impact perimeter and critical-impact entities to apply the advanced cybersecurity controls within their critical-impact perimeter. Article 29(1) has the TSOs, with the assistance of the ENTSO for Electricity and in cooperation with the EU DSO entity, develop the proposal for the minimum and advanced cybersecurity controls.
Article 29(6) sets the time for applying the controls at 12 months after the approval of the minimum and advanced cybersecurity controls, or after each update. Article 31 requires a critical-impact entity to be able to demonstrate its compliance with the cybersecurity management system and the controls at the request of the competent authority, no later than 24 months after the controls are adopted and the management system is established.
A critical-impact entity meets that duty by independent third-party security audits or by taking part in a national verification scheme. The verification is repeated at the latest 36 months after the end of the first verification and every 3 years thereafter. Article 32 requires each such entity to establish a cybersecurity management system within 24 months after the Article 24(6) notification and to review it every three years thereafter.
Article 4(1) has each Member State designate a national governmental or regulatory authority as the competent authority responsible for carrying out the tasks the Regulation assigns.
When LexLint raises it
When your app profile says your app runs an essential service.