Law / European Union

Commission Delegated Regulation (EU) 2024/1366, Cybersecurity Network Code for Cross-Border Electricity Flows: Information Sharing on Cyber-Attacks and Threats

Commission Delegated Regulation (EU) 2024/1366, Art. 38

In force since .

A vulnerability and incident reporting rule binding public and private bodies.

Obligation class
Reporting, Security

As of .

What it requires

  • This duty reaches you if you declare that you operate an essential service, as an essential or important entity under Directive (EU) 2022/2555 or as an entity a competent authority has identified under Article 24 of Commission Delegated Regulation (EU) 2024/1366 as a high-impact or critical-impact entity for cross-border electricity flows. Article 2(1) lists the entities that can be identified: electricity undertakings, nominated electricity market operators, organized market places that arrange transactions on products relevant to cross-border electricity flows, critical ICT service providers, the ENTSO for Electricity, the EU DSO entity, balancing responsible parties, operators of recharging points, regional coordination centers and managed security service providers. Each competent authority notifies the entities on its list no later than (Article 24(6)).
  • Establish, for all assets within your cybersecurity perimeter, at least the capabilities of a cybersecurity operation center (CSOC): security logs from your systems and applications, security monitoring including intrusion detection and vulnerability assessment, analysis and the actions needed to protect the entity, and participation in the information collection and sharing Article 38 describes (Article 38(1), point (a)); you may procure these through managed security service providers but remain responsible for them and supervise their efforts (Article 38(1), point (b)).
  • Designate a single point of contact at entity level for information sharing (Article 38(1), point (c)).
  • Share relevant information related to a reportable cyber-attack with your CSIRTs and your competent authority without undue delay and no later than four hours of becoming aware that the incident is reportable; a cyber-attack is reportable when you assess its criticality as ranging from high to critical on the classification scale methodology under Article 37(8) (Article 38(3) and (4)).
  • Provide your CSIRTs without undue delay with any information related to a reportable cyber threat that may have a cross-border effect (Article 38(6)).
  • When you share information under Article 38, specify that it is submitted pursuant to the Regulation, which kind of information it is, and, for a reportable cyber-attack, its level on the classification scale with the information leading to that classification (Article 38(7)).
  • Where your report of a significant incident under Article 23(1) of Directive (EU) 2022/2555 contains the information Article 38(3) requires, that report counts as your Article 38(3) report (Article 38(8)).

Who enforces it

Enforcement body

The competent authority each Member State designates under Article 4(1) of the Regulation, a national governmental or regulatory authority responsible for carrying out the tasks the Regulation assigns.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 2(1) applies the Regulation to the activities of the listed entities if they are identified as high-impact or critical-impact entities in accordance with Article 24, among them electricity undertakings, nominated electricity market operators, organized market places that arrange transactions on products relevant to cross-border electricity flows, critical ICT service providers, balancing responsible parties, operators of recharging points, regional coordination centers and managed security service providers.

Article 1 establishes a network code that lays down sector-specific rules for cybersecurity aspects of cross-border electricity flows, including rules on common minimum requirements, planning, monitoring, reporting and crisis management. Article 24(1) has each competent authority identify the high-impact and critical-impact entities in its Member State, using the electricity cybersecurity impact index and the thresholds in the Union-wide cybersecurity risk assessment report.

Article 24(6) has each competent authority notify the entities on its list that they have been identified, within nine months after it is notified of the Union-wide cybersecurity risk assessment report and in any case no later than .

Article 38(1) requires each high-impact and critical-impact entity to establish, for all assets within its cybersecurity perimeter, at least the capabilities of a cybersecurity operation center to ensure that systems provide security logs, to conduct security monitoring including detecting intrusions and assessing vulnerabilities, to analyze and take the actions needed to protect the entity, and to participate in the information collection and sharing described in that Article.

The entity may procure all or parts of those capabilities through managed security service providers but remains responsible for them and supervises their efforts. The entity designates a single point of contact at entity level for the purpose of information sharing.

Article 38(3) requires each critical-impact and high-impact entity to share relevant information related to a reportable cyber-attack with its CSIRTs and its competent authority without undue delay and no later than four hours of becoming aware that the incident is reportable. Information related to a cyber-attack is reportable when the affected entity assesses its criticality as ranging from high to critical following the cyber-attack classification scale methodology under Article 37(8).

Article 37(8) has the TSOs, with the assistance of the ENTSO for Electricity and in cooperation with the EU DSO entity, develop the cyber-attack classification scale methodology by . Article 38(6) requires the entity to provide its CSIRTs without undue delay with any information related to a reportable cyber threat that may have a cross-border effect.

Article 38(7) requires the entity, when sharing information under that Article, to specify that the information is submitted pursuant to the Regulation, among other particulars. Where an entity notifies a significant incident under Article 23 of Directive (EU) 2022/2555 and that report contains the information Article 38(3) requires, the Article 23(1) report constitutes the Article 38(3) report.

Article 4(1) has each Member State designate a national governmental or regulatory authority as the competent authority responsible for carrying out the tasks the Regulation assigns.

When LexLint raises it

When your app profile says your app runs an essential service.

Back to the example  ·  Lint your app