My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1366 CHAPTER I — GENERAL PROVISIONS

Article 1–Article 17 · 17 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Subject matter

Article 1

This Regulation establishes a network code which lays down sector-specific rules for cybersecurity aspects of cross-border electricity flows, including rules on common minimum requirements, planning, monitoring, reporting and crisis management.

Scope

Article 2

1.   This Regulation applies to cybersecurity aspects of cross-border electricity flows in the activities of the following entities, if they are identified as high-impact or critical-impact entities in accordance with Article 24: (a) electricity undertakings as defined in Article 2(57) of Directive (EU) 2019/944; (b) nominated electricity market operators (‘NEMOs’) as defined in Article 2(8) of Regulation (EU) 2019/943; (c) organised market places or ‘organised markets’ as defined in Article 2(4) of Commission Implementing Regulation (EU) No 1348/2014  ( 14 ) that arrange transactions on products relevant to cross-border electricity flows; (d) critical ICT service providers as referred to in Article 3, point (9) of this Regulation; (e) the ENTSO for Electricity established pursuant to Article 28 of Regulation (EU) 2019/943; (f) the EU DSO entity established pursuant to Article 52 of Regulation (EU) 2019/943; (g) balancing responsible parties as defined in Article 2, point (14) of Regulation (EU) 2019/943; (h) operators of recharging points as defined in Annex I to Directive (EU) 2022/2555; (i) regional coordination centres (‘RCCs’) as established pursuant to Article 35 of Regulation (EU) 2019/943; (j) managed security service providers (‘MSSP’) as defined in Article 6(40) of Directive (EU) 2022/2555; (k) any other entity or third party to whom responsibilities have been delegated or assigned pursuant to this Regulation. 2.   The following authorities are, as part of their current mandates, responsible to perform tasks assigned in this Regulation: (a) the European Union Agency for the Cooperation of Energy Regulators (‘ACER’) established by Regulation (EU) 2019/942 of the European Parliament and of the Council  ( 15 ) ; (b) national competent authorities responsible for carrying out the tasks assigned to them under this Regulation and designated by Member States pursuant to Article 4, or ‘competent authority’; (c) national regulatory authorities (‘NRAs’) designated by each Member State pursuant to Article 57(1) of Directive (EU) 2019/944; (d) competent authorities for risk preparedness (‘RP-NCAs’) established pursuant to Article 3 of Regulation (EU) 2019/941; (e) computer security incident response teams (‘CSIRTs’) as designated or established pursuant to Article 10 of Directive (EU) 2022/2555; (f) competent authorities responsible for cybersecurity (‘CS-NCAs’) as designated or established pursuant to Article 8 of Directive (EU) 2022/2555; (g) the European Union Agency for Cybersecurity established pursuant to Regulation (EU) 2019/881; (h) any other authorities or third party to whom responsibilities have been delegated or assigned pursuant to Article 4(3). 3.   This Regulation shall also apply to all entities who are not established in the Union but who deliver services to entities in the Union, provided they have been identified as high or critical-impact entities by the competent authorities in accordance with Article 24(2). 4.   This Regulation is without prejudice to the Member States’ responsibility for safeguarding national security and their power to safeguard other essential State functions, including ensuring the territorial integrity of the State and maintaining law and order. 5.   This Regulation is without prejudice to the Member States’ responsibility for safeguarding national security with respect to activities in the production of electricity from nuclear powers plants, including activities within the nuclear value chain, in accordance with the Treaties. 6.   Entities, the competent authorities, the single points of contact at entity level and the CSIRTs shall process personal data to the extent necessary for the purposes of this Regulation and in accordance with Regulation (EU) 2016/679, in particular such processing shall rely on Article 6 thereof.

Definitions

Article 3

The following definitions apply: (1) ‘asset’ means any information, software or hardware in the network and information systems either tangible or intangible, that has value to an individual, an organisation or a government; (2) ‘competent authority for risk preparedness’ means the competent authority designated pursuant to Article 3 of Regulation (EU) 2019/941; (3) ‘computer security incident response team’ means a team responsible for risk and incident handling in accordance with Article 10 of Directive (EU) 2022/2555; (4) ‘critical-impact asset’ means an asset that is necessary to carry out a critical-impact process; (5) ‘critical-impact entity’ means an entity that carries out a critical-impact process and that is identified by the competent authorities in accordance with Article 24; (6) ‘critical-impact perimeter’ means a perimeter defined by an entity referred to in Article 2(1) that contains all critical-impact assets and on which access to these assets can be controlled and that defines the scope where the advanced cybersecurity controls apply; (7) ‘critical-impact process’ means a business process carried out by an entity for which the electricity cybersecurity impact indices are above the critical-impact threshold; (8) ‘critical-impact threshold’ means the values of the electricity cybersecurity impact indices referred to in Article 19(3)b, above which a cyber-attack on a business process will cause critical disruption of cross-border electricity flows; (9) ‘critical ICT service provider’ means an entity which provides an ICT service, or ICT process that is necessary for a critical-impact or high-impact process affecting cybersecurity aspects of cross-border electricity flows and that, if compromised, may cause a cyber-attack with impact above the critical-impact or high-impact threshold; (10) ‘cross-border electricity flow’ means a cross-border flow as defined in Article 2(3) of Regulation (EU) 2019/943; (11) ‘cyber-attack’ means an incident as defined in Article 3, point (14), of Regulation (EU) 2022/2554; (12) ‘cybersecurity’ means cybersecurity as defined in Article 2, point (1) of Regulation (EU) 2019/881; (13) ‘cybersecurity control’ means the actions or procedures carried out with the purpose of avoiding, detecting, counteracting, or minimising cybersecurity risks; (14) ‘cybersecurity incident’ means an incident as defined in Article 6, point (6) of Directive (EU) 2022/2555; (15) ‘cybersecurity management system’ means the policies, procedures, guidelines, and associated resources and activities, collectively managed by an entity, in the pursuit of protecting its information assets from cyber threats systematically establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organisation’s network and information system security; (16) ‘cybersecurity operation centre’ means a dedicated centre where a technical team consisting of one or more experts, supported by cybersecurity IT systems, performs security-related tasks (Cybersecurity operation center (‘CSOC’) services) such as handling of cyber-attacks and security configuration errors, security monitoring, log analysis, and cyber-attack detection; (17) ‘cyber threat’ means a cyber threat as defined in Article 2, point (8) of Regulation (EU) 2019/881; (18) ‘cybersecurity vulnerability management’ means the practice of identifying and addressing vulnerabilities; (19) ‘entity’ means entity as defined in Article 6, point (38) of Directive (EU) 2022/2555; (20) ‘early alert’ means the information necessary to indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact; (21) ‘electricity cybersecurity impact index’ (‘ECII’) means an index or classification scale that ranks possible consequences of cyber-attacks to business processes involved in cross-border electricity flows; (22) ‘European cybersecurity certification scheme’ means a scheme as defined in Article 2, point (9) of Regulation (EU) 2019/881; (23) ‘high-impact entity’ means an entity that carries out a high-impact process and that is identified by the competent authorities in accordance with Article 24; (24) ‘high-impact process’ means any business process carried out by an entity for which the electricity cybersecurity impact indices are above the high-impact threshold; (25) ‘high-impact asset’ means an asset that is necessary to carry out a high-impact process; (26) ‘high-impact threshold’ means the values of the electricity cybersecurity impact indices referred to in Article 19(3)b, above which a successful cyber-attack on a process will cause high disruption of cross-border electricity flows; (27) ‘high-impact perimeter’ means a perimeter defined by any entity listed in Article 2(1) that contains all high-impact assets and on which access to these assets can be controlled and that defines the scope where the minimum cybersecurity controls apply; (28) ‘ICT product’ means an ICT product as defined in Article 2, point (12) of Regulation (EU) 2019/881; (29) ‘ICT service’ means an ICT service as defined in Article 2, point (13) of Regulation (EU) 2019/881; (30) ‘ICT process’ means an ICT process as defined in Article 2, point (14) of Regulation (EU) 2019/881; (31) ‘legacy system’ means a legacy ICT system as defined in Article 3(3) of Regulation (EU) 2022/2554; (32) ‘national single point of contact’ means the single point of contact designated or established by each Member State pursuant to Article 8(3) of Directive (EU) 2022/2555; (33) ‘NIS cyber crisis management authorities’ means the authorities designated or established pursuant to Article 9, point (1) of Directive (EU) 2022/2555; (34) ‘originator’ means an entity that initiates an information exchange, information sharing or information storage event; (35) ‘procurement specifications’ means the specifications that entities define for the procurement of new or updated ICT products, ICT processes or ICT services; (36) ‘representative’ means a natural or legal person established in the Union who is explicitly designated to act on behalf of a high or critical-impact entity not established in the Union but delivering services to entities in the Union and who may be addressed by a competent authority or a CSIRT in the place of the high or critical-impact entity itself with regard to the obligations of that entity under this Regulation; (37) ‘risk’ means risk as defined in Article 6, point (9) of Directive (EU) 2022/2555; (38) ‘risk impact matrix’ means a matrix used during risk assessment to determine the resulting risk impact level for each risk assessed; (39) ‘simultaneous electricity crisis’ means an electricity crisis as defined in Article 2, point (10) of Regulation (EU) 2019/941; (40) ‘single point of contact at entity level’ means single point of contact at entity level as designated under Article 38(1) point (c); (41) ‘stakeholder’ is any party that has an interest in the success and ongoing operation of an organisation or process such as employees, directors, shareholders, regulators, associations, suppliers and customers; (42) ‘standard’ means a standard as defined in Article 2(1) of Regulation (EU) No 1025/2012 of the European Parliament and of the Council  ( 16 ) ; (43) ‘system operation region’ means the system operation regions as defined in Annex I to ACER Decision 05-2022 on the Definition of System Operation Regions, established in accordance with Article 36 of Regulation (EU) 2019/943; (44) ‘system operators’ means ‘distribution system operator’ (DSO) and ‘transmission system operator’ (TSO) as defined in Articles 2(29) and 2(35) of Directive (EU) 2019/944; (45) ‘Union-wide critical-impact process’ means any electricity sector process, possibly involving multiple entities, for which the possible impact of a cyber-attack may be deemed critical during the performance of the Union-wide cybersecurity risk assessment; (46) ‘Union-wide high-impact process’ means any electricity sector process, possibly involving multiple entities, for which the possible impact of a cyber-attack may be deemed high during the performance of the Union-wide cybersecurity risk assessment; (47) ‘unpatched actively exploited vulnerability’ means a vulnerability, which has not yet been publicly disclosed and patched and for which there is reliable evidence that execution of malicious code was performed by an actor on a system without permission of the system owner; (48) ‘vulnerability’ means a vulnerability as defined in Article 6, point (15) of Directive (EU) 2022/2555.

Competent authority

Article 4

1.   As soon as possible and in any event by 13 December 2024, each Member State shall designate a national governmental or regulatory authority responsible for carrying out the tasks assigned to it in this Regulation (‘competent authority’). Until the competent authority has been assigned with carrying out the tasks under this Regulation, the regulatory authority designated by each Member State pursuant to Article 57(1) of Directive (EU) 2019/944 shall carry out the tasks of the competent authority in accordance with this Regulation. 2.   Member States shall, without delay, notify the Commission, ACER, ENISA, the NIS Cooperation Group established pursuant to Article 14 of Directive (EU) 2022/2555 and the Electricity Coordination Group set up under Article 1 of Commission Decision of 15 November 2012  ( 17 ) and communicate to them the name and the contact details of their competent authority designated pursuant to paragraph 1 of this article and any subsequent changes thereto. 3.   Member States may allow their competent authority to delegate tasks assigned to it in this Regulation to other national authorities with the exception of the tasks listed in Article 5. Each competent authority shall monitor the application of this Regulation by the authorities to whom it has delegated tasks. The competent authority shall communicate the name, contact details, assigned tasks and any subsequent changes thereto of the authorities to whom a task has been delegated to the Commission, to ACER, to the Electricity Coordination Group, to ENISA and to the NIS Cooperation Group.

Cooperation between relevant authorities and bodies at national level

Article 5

The competent authorities shall coordinate and ensure appropriate cooperation between the competent authorities responsible for cybersecurity, the cyber crisis management authorities, the NRAs, competent authorities for risk preparedness and CSIRTs for the purpose of the fulfilment of the relevant obligations laid down in this Regulation. The competent authorities shall also coordinate with any other bodies or authorities as determined by each Member State, to ensure efficient procedures and avoid duplications of tasks and obligations. The competent authorities shall be able to instruct the respective NRAs to request ACER for an opinion pursuant to Article 8(3).

Terms and conditions or methodologies or plans

Article 6

1.   TSOs shall develop, in cooperation with the EU DSO entity, proposals for the terms and conditions or methodologies pursuant to paragraph 2, or for plans pursuant to paragraph 3. 2.   The following terms and conditions or methodologies and any amendments thereof shall be subject to approval by all competent authorities: (a) the cybersecurity risk assessment methodologies pursuant to Article 18(1); (b) the comprehensive cross-border electricity cybersecurity risk assessment report pursuant to Article 23; (c) the minimum and advanced cybersecurity controls pursuant to Article 29, the mapping of electricity cybersecurity controls against standards pursuant to Article 34, including minimum and advanced cybersecurity controls in the supply chain in accordance with Article 33; (d) a cybersecurity procurement recommendation pursuant to Article 35; (e) the cyber-attacks classification scale methodology pursuant to Article 37(8). 3.   The proposals for the regional cybersecurity risk mitigation plans pursuant to Article 22 shall be subject to approval by all competent authorities of the concerned system operation region. 4.   The proposals for terms and conditions, methodologies listed in paragraph 2, or for plans listed in paragraph 3, shall include a proposed timescale for their implementation and a description of their expected impact on the objectives of this Regulation. 5.   The EU DSO entity may provide a reasoned opinion to the concerned TSOs until 3 weeks before the deadline to submit the proposal for terms and conditions or methodologies or plans to the competent authorities. TSOs responsible for the proposal for terms and conditions or methodologies or plans shall take into consideration the reasoned opinion of the EU DSO entity prior to its submission for competent authorities’ approval. TSOs shall provide reasoning where the EU DSO entity opinion is not taken into account. 6.   When jointly developing terms, conditions and methodologies and plans, the participating TSOs shall closely cooperate. TSOs, with the assistance of the ENTSO for Electricity, and in cooperation with the EU DSO entity, shall regularly inform competent authorities and ACER about the progress of developing the terms and conditions or methodologies, or plans.

Voting rules in the TSOs

Article 7

1.   Where TSOs deciding on proposals for terms and conditions or methodologies are not able to reach an agreement, they shall decide by qualified majority voting. A qualified majority for such proposals shall be calculated as follows: (a) TSOs representing at least 55 % of the Member States; and (b) TSOs representing Member States comprising at least 65 % of the population of the Union. 2.   A blocking minority for decisions on proposals for terms and conditions or methodologies listed in Article 6(2) shall include TSOs representing at least four Member States, failing of which the qualified majority shall be deemed attained. 3.   Where TSOs of a system operation region deciding on proposals for plans listed in Article 6(2) are not able to reach an agreement, and where the system operation region concerned is composed of more than five Member States, TSOs shall decide by qualified majority voting. A qualified majority for proposals listed in Article 6(2) shall require the following majority: (a) TSOs representing at least 72 % of the Member States concerned; and (b) TSOs representing Member States comprising at least 65 % of the population of the concerned area. 4.   A blocking minority for decisions on proposals for the plans shall include at least a minimum number of TSOs representing more than 35 % of the population of the participating Member States, plus TSOs representing at least one additional Member State concerned, failing of which the qualified majority shall be deemed attained. 5.   For TSO decisions on proposals for terms and conditions or methodologies pursuant to Article 6(2), one vote shall be attributed per Member State. If there is more than one TSO in the territory of a Member State, the Member State shall allocate the voting powers among the TSOs. 6.   If TSOs, in cooperation with the EU DSO entity, fail to submit an initial or amended proposal for terms and conditions or methodologies, or for plans, to the relevant competent authorities within the deadlines set out in this Regulation, they shall provide the relevant competent authorities and ACER with the relevant drafts of the terms and conditions or methodologies, or of the plans. They shall explain what has prevented an agreement. The competent authorities shall jointly take the appropriate steps for the adoption of the required terms and conditions or methodologies, or of the required plans. This may be done for instance by requesting amendments to the drafts pursuant to this paragraph, by revising and completing those drafts, or, where no drafts have been provided, by defining and approving the required terms and conditions or methodologies or plans.

Submission of proposals to the competent authorities

Article 8

1.   TSOs shall submit the proposals for terms and conditions or methodologies, or for plans for approval to the relevant competent authorities within the respective deadlines set out in Articles 18, 23, 29, 33, 34, 35 and 37. The competent authorities may jointly prolong these deadlines in exceptional circumstances, notably in cases where a deadline cannot be met due to circumstances external to the sphere of TSOs or of the EU DSO entity. 2.   Proposals for terms and conditions, methodologies or for plans pursuant to paragraph 1, shall be submitted for information to ACER at the same time that they are submitted to the competent authorities. 3.   Upon a joint request of the NRAs, ACER shall issue an opinion on the proposal for terms and conditions or methodologies, or for the plans, within six months of the receipt of the proposals for terms and conditions or methodologies, or for plans and notify NRAs and competent authorities of the opinion. NRAs, CS-NCAs and any other authorities designated as competent authorities shall coordinate with each other before the NRAs requests an opinion to ACER. ACER may include recommendations in such opinion. ACER shall consult ENISA before issuing an opinion on the proposals listed in Article 6(2). 4.   The competent authorities shall consult and closely cooperate and coordinate with each other in order to reach an agreement on the proposed terms and conditions, methodologies, or plans. Before approving the terms and conditions or methodologies, or the plans, they shall revise and complete the proposals where necessary, after consulting the ENTSO for Electricity and the EU DSO entity, in order to ensure that the proposals are in line with this Regulation and contribute to a high common level of cybersecurity across the Union. 5.   The competent authorities shall decide on the terms and conditions or methodologies or on the plans within six months following the receipt of the terms and conditions or methodologies or of the plans by the relevant competent authority or, where applicable, by the last relevant competent authority concerned. 6.   Where ACER issues an opinion, the relevant competent authorities shall take that opinion into account and shall take their decisions within six months from the receipt of ACER’s opinion. 7.   Where the competent authorities jointly require an amendment to the proposed terms and conditions or methodologies, or the plans, in order to approve them, the TSOs shall develop, in cooperation with the EU DSO entity, a proposal for such amendment to the terms and conditions or methodologies, or the plans. The TSOs shall submit the amended proposal for approval within two months following the request of the competent authorities. The competent authorities shall decide on the amended terms and conditions or methodologies, or plans, within two months following their submission. 8.   Where the competent authorities have not been able to reach an agreement within the period referred to in paragraph 5 or 7, they shall inform the Commission. The Commission may take appropriate steps to make possible the adoption of the required terms and conditions or methodologies, or plans. 9.   TSOs, with the assistance of the ENTSO for Electricity, and the EU DSO entity shall publish the terms and conditions or methodologies, or the plans, on their websites following approval by the relevant competent authorities, except where such information is considered as confidential in accordance with Article 47. 10.   The competent authorities may jointly request proposals for amendments of the approved terms and conditions or methodologies, or of the approved plans, from TSOs and the EU DSO entity and determine a deadline for the submission of those proposals. TSOs, in cooperation with the EU DSO entity, may propose amendments to the competent authorities also on its own initiative. The proposals for amendment to the terms and conditions or methodologies, or for the amendments to the plans, shall be developed and approved in accordance with the procedure set out in this Article. 11.   At least every three years after the first adoption of the respective terms and conditions or methodologies, or the respective adopted plans, TSOs in cooperation with the EU DSO entity, shall review the effectiveness of the adopted terms and conditions or methodologies, or the adopted plans, and shall report the findings of the review to the competent authorities and ACER without undue delay.

Consultation

Article 9

1.   TSOs, with the assistance of the ENTSO for Electricity, and in cooperation with the EU DSO entity shall consult stakeholders, including ACER, ENISA and the competent authority of each Member State, on the draft proposals for terms and conditions or methodologies listed in Article 6(2) and for plans referred to in Article 6(3). The consultation shall last for a period of not less than one month. 2.   The proposals for terms and conditions or methodologies listed in Article 6(2) submitted by the TSOs, in cooperation with the EU DSO entity, shall be published and submitted to consultation at Union level. The proposals for plans listed in Article 6(3) submitted by the relevant TSOs, in cooperation with the EU DSO entity, at regional level shall be submitted to consultation at least at regional level. 3.   TSOs, with the assistance of the ENTSO for Electricity, and the EU DSO Entity responsible for the proposal for terms and conditions or methodologies or plans shall duly take into account the views of stakeholders resulting from the consultations undertaken in accordance with paragraph 1, prior to its submission for regulatory approval. In all cases, a sound justification for including or not including the views resulting from the consultation shall be provided together with the submission and published in a timely manner before or simultaneously with the proposal for terms and conditions or methodologies.

Stakeholder involvement

Article 10

ACER, in close cooperation with ENTSO for Electricity and the EU DSO entity, shall organise stakeholder involvement, including regular meetings with stakeholders to identify problems and propose improvements related to the implementation of this Regulation.

Recovery of costs

Article 11

1.   The costs borne by TSOs and DSOs subject to network tariff regulation and stemming from the obligations laid down in this Regulation, including the costs borne by the ENTSO for Electricity and the EU DSO entity, shall be assessed by the relevant NRA of each Member State. 2.   Costs assessed as reasonable, efficient and proportionate shall be recovered through network tariffs or other appropriate mechanisms, as determined by the relevant NRA. 3.   If requested by the relevant NRAs, TSOs and DSOs referred to in paragraph 1 shall, within a reasonable period determined by the NRA, provide the information necessary to facilitate the assessment of the costs incurred.

Monitoring

Article 12

1.   ACER shall monitor the implementation of this Regulation in accordance with Article 32(1) of Regulation (EU) 2019/943 and Article 4(2) of Regulation (EU) 2019/942. In carrying out this monitoring, ACER may cooperate with ENISA and request support from the ENTSO for Electricity and the EU DSO entity. ACER shall regularly inform the Electricity Coordination Group and the NIS Cooperation Group on the implementation of this Regulation. 2.   ACER shall publish a report at least every three years after the entry into force of this Regulation to: (a) review the status of implementation of the applicable cybersecurity risk management measures with regard to the high-impact and critical-impact entities; (b) identify whether additional rules on common requirements, planning, monitoring, reporting and crisis management may be necessary to prevent risks for the electricity sector; and (c) identify areas of improvement for the revision of this Regulation, or determine uncovered areas and new priorities that may emerge due to technological developments. 3.   By 13 June 2025, ACER, in cooperation with ENISA and after consultation of the ENTSO for Electricity and the EU DSO entity, may issue guidance on the relevant information to be communicated to ACER for the monitoring purposes as well as the process and frequency for the collection, based on the performance indicators defined in accordance with paragraph 5. 4.   The competent authorities may have access to the relevant information held by ACER, which it has collected in accordance with this Article. 5.   ACER in cooperation with ENISA and with the support of the ENTSO for Electricity and the EU DSO entity, shall issue non-binding performance indicators for the assessment of operational reliability that are related to cybersecurity aspects of cross-border electricity flows. 6.   The entities listed in Article 2(1) of this Regulation shall submit to ACER the information required for ACER to perform the tasks listed in paragraph 2.

Benchmarking

Article 13

1.   By 13 June 2025, ACER, in cooperation with ENISA, shall establish a non-binding cybersecurity benchmarking guide. The guide shall explain to NRAs the principles of benchmarking of the implemented cybersecurity controls pursuant to paragraph 2 of this Article, taking into consideration the costs of implementing the controls and the effectiveness of the function played by processes, products, services, systems and solutions used to implement such controls. ACER shall take into account existing benchmarking reports when establishing the non-binding cybersecurity benchmarking guide. ACER shall submit the non-binding cybersecurity benchmarking guide to the NRAs for information. 2.   Within 12 months after the establishment of the benchmarking guide pursuant to paragraph 1, the NRAs shall carry out a benchmarking analysis to assess whether current investments in cybersecurity: (a) mitigate risks having an impact on cross-border electricity flows; (b) provide the desired results and engender efficiency gains for the development of the electricity systems; (c) are efficient and integrated into the overall procurement of assets and services. 3.   For the benchmarking analysis, the NRAs may take into account the non-binding cybersecurity benchmarking guide established by ACER, and shall assess in particular: (a) the average expenditure related to cybersecurity for mitigating risks having an impact on electricity cross-border flows, especially with respect to the high-impact and critical-impact entities; (b) in cooperation with the ENTSO for Electricity and the EU DSO entity, the average prices of cybersecurity services, systems and products that contribute to a large extent to the enhancement and maintenance of the cybersecurity risk-management measures in the different system operation regions; (c) the existence and level of comparability of costs and functions of cybersecurity services, systems and solutions suitable for the implementation of this Regulation, identifying possible measures necessary to foster efficiency in spending, particularly where cybersecurity technological investments may be needed. 4.   Any information related to benchmarking analysis shall be handled and processed pursuant to data classification requirements of this Regulation, the minimum cybersecurity controls and the cross-border electricity cybersecurity risk assessment report. The benchmarking analysis referred to in paragraphs 2 and 3 shall not be made public. 5.   Without prejudice to the confidentiality requirements in Article 47 and to the need to protect the security of entities subject to the provisions of this Regulation, the benchmarking analysis referred in paragraphs 2 and 3 of this Article shall be shared with all NRAs, all competent authorities, ACER, ENISA and the Commission.

Agreements with TSOs from outside the Union

Article 14

1.   Within 18 months after the entry into force of this Regulation, TSOs of a system operation region that is neighbouring to a third country shall endeavour to conclude agreements with TSOs of the neighbouring third country that are in accordance with relevant Union law and that set out the basis for cooperation on cybersecurity protection and the cybersecurity cooperation arrangements with those TSOs. 2.   TSOs shall inform the competent authority of the agreements concluded pursuant to paragraph 1.

Legal representatives

Article 15

1.   Entities who do not have an establishment in the Union, but who deliver services to entities in the Union and have been notified as being high-impact or critical-impact entities in accordance with Article 24(6), shall, within three months after the notification, designate, in writing, a representative in the Union and inform the notifying competent authority accordingly. 2.   This representative shall be mandated for the purpose of being addressed by any competent authority or a CSIRT in the Union in addition to or instead of the high-impact or critical-impact entity with regard to the obligations of the entity under this Regulation. The high-impact or critical-impact entity shall provide their legal representative with the necessary powers and sufficient resources to guarantee their efficient and timely cooperation with the relevant competent authorities or CSIRTs. 3.   The representative shall be established in one of the Member States where the entity offers its services. The entity shall be deemed to be under the jurisdiction of the Member State where the representative is established. High-impact or critical-impact entities shall notify the name, postal address, email address and telephone number of their legal representative to the competent authority in the Member State where that legal representative resides or is established. 4.   It shall be possible for the designated legal representative to be held liable for non-compliance with obligations under this Regulation, without prejudice to the liability and legal actions that could be initiated against the high-impact or critical-impact entity itself. 5.   In the absence of a representative within the Union designated under this Article, any Member State in which the entity provides services may take legal action against the entity for non-compliance with the obligations under this Regulation. 6.   The designation of a legal representative within the Union pursuant to paragraph 1 shall not constitute an establishment in the Union.

Cooperation between the ENTSO for Electricity and the EU DSO Entity

Article 16

1.   The ENTSO for Electricity and the EU DSO entity shall cooperate in performing cybersecurity risk assessments pursuant to Article 19 and Article 21, and in particular the following tasks: (a) development of the cybersecurity risk assessment methodologies pursuant to Article 18(1); (b) development of the Comprehensive Cross-border electricity cybersecurity risk assessment report pursuant to Article 23; (c) development of the common electricity cybersecurity framework pursuant to Chapter III; (d) development of the cybersecurity procurement recommendation pursuant to Article 35; (e) development of the cyber-attacks classification scale methodology pursuant to Article 37(8); (f) development of the provisional electricity cybersecurity impact index (‘ECII’) electricity cybersecurity impact index pursuant to Article 48(1) point (a); (g) development of the consolidated provisional list of high-impact and critical-impact entities pursuant to Article 48(3); (h) development of the provisional list of Union-wide high-impact and critical-impact processes pursuant to Article 48(4); (i) development of the provisional list of European and international standards and controls pursuant to Article 48(6); (j) performance of the Union-wide cybersecurity risk assessment pursuant to Article 19; (k) performance of the regional cybersecurity risk assessments pursuant to Article 21; (l) definition of the regional cybersecurity risk mitigation plans pursuant to Article 22; (m) development of guidance on European cybersecurity certification schemes for ICT products, ICT services, and ICT processes in accordance with Article 36; (n) development of guidelines for the implementation of this Regulation in consultation with ACER and ENISA. 2.   The cooperation between the ENTSO for Electricity and the EU DSO entity may take the form of a cybersecurity risk working group. 3.   The ENTSO for Electricity and the EU DSO entity shall regularly inform ACER, ENISA, the NIS Cooperation Group and the Electricity Coordination Group on the progress in implementing the Union-wide and regional cybersecurity risk assessments pursuant to Article 19 and Article 21.

Cooperation between ACER and the competent authorities

Article 17

ACER, in cooperation with each competent authority, shall: (1) monitor the implementation of cybersecurity risk management measures pursuant to Article 12(2) point (a) and reporting obligations pursuant to Article 27 and Article 39; and (2) monitor the adoption process and the implementation of the terms and conditions, methodologies or plans pursuant to Article 6(2) and (3). The cooperation between ACER, ENISA and each competent authority may take the form of a cybersecurity risk monitoring body.

Back to Commission Delegated Regulation (EU) 2024/1366 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next