My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1366 CHAPTER V — INFORMATION FLOWS, CYBER-ATTACKS AND CRISIS MANAGEMENT

Article 37–Article 42 · 6 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Rules on information sharing

Article 37

1.   If a competent authority receives information related to a reportable cyber-attack, that competent authority: (a) shall assess the level of confidentiality of that information and inform the entity about the outcome of its assessment without undue delay and not later than within 24 hours of receipt of the information; (b) shall attempt to find any other similar cyber-attack in the Union reported to other competent authorities, in order to correlate the information received in the context of the reportable cyber-attack with information provided in the context of other cyber-attacks and enrich existing information, strengthen and coordinate cybersecurity responses; (c) shall be responsible for the removal of business secrets and the anonymisation of the information in accordance with the relevant national and Union rules; (d) shall share the information with the national single points of contact, CSIRTs and all competent authorities designated pursuant to Article 4 in other Member States without undue delay and no later than 24 hours after the reception of a reportable cyber-attack and provide updated information on a regular basis to those authorities or bodies; (e) shall disseminate the information of the cyber-attack, after anonymisation and removal of business secrets pursuant to paragraph 1(c), to critical-impact and high-impact entities in its Member State without undue delay and no later than 24 hours after receiving information according to paragraph 1(a), and provide updated information on a regular basis allowing the entities to organise their defence effectively; (f) may request the reporting high-impact or critical-impact entity to further disseminate the reportable cyber-attack information in a secure manner to other entities that may be affected, with the aim to generate situational awareness by the electricity sector and to prevent the materialisation of a risk that may escalate in a cross-border cybersecurity electricity incident; (g) shall share with ENISA a summary report, after anonymisation and removal of business secrets, with the information of the cyber-attack. 2.   If a CSIRT becomes aware of an unpatched actively exploited vulnerability, it shall: (a) share it with ENISA via an appropriate secure information exchange channel without delay, unless otherwise specified in other Union law; (b) support the concerned entity to receive from the manufacturer or provider an effective, coordinated and rapid management of the unpatched actively exploited vulnerability or of effective and efficient mitigation measures; (c) share available information with the vendor and request the manufacturer or provider, where possible, to identify a list of CSIRTs in Member States concerned by the unpatched actively exploited vulnerability and that shall be informed; (d) share available information with the CSIRTs identified under the previous point, based on need-to-know principle; (e) share, where they exist, mitigation strategies and measures to the reported unpatched actively exploited vulnerability. 3.   If a competent authority becomes aware of an unpatched actively exploited vulnerability, that competent authority shall: (a) share, where they exist, mitigation strategies and measures to the reported unpatched actively exploited vulnerability, in coordination with the CSIRTs in its Member State; (b) shall share the information with a CSIRT in the Member State where the unpatched actively exploited vulnerability has been reported. 4.   If the competent authority becomes aware of an unpatched vulnerability, without evidence of yet being actively exploited, it shall without undue delay coordinate with the CSIRT for the purposes of coordinated vulnerability disclosure as laid down in Article 12(1) of Directive (EU) 2022/2555. 5.   If a CSIRT receives information related to cyber threats from one or several high-impact or critical-impact entities pursuant to Article 38(6), it shall disseminate that information or any other information of importance for preventing, detecting, responding to or mitigating the related risk to critical-impact and high-impact entities in its Member State and, where appropriate, to all concerned CSIRTs and to its national single point of contact without undue delay and no later than four hours after receiving information. 6.   If a competent authority becomes aware of information related to cyber threats from one or several high-impact or critical-impact entities, it shall forward this information to the CSIRT for the purpose of paragraph 5. 7.   The competent authorities may delegate in full or in part the responsibilities under paragraphs 3 and 4 concerning one or more high-impact or critical-impact entities that operate in more than one Member State to another competent authority in one of those Member States, following an agreement among the concerned competent authorities. 8.   The TSOs, with the assistance of the ENTSO for Electricity, and in cooperation with the EU DSO entity shall develop a cyber-attack classification scale methodology by 13 June 2025. The TSOs, with the assistance of the ENTSO for Electricity and the EU DSO entity may request the competent authorities to consult ENISA and their competent authorities responsible for cybersecurity for assistance in the development of such classification scale. The methodology shall provide the classification for the gravity of a cyber-attack according to five levels, the two highest levels being ‘high’ and ‘critical’. The classification shall be based on the assessment of the following parameters: (a) the potential impact considering the assets and perimeters exposed determined in accordance with Article 26(4), point (c); and (b) the severity of the cyber-attack. 9.   By 13 June 2026, the ENTSO for Electricity, in collaboration with the EU DSO entity, shall perform a feasibility study to assess the possibility and the financial costs necessary to develop a common tool enabling all entities to share information with relevant national authorities. 10.   The feasibility study shall address the possibility for such a common tool to: (a) support critical-impact and high-impact entities with relevant security related information for operations of cross-border electricity flows, such as near real-time reporting of cyber-attacks, early alerts related to cybersecurity matters and undisclosed vulnerabilities on equipment in use in the electricity system; (b) be maintained in a suitable and highly trustable environment; (c) allow for data collection from critical-impact and high-impact entities and facilitate removal of confidential information and anonymisation of the data and their prompt dissemination to critical-impact and high-impact entities. 11.   The ENTSO for Electricity, in cooperation with the EU DSO entity, shall: (a) consult ENISA and the NIS Cooperation Group, the national single points of contact and the representatives of main stakeholders when assessing the feasibility; (b) present the results of the feasibility study to ACER and the NIS Cooperation Group. 12.   The ENTSO for Electricity, in cooperation with the EU DSO entity may analyse and facilitate initiatives proposed by critical-impact and high-impact entities to evaluate and test such tools for information sharing.

Role of high-impact and critical-impact entities as regards information sharing

Article 38

1.   Each high-impact and critical-impact entity shall: (a) establish, for all assets within its cybersecurity perimeter determined pursuant to Article 26(4) point (c), at least the CSOC capabilities to: (i) ensure that the relevant network and information systems and applications provide security logs for security monitoring to enable the detection of anomalies and collect information on cyber-attacks; (ii) conduct security monitoring, including detecting intrusions and assessing vulnerabilities of network and information systems; (iii) analyse and, if necessary, take all actions required under its responsibility and capacity to protect the entity; (iv) participate in the information collection and sharing described in this Article; (b) have the right to procure all or parts of these capabilities pursuant to point (a) through MSSPs. Critical-impact and high-impact entities shall remain responsible for MSSPs and supervise their efforts; (c) designate a single point of contact at entity level for the purpose of information sharing. 2.   ENISA may issue non-binding guidance on establishing such capabilities or subcontracting the service to MSSPs, as part of the task defined in Article 6(2) of Regulation (EU) 2019/881. 3.   Each critical-impact and high-impact entity shall share relevant information related to a reportable cyber-attack with its CSIRTs and its competent authority without undue delay and no later than four hours of becoming aware that the incident is reportable. 4.   Information related to a cyber-attack shall be considered reportable when the cyber-attack is assessed by the affected entity resulting in a criticality ranging from ‘high’ to ‘critical’ following the cyber-attack classification scale methodology pursuant to Article 37(8). The single point of contact at entity level designated pursuant to paragraph 1 point (c) shall communicate the incident classification. 5.   Where critical-impact and high-impact entities notify relevant information related to unpatched actively exploited vulnerabilities to a CSIRT, the latter may forward this information to its competent authority. In light of the level of sensitivity of the notified information, the CSIRT may withhold the information or delay its forwarding based on justified cybersecurity-related grounds. 6.   Each critical-impact and high-impact entity shall provide without undue delay to its CSIRTs any information related to a reportable cyber threat that may have a cross-border effect. Information related to a cyber threat shall be considered reportable when at least one of the following conditions is met: (a) it provides relevant information for other critical-impact and high-impact entity for preventing, detecting, responding or mitigating the impact of the risk; (b) the identified techniques, tactics and procedures used in the context of an attack lead to information such as compromised URL or IP addresses, hashes or any other attribute useful to contextualise and correlate the attack; (c) a cyber threat may be further assessed and contextualised with additional information provided by service providers or third parties not subject to this Regulation. 7.   Each critical-impact entity and high-impact entity shall, when sharing information pursuant to this Article, specify the following: (a) that the information is submitted pursuant to this Regulation; (b) whether the information concerns: (i) a reportable cyber-attack referred to in paragraph 3; (ii) unpatched actively exploited vulnerabilities not publicly known referred to in paragraph 4; (iii) a reportable cyber threat referred to in paragraph 5; (c) in the case of a reportable cyber-attack, the level of the cyber-attack according to the cyber-attack classification scale methodology referred to in Article 37(8) and information leading to this classification including at least the criticality of the cyber-attack. 8.   When a critical or high-impact entity notifies a significant incident pursuant to Article 23 of Directive (EU) 2022/2555 and the incident reporting under that Article contains relevant information as required under paragraph 3 of this Article, the reporting of the entity under Article 23(1) of that Directive shall constitute reporting of information under paragraph 3 of this Article. 9.   Each critical-impact and high-impact entity shall report to its competent authority or CSIRT by clearly identifying specific information that shall only be shared with the competent authority or CSIRT in cases where the information sharing could be source of a cyber-attack. Each critical-impact and high-impact entity shall have the right to provide a non-confidential version of the information to the competent CSIRT.

Detection of cyber-attacks and handling of related information

Article 39

1.   Critical-impact and high-impact entities shall develop the necessary capabilities to handle detected cyber-attacks with the necessary support from the relevant competent authority, the ENTSO for Electricity and the EU DSO entity. The critical-impact and high-impact entities may be supported by the CSIRT designated in their respective Member State as part of the task assigned to the CSIRTs by Article 11(5), point (a) of Directive (EU) 2022/2555. Critical-impact and high-impact entities shall implement effective processes to identify, classify and respond to cyber-attacks that will or may affect cross-border electricity flows in order to minimise their impact. 2.   If a cyber-attack has an effect on cross-border electricity flows, the single points of contact at entity level of affected critical-impact and high-impact entities shall cooperate to share information among them, coordinated by the competent authority of the Member State in which the cyber-attack was first reported. 3.   Critical-impact and high-impact entities shall: (a) ensure that their own single point of contact at entity level has access on a need-to-know basis to the information they received from the national single point of contact through their competent authority; (b) unless already done pursuant to Article 3(4) of Directive (EU) 2022/2555, notify the competent authority of the Member State in which they are established and the national single point of contact with a list of their cybersecurity single points of contact at entity level: (i) from which that competent authority and national single point of contact may expect to receive information about reportable cyber-attacks; (ii) to which competent authorities and national single points of contact may have to provide information; (c) establish cyber-attack management procedures for cyber-attacks, including roles and responsibilities, tasks and reactions based on the observable evolution of the cyber-attack within the critical-impact and high-impact perimeters; (d) test the overall cyber-attack management procedures at least every year by testing at least one scenario affecting directly or indirectly cross-border electricity flows. That annual test may be conducted by critical-impact and high-impact entities during the regular exercises referred to in Article 43. Any live cyber-attack response activity with a consequence classified at least Scale 2, according to the cyber-attack classification scale methodology referred to in Article 37(8) and with a cybersecurity root cause, may serve as an annual test of the cyber-attack response plan. 4.   The tasks referred to in paragraph 1 may be delegated by the Member States also to the Regional Coordination Centres in accordance with Article 37(2) of Regulation (EU) 2019/943.

Crisis management

Article 40

1.   When the competent authority establishes that an electricity crisis is related to a cyber-attack which has an impact on more than one Member State, the competent authorities from the affected Member States, the CS-NCAs, the RP-NCA and the NIS cyber crisis management authorities from the affected Member States shall jointly create an ad hoc cross-border crisis coordination group. 2.   The ad hoc cross-border crisis coordination group shall: (a) coordinate the efficient retrieval and further dissemination of all relevant cybersecurity information to the entities involved in the crisis management process; (b) organise the communication between all the entities impacted by the crisis and the competent authorities, in order to reduce overlaps and increase the efficiency in the analyses and technical responses to remedy the simultaneous electricity crises with a cybersecurity root cause; (c) provide, in cooperation with the competent CSIRTs, the expertise required, including operational advice on the implementation of possible mitigation measures to the entities impacted by the incident; (d) notify and provide regular updates on the state of the incident to the Commission and the Electricity Coordination Group, following the protection principles laid down in Article 46; (e) seek advice from relevant authorities, agencies or entities that might be of help to mitigate the electricity crisis. 3.   Where the cyber-attack qualifies or is expected to qualify as a large-scale cybersecurity incident, the ad hoc cross-border crisis coordination group shall immediately inform the national cyber crisis management authorities in accordance with Article 9(1) of Directive (EU) 2022/2555 in the Member States affected by the incident, as well as the Commission and the EU CyCLONe. In such situation, the ad hoc cross-border crisis coordination group shall support the EU CyCLONe concerning sectoral specificities. 4.   Critical-impact and high-impact entities shall develop and have at their disposal capabilities, internal guidelines, preparedness plans, and staff to take part in the detection and mitigation of cross-border crisis. The critical-impact or high-impact entity impacted by a simultaneous electricity crisis shall investigate the root cause of such crisis in cooperation with its competent authority to determine the extent to which the crisis is related to a cyber-attack. 5.   The tasks in paragraph 4 may be delegated by the Member States also to the Regional Coordination Centres in accordance with Article 37(2) of Regulation (EU) 2019/943.

Cybersecurity crisis management and response plans

Article 41

1.   Within 24 months after the notification to ACER of the Union-wide risk assessment report, ACER shall in close cooperation with ENISA, the ENTSO for Electricity, the EU DSO entity, CS-NCAs, competent authorities, RP-NCAs, the NRAs and the NIS national cyber crisis management authorities, develop a Union-level cybersecurity crisis management and response plan for the electricity sector. 2.   Within 12 months after the development by ACER of the Union-level cybersecurity crisis management and response plan for the electricity sector pursuant to paragraph 1, each competent authority shall develop a national cybersecurity crisis management and response plan for cross-border electricity flows taking into account the Union-level cybersecurity crisis management plan and the national risk preparedness plan established in accordance with Article 10 of Regulation (EU) 2019/941. This plan shall be consistent with the large-scale cybersecurity incident and crisis response plan pursuant to Article 9(4) of Directive (EU) 2022/2555. The competent authority shall coordinate with the critical-impact and high-impact entities and with the RP-NCA in its Member State. 3.   The national large-scale cybersecurity incident and crisis response plan required pursuant to Article 9(4) of Directive (EU) 2022/2555 shall be considered as a national cybersecurity crisis management plan under this Article if it includes crisis management and response provisions for the cross-border electricity flows. 4.   The tasks listed in at paragraphs 1 and 2 may be delegated by the Member States also to the Regional Coordination Centres in accordance with Article 37(2) of Regulation (EU) 2019/943. 5.   Critical-impact and high-impact entities shall ensure that their cybersecurity-related crisis management processes: (a) have compatible cross-border cybersecurity incident handling procedures as defined in Article 6(8) of Directive (EU) 2022/2555 formally incorporated in their crisis management plans; (b) are part of the general crisis management activities. 6.   Within 12 months after the notification of the high-and critical-impact entities pursuant to Article 24(6), and every three years thereafter, critical impact and high-impact entities shall develop a crisis management plan at entity level for a cybersecurity related crisis which shall be included into their general crisis management plans. This plan shall include at least the following: (a) rules of declaration of the crisis as set out in Article 14(2) and (3) of the Regulation (EU) 2019/941; (b) clear roles and responsibilities for crisis management, including the role of other relevant critical-impact and high-impact entities; (c) up-to-date contact information as well as rules for communication and information sharing during a crisis situation including the connection to the CSIRTs. 7.   The measures for crisis management pursuant to Article 21(2), point (c) of Directive (EU) 2022/2555 shall be considered as a crisis management plan at entity level for the electricity sector under this Article if it includes all requirements listed in paragraph 6. 8.   The crisis management plans shall be tested during the cybersecurity exercises referred to in Articles 43, 44 and 45. 9.   The critical-impact and high-impact entities shall include their crisis management plans at entity level into their business continuity plans for the critical-impact and high-impact processes. The crisis management plans at entity level shall include: (a) processes depending on availability, integrity and reliability of IT services; (b) all business continuity locations including the locations for hardware and software; (c) all internal roles and responsibilities connected to business continuity processes. 10.   The critical-impact and high-impact entities shall update their crisis management plans at entity level at least every three years and whenever necessary. 11.   ACER shall update the Union-level cybersecurity crisis management and response plan for the electricity sector developed pursuant to paragraph (1) at least every three years and whenever necessary. 12.   Each competent authority shall update the national cybersecurity crisis management and response plan for cross-border electricity flows developed pursuant to paragraph (2) at least every three years and whenever necessary. 13.   The critical-impact and high-impact entities shall test their business continuity plans at least once every three years or after major changes in a critical-impact process. The outcome of the business continuity plan tests shall be documented. The critical-impact and high-impact entities may include the test of their business continuity plan in the cybersecurity exercises. 14.   The critical-impact and high-impact entities shall update their business continuity plan whenever necessary and at least once every three years taking into account the outcome of the test. 15.   If a test identifies deficiencies in the business continuity plan, the critical-impact and high-impact entity shall correct those deficiencies within 180 calendar days after the testing and shall conduct a new test to provide evidence that the corrective measures are effective. 16.   Where a critical-impact or high-impact entity cannot correct the deficiencies within 180 calendar days, it shall include the reasons in the report to be provided to its competent authority in accordance with Article 27.

Cybersecurity early alert capabilities for the electricity sector

Article 42

1.   The competent authorities shall cooperate with ENISA to develop Electricity Cybersecurity Early Alert Capabilities (ECEAC) as part as the assistance to Member States pursuant to Articles 6(2) and (7) of Regulation (EU) 2019/881. 2.   The ECEAC shall enable ENISA when carrying out the tasks listed in Article 7(7) of Regulation (EU) 2019/881 to: (a) collect voluntary shared information from: (i) CSIRTs, competent authorities; (ii) the entities listed in Article 2 of this Regulation; (iii) any other entity that wants to share relevant information on a voluntary basis; (b) assess and classify collected information; (c) assess the information ENISA has access to for identifying cyber risk conditions and relevant indicators for aspects of cross-border electricity flows; (d) identify conditions and indicators that frequently correlate with cyber-attacks within the electricity sector; (e) define whether further analysis and preventive actions shall be taken through assessment and identification of risk factors; (f) inform the competent authorities on the identified risks and recommended preventive actions specific to the entities concerned; (g) inform all relevant entities listed in Article 2 on the results of the information assessed in accordance with points (b), (c) and (d) of this paragraph; (h) periodically include the relevant information in the situational awareness report, issued in accordance with Article 7(6) of Regulation (EU) 2019/881; (i) derive, where possible, applicable data that indicates that a potential security breach or cyber-attack (‘indicators of compromise’) from the collected information. 3.   The CSIRTs shall disseminate the information received from ENISA to the entities concerned without delay, within their tasks defined in Article 11(3), point (b) of Directive (EU) 2022/2555. 4.   ACER shall monitor the effectiveness of the ECEAC. ENISA shall assist ACER by providing all necessary information, pursuant to Articles 6(2) and 7(1) of Regulation (EU) 2019/881. The analysis of this monitoring activity shall be part of the monitoring pursuant to Article 12 of this Regulation.

Back to Commission Delegated Regulation (EU) 2024/1366 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next