My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1366 CHAPTER VIII — FINAL PROVISIONS

Article 48–Article 49 · 2 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Temporary provisions

Article 48

1.   Until the approval of the terms and conditions or methodologies referred to in Article 6(2) or plans referred to in Article 6(3), the ENTSO for Electricity, in cooperation with the EU DSO entity, shall develop non-binding guidance on the following issues: (a) a provisional electricity cybersecurity impact index (‘ECII’) pursuant to paragraph 2 of this Article; (b) a provisional list of Union-wide high-impact and critical-impact processes pursuant to paragraph 4 of this Article; and (c) a provisional list of European and international standards and controls required by national legislation with relevance for cybersecurity aspects of cross-border electricity flows pursuant to paragraph 6 of this Article. 2.   By 13 October 2024, the ENTSO for Electricity, in cooperation with the EU DSO entity, shall develop a recommendation for a provisional ECII. The ENTSO for Electricity, in cooperation with the EU DSO entity, shall notify the recommended provisional ECII to the competent authorities. 3.   Four months of receipt of the recommended provisional ECII, or the latest by 13 February 2025, the competent authorities shall identify candidates for high-impact and critical-impact entities in their Member State based on the recommended ECII and shall develop a provisional list of high-impact and critical-impact entities. The high-impact and critical-impact entities identified in the provisional list may voluntarily fulfil their obligations as laid down in this Regulation based on a precautionary principle. By 13 March 2025, the competent authorities shall notify the entities identified in the provisional list that they have been identified as a high-impact or critical-impact entity. 4.   By 13 December 2024, the ENTSO for Electricity, in cooperation with the EU DSO entity, shall develop a provisional list of Union-wide high-impact and critical-impact processes. The entities notified pursuant to paragraph (3) that voluntarily decide to fulfil their obligations as laid down in this Regulation based on a precautionary principle shall use the provisional list of high-impact and critical-impact processes to determine the provisional high-impact and critical-impact perimeters and to determine which assets are to be included in the first cybersecurity risk assessment at entity level. 5.   By 13 September 2024, each competent authority according to Article 4 (1) shall provide a list of its national legislation with relevance for cybersecurity aspects of cross-border electricity flows to the ENTSO for Electricity and the EU DSO entity. 6.   By 13 June 2025, the ENTSO for Electricity, in cooperation with the EU DSO entity, shall prepare a provisional list of European and international standards and controls required by national legislation with relevance for cybersecurity aspects of cross-border electricity flows, taking into account the information provided by the competent authorities. 7.   The provisional list of European and international standards and controls shall include: (a) European and international standards and national legislation which provide guidance on methodologies for cybersecurity risk management at entity level; and (b) cybersecurity controls equivalent to the controls that are expected to be part of the minimum and advanced cybersecurity controls. 8.   The ENTSO for Electricity and the EU DSO entity shall take into account the views provided by ENISA and ACER when finalising the provisional list of standards. The ENTSO for Electricity and the EU DSO entity shall publish the transitional list of European and international standards and controls on their websites. 9.   The ENTSO for Electricity and the EU DSO entity shall consult ENISA and ACER on the proposals for non-binding guidance developed pursuant to paragraph 1. 10.   Until the minimum and advanced cybersecurity controls are developed pursuant to Article 29 and adopted pursuant to Article 8, all entities listed in Article 2(1) shall strive to progressively apply the non-binding guidance developed pursuant to paragraph 1.

Entry into force

Article 49

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Back to Commission Delegated Regulation (EU) 2024/1366 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next