Two regimes, one grid
Most cybersecurity conversations in the European energy sector begin and end with NIS2. That is a mistake, because since 13 June 2024 there has been a second binding instrument specifically for electricity: Regulation (EU) 2024/1366, the Network Code on Cybersecurity, generally shortened to NCCS. It began applying on 2 July 2025.
NIS2 is a horizontal directive transposed differently in each member state. NCCS is a regulation, which means it applies directly and identically across the union, and it targets cross-border electricity flows specifically. An organisation that operates transmission or distribution infrastructure, significant generation assets, or ICT services to those operators is likely in scope of both - and the two do not ask for the same things.
What NCCS adds that NIS2 does not
The additions are structural rather than cosmetic. NCCS introduces a classification of entities by cross-border electricity impact, union-wide risk assessments on a recurring multi-year cycle, minimum cybersecurity controls defined at sector level rather than left to national discretion, cybersecurity certification requirements for products and services in the electricity chain, and cross-border crisis management obligations that assume an incident in one country becomes an operational problem in three.
Read as a set, these push in one direction: the electricity sector is being asked to produce evidence that is comparable across borders. A Portuguese DSO and a Dutch DSO should be able to demonstrate the same controls in the same terms to different supervisors. That is a much harder standard than 'satisfy your own national regulator', and it changes what evidence has to look like.
The certification problem
The requirement that draws least attention and creates most work is product and service certification. NIS2 asks entities to manage supply chain risk. NCCS moves toward asking whether specific products and services in the electricity chain hold recognised cybersecurity certification.
The operational difference is significant. Managing supply chain risk is something you can do with questionnaires, contract clauses, and a register. Demonstrating that deployed components hold current certification requires knowing, continuously, what is actually deployed and what its certification status is today - not what it was when procurement signed. Asset inventories drift. Certifications expire. Firmware gets updated by a vendor without a change ticket on your side.
The entities that handle this well treat the deployed-asset record as a live, verifiable artefact rather than a spreadsheet reconciled quarterly. We described the same structural problem in a financial services context in our guide to DORA ICT third-party risk management, and the solution shape is identical even though the regulator is different.
Cross-border crisis management changes the evidence question
In a single-jurisdiction incident, evidence is a conversation between an operator and its national supervisor, conducted after the fact, in a shared language and legal context. In a cross-border electricity incident, evidence has to travel: to a second national supervisor with a different transposition, to ENTSO-E and regional coordination structures, and potentially into a dispute about causation between commercial parties.
Evidence that travels well has a specific property. It can be verified by a party that does not trust the organisation that produced it. Logs exported from an operator's own SIEM do not have this property, not because they are untrue but because there is no way for a third party to distinguish an unaltered export from a curated one. Independently verifiable records do have it, which is why the cross-border dimension of NCCS quietly pushes the sector toward cryptographic integrity whether or not the text uses that language.
A practical readiness sequence
- Confirm whether your entity falls inside the NCCS impact classification, and at what level - this determines almost everything downstream
- Map your existing NIS2 control evidence against NCCS requirements and mark the gaps, rather than starting a parallel programme
- Build a live deployed-asset record covering OT and IT components in the electricity chain, including certification status and firmware version
- Define which incident evidence must be shareable with a supervisor in another member state, and confirm it is verifiable without your cooperation
- Test the cross-border notification path before you need it, and keep the test evidence
For integrators serving the energy sector
NCCS is an unusually good opportunity for systems integrators and resellers working with utilities. The regime is new enough that in-house teams have not built expertise, specific enough that generic NIS2 consultancy does not cover it, and evidence-heavy enough that the work does not end at assessment.
If you deliver cybersecurity or compliance services into the European electricity sector, the ROOTKey integrator programme exists for exactly this pattern of engagement. If you operate the infrastructure yourself, the fastest way to see what a verifiable evidence layer looks like against your own records is to try it on a single asset register.
在邮箱中获取网络韧性洞见
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。





