Two engineers in helmets stand at the security fence of a high-voltage substation looking at transformers and steel gantries

NCCS: The Network Code on Cybersecurity, the Duties for TSOs and DSOs

The first EU cyber rulebook just for the electricity sector is ramping up, and 2026 is the year of preparation

A cyberattack on a substation in one country can drag down the neighbours' grid. That is exactly what a dedicated EU regulation now addresses. Anyone controlling more than 1,500 megawatts should know it.

Summary

The network code on cybersecurity (Commission Delegated Regulation (EU) 2024/1366, NCCS) has been in force since 13 June 2024 and is the first sector-specific EU cyber rulebook for electricity. It classifies actors by their effect on cross-border electricity flows: high-impact from a provisional German threshold of 1,500 MW, critical-impact from 3,000 MW. Designated entities must build a cybersecurity management system, run risk assessments, undergo a full external audit at least every three years and report cyberattacks under the CACS scale. The roadmap is staggered: Union-wide risk report in mid-2026, controls proposal in early 2027, formal designation in mid-2027, first entity reports in 2028. For German grid operators the NCCS adds to NIS2 and the IT security catalogue under Section 5c EnWG; compliance evidence may be used across frameworks. 2026 is the year for self-assessment, gap analysis and supplier contracts.

The first EU cyber rulebook just for electricity

Every energy utility knows NIS2 by now. The NCCS is something different. Not a cross-sector law for all critical industries, but a regulation that asks a single question: what happens to cross-border electricity flows if someone hacks you?

The answer sits in Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024, in force since 13 June 2024. It supplements the electricity market regulation 2019/943 and thereby moves cybersecurity to where the European power system is governed anyway: into the network codes.

13 Jun 2024
the NCCS has been in force since this day
1,500 MW
marks the provisional German high-impact threshold
2028
designated entities deliver their first risk reports

Why a dedicated rulebook? Because the power grid is Europe's most tightly coupled critical sector. A bank can be hacked nationally. A transmission grid cannot. Frequency and load flows stop at no border, so the regulation no longer does either.

Who is covered: far more than TSOs and DSOs

Strictly speaking, the title of this page is too narrow. TSOs and DSOs are the core addressees, but the NCCS reaches everywhere a disruption could hit cross-border flows. The list is long.

  • Transmission and distribution system operators
  • Generators, storage operators, aggregators and demand response providers
  • NEMOs and electricity market platforms, balancing responsible parties
  • Regional coordination centres, ENTSO-E and the EU DSO Entity itself
  • Critical ICT service providers and managed security providers
  • Operators of recharging points

The last item surprises many. Charge point operators sit on the same list as transmission operators, because controllable load becomes grid-relevant in aggregate. One more peculiarity: companies outside the EU can also be designated if their systems influence European electricity flows.

The yardstick is impact, not size

The NCCS does not ask how many employees or customers a company has. It asks what a successful attack on its systems would mean for cross-border electricity flows. A small service provider with privileged access to control systems can matter more than a large retail arm with no grid connection.

The classification: ECII, high-impact and critical-impact

The heart of the NCCS is a two-tier classification. The measure is the Electricity Cybersecurity Impact Index, ECII for short, developed by ENTSO-E and the EU DSO Entity.

ECII is the Electricity Cybersecurity Impact Index, the NCCS yardstick. It assesses how severely the disruption of an entity would affect cross-border electricity flows, and thereby decides its classification as a high-impact or critical-impact entity.
Side-by-side view of the NCCS tiers high-impact from 1,500 MW and critical-impact from 3,000 MW with their respective duties
Two tiers, one index: the provisional German ECII thresholds and the duty packages behind them.

High-impact means a disruption would have a major effect on cross-border flows. Critical-impact means it would lead to critical interruption or destabilisation. For Germany the provisional thresholds sit at 1,500 MW and 3,000 MW. Provisional, because the formal designation by the authorities only follows in mid-2027; until then the associations work with provisional lists.

That provisionality is exactly the trap. Whoever sits just below the threshold today can still be designated in 2027, the methodology keeps being refined until then. And once designated, the clock runs: twelve months to the first complete risk report. Nobody builds a CSMS from zero in twelve months.

The roadmap to 2028

"Obligations by 2026" is a common reading, and it is only half true. 2026 is the year of methodologies and preparation. The hard entity duties follow in 2027 and 2028. That is no all-clear, it is the reason 2026 matters: afterwards the lead time is gone.

13 Jun 2024

Entry into force

The NCCS applies. Six months later, by 13 December 2024, all Member States had to designate their competent authorities.

2025 to mid-2026

Methodology phase

ACER delivers guidance on information exchange (25 April 2025), investment benchmarking (13 June 2025) and reliability indicators (27 January 2026). Mid-2026 brings the first Union-wide electricity cyber risk report.

2027

Controls and designation

Early 2027 brings the proposal for minimum and advanced controls, and in mid-2027 the authorities formally designate the high-impact and critical-impact entities.

2028

First entity reports

Twelve months after designation each entity delivers its first complete risk report, then on a three-year cycle.

The duties in detail

What lands on designated entities is a complete management system with a duty of proof. Considerably more than a virus scanner and an emergency binder.

Technician traces a yellow patch cable in an open network cabinet next to a grid control centre
The duties reach into the control systems: whoever runs critical processes must also secure the ICT supply chain behind them.

The foundation is a cybersecurity management system built on European and international standards, in practice the ISO 27001 family. On top sits a risk management cycle of context analysis, assessment, treatment and acceptance, to be run completely every three years. All of it is verified externally: the full scope at least every three years, partial audits yearly.

Two duties go beyond the usual ISMS. First, the reporting of significant cyberattacks under the Cyber-Attack Classification Scale, a dedicated severity scale; a complete NIS2 notification under Article 23 satisfies this duty too. Second, the supply chain: controls across the entire ICT lifecycle, personnel background checks, secure by design, zero-trust architectures and contractually secured audit rights towards suppliers. Under Article 27, entities must even actively report their critical ICT service providers to the authority.

And there will be drills. The NCCS demands cybersecurity exercises at several levels, from the individual company up to regional crisis simulation. The information exchange runs under the Traffic Light Protocol.

German perspective: three frameworks stacked

No German grid operator implements the NCCS on a green field. NIS2 transposition, the IT security catalogue under Section 5c EnWG and the KRITIS umbrella act run in parallel, with the Federal Network Agency as the common bracket. It is currently consolidating its security catalogues; the new framework becomes binding from October 2026.

The good news sits in Recital 15 of the NCCS: compliance with one framework may serve as evidence for the other. Whoever runs their ISO 27001 based ISMS from the national catalogue properly already brings the foundation for the NCCS CSMS. Nobody has to build twice. Proving twice, though, happens quickly when the reporting paths are not cleanly mapped.

That is precisely the German homework: three reporting logics. The 24-hour deadline for security incidents from national law, the NIS2 cascade of initial and follow-up reports, the CACS notification under the NCCS. Without a shared reporting matrix, in an emergency either nobody reports or everyone reports three times.

Challenges and risks

The NCCS is hard to fault on substance, a coordinated attack on the interconnected grid is one of Europe's most real disaster scenarios. The burden lies in implementation.

Where it pinches
OT security professionals are the bottleneck, not the budget. The market for control-system security expertise is swept empty.
Until the designation in mid-2027, uncertainty rules: whoever sits just below 1,500 MW does not know whether to invest.
The supply chain duties hit small suppliers who can manage neither zero trust nor background checks.
What speaks for it
Whoever took NIS2 and the national catalogues seriously already meets a large part of the NCCS baseline.
The mutual recognition of evidence (Recital 15) prevents genuine duplicate build-up.
The ACER and ENTSO-E methodology documents are public, the later duties can be anticipated today.

One structural point remains: the NCCS regulates impact on cross-border flows, not national security of supply. An attack that only hits a German distribution grid stays under NIS2 and the national catalogue. The three frameworks complement each other, but none makes the others redundant.

What grid operators should do now

Wait for the designation? You can. Then the CSMS build starts exactly when the twelve-month clock for the first risk report is already running. The alternative: use 2026 as the preparation year it is.

Employee sorts printed documents into two piles at a meeting table while a colleague sits beside her
Preparation means sorting: what does the existing ISMS already cover, what does the NCCS demand on top?

Five steps for 2026

  1. Self-assess against the ECII thresholds

    Does your controllable generation or load exceed 1,500 MW? Even just below, the look is worth it, the methodology keeps being refined until 2027 and the thresholds are provisional.

  2. Gap analysis against the existing ISMS

    Lay the ISO 27001 based ISMS from the national catalogue next to the NCCS requirements. Experience says the gaps are called: supply chain controls, CACS reporting capability, exercise programme.

  3. Bring the reporting paths into one matrix

    NIS2, national catalogue and NCCS side by side: who reports what, to whom, within which deadline? One page of paper that saves hours in an emergency.

  4. Sharpen supplier contracts

    Audit rights, security requirements and exit clauses for critical ICT service providers belong in every contract renewal now. Renegotiating under time pressure in 2027 gets expensive.

  5. Actively follow the 2026 methodology documents

    The Union-wide risk report in mid-2026 and the controls proposal in early 2027 define what will later be audited. Whoever reads along knows their duties before the designation.

The NCCS is part of a larger pattern: the EU is shifting energy regulation from national catalogues to directly applicable regulations, from the Data Act to the network codes. Whoever sets up their security and data architecture cleanly once serves all three frameworks from one system.

Further reading

Frequently asked questions

What is the NCCS? +

The Network Code on Cybersecurity, Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024. It is the first EU cyber rulebook specifically for the electricity sector, in force since 13 June 2024, and supplements the electricity market regulation 2019/943. Its goal is protecting cross-border electricity flows against cyberattacks.

Who falls under the NCCS? +

Far more than TSOs and DSOs. It covers every actor whose disruption could affect cross-border electricity flows: generators, electricity market platforms, NEMOs, balancing responsible parties, regional coordination centres, aggregators, critical ICT service providers and even operators of recharging points.

What do high-impact and critical-impact mean? +

The two tiers of the NCCS classification under the Electricity Cybersecurity Impact Index (ECII). High-impact means a disruption would have a major effect on cross-border electricity flows. Critical-impact means it would lead to critical interruption or destabilisation. The provisional thresholds for Germany are 1,500 MW and 3,000 MW.

Which deadlines apply when? +

Staggered until 2028: competent authorities since December 2024, ACER guidance documents in 2025 and January 2026, the Union-wide risk report in mid-2026, the proposal for minimum and advanced controls in early 2027, the formal designation of entities in mid-2027 and each entity's first risk report twelve months after its designation, so in 2028.

How does the NCCS relate to NIS2 and national security catalogues? +

The frameworks apply in parallel. The NCCS deepens NIS2 requirements sector-specifically but does not replace them. Recital 15 allows compliance evidence to be used across frameworks, and a complete NIS2 notification under Article 23 also satisfies the NCCS reporting duty. An ISO 27001 based ISMS from a national catalogue is the foundation for the NCCS CSMS.

What should a grid operator actually do in 2026? +

Four things: check your own position against the provisional ECII thresholds, run a gap analysis of the existing ISMS against the NCCS requirements, consolidate the reporting paths from NIS2, national catalogues and NCCS into one matrix, and add audit rights and security requirements to supplier contracts. Waiting for the 2027 designation wastes the lead time.