NIS2 for the Energy Sector: The Network Code on Cybersecurity Changes Your Scope

A German generation portfolio of 1,500 MW is an essential entity under NIS2. Under the provisional Electricity Cybersecurity Impact Index, it is also a candidate high-impact entity under a second EU regulation that most IT consultants have never opened.
That regulation is the Network Code on Cybersecurity — Commission Delegated Regulation (EU) 2024/1366, in force since 13 June 2024. It applies directly in every Member State. No transposition, no national implementing law, no waiting.
If you run NIS2 readiness work for energy clients and your scope stops at Article 21, your scope is wrong.
NIS2 in the energy sector is the floor, not the ceiling
NIS2 places electricity, gas, oil, hydrogen, and district heating in Annex I. Operators above 250 staff or €50m turnover land as essential entities; the 50-staff / €10m band lands as important entities. From there it is the standard programme: the ten measures in Article 21, incident reporting under Article 23, and management accountability under Article 20.
The NCCS sits on top of that, for electricity specifically. It exists because a cyber incident inside one control room does not stop at a border — frequency deviations propagate across a synchronous area in seconds. So the EU wrote sector rules for cross-border electricity flows and gave them direct effect.
Two consequences your clients will feel immediately:
- The NCCS defines its own scope, its own control set, and its own audit cycle. None of it is inherited from national NIS2 law.
- Under Recital 15, compliance with one framework can serve as evidence for the other. The work is reusable — but only if you map it deliberately.
Designation decides scope, not headcount
This is the part consultants get wrong. NIS2 scope is mechanical: sector plus size thresholds. NCCS scope is not.
Under Article 24, a national competent authority designates entities as high-impact or critical-impact using the Electricity Cybersecurity Impact Index. High-impact means a disruption would materially affect cross-border flows. Critical-impact means it would destabilise them.
ENTSO-E and the EU DSO Entity published provisional ECII thresholds so Member States can notify candidates ahead of the final Union-wide risk assessment. They vary sharply by country:
| Member State | High-impact | Critical-impact |
|---|---|---|
| Germany, France, Italy, Netherlands, Sweden | 1,500 MW | 3,000 MW |
| Spain, Poland, Romania, Slovenia | 1,000 MW | 3,000 MW |
| Austria, Czechia, Greece, Hungary, Slovakia | 500 MW | 3,000 MW |
| Estonia, Latvia, Lithuania | 500 MW | 900 MW |
| Ireland | 500 MW | 700 MW |
| Malta | 250 MW | 250 MW |
A 900 MW portfolio in Ireland is a critical-impact candidate. The same portfolio in Germany does not even reach high-impact. Cross-border groups need this checked per operating company, not per group.
Scope also runs well beyond generators. Article 2(1) lists TSOs, DSOs, nominated electricity market operators, power exchanges, balancing responsible parties, regional coordination centres, and operators of recharging points — and, importantly for readers of this blog, critical ICT service providers and managed security service providers. If you run a SOC or operate SCADA and EMS infrastructure for a designated entity, you can be pulled into designation yourself.
NIS2 Implementation Status by Country (2025–2026)
Fully in force
BelgiumCroatiaHungaryLithuaniaLatviaItaly6 countriesAdopted — late 2025
GermanyCzech RepublicFinland3 countriesIn progress — expected 2026
NetherlandsFranceSpainPolandAustriaSwedenIreland7 countries
The NCCS clock starts at designation, not on a fixed EU date
There is no single deadline to write into the client plan. The clock is personal to each entity.
- 12 months from designation — submit a risk report to the competent authority: selected mitigation controls and their implementation status, residual risk estimates for Union-wide critical-impact processes using the EU risk impact matrix, and a list of critical ICT providers supporting those processes (Art. 27).
- 24 months — demonstrate compliance with the applicable controls, through a national verification scheme or an independent third-party audit (Art. 25, Art. 31).
- Every three years — a full risk management cycle and a refreshed report. Critical-impact entities re-verify compliance across all critical assets (Art. 26, Art. 31).
- Annually — partial audits, with the full verification scope covered at least once every three years (Art. 25(2)).
One obligation has already bitten. Under Article 18(1), TSOs had to develop harmonised cybersecurity risk assessment frameworks at Union, regional, and Member State level by 13 March 2025 — binding regardless of whether their national authority had designated anyone yet.
Practical read: if your client is a plausible candidate, do not wait for the designation letter. Twelve months is not long to stand up a CSMS, complete an entity-level risk assessment, and produce an evidenced control list.
Where the NCCS goes deeper than Article 21
Article 21 tells you what to address. The NCCS tells designated entities how much, and then verifies it.
A CSMS, not a policy set. Article 28 requires a cybersecurity management system aligned to European and international standards — the sector equivalent of an ISMS — plus a documented mapping of controls to those standards (Art. 34). "We have policies" does not survive this.
Two control tiers. Minimum controls apply to high-impact entities; advanced controls apply to critical-impact entities, and only inside the designated perimeter. Perimeter definition becomes an audit artefact in its own right — the same discipline we describe for the IT/OT boundary in manufacturing.
A fixed risk cycle. Article 26 mandates a full cycle every three years — context, assessment, treatment, acceptance — using the EU risk impact matrix. Not "periodically". Every three years, documented and signed off.
Real supervisory powers. Competent authorities may run on-site inspections, off-site supervision, random checks, risk-based audits, and technical security scans, and may demand policies, audit reports, and implementation evidence (Art. 25).
Reporting that overlaps rather than duplicates. An incident notification filed under NIS2 Article 23 satisfies NCCS reporting, provided it carries the additional information the NCCS requires (Art. 38). Your client's existing 24-hour and 72-hour reporting workflow needs an extra field set, not a second process.
NIS2 vs ISO 27001 — Requirements Comparison
◈NIS2 OnlyMandatory incident reporting to authorities (24h / 72h)Board-level personal liability for cybersecuritySupply chain security obligations for essential entitiesSector-specific regulatory obligations⬡Shared RequirementsInformation security risk managementAccess control and identity managementBusiness continuity and disaster recoverySecurity awareness and training◇ISO 27001 OnlyInternal audit and management review cyclesStatement of Applicability (SoA) documentationFormal certification and third-party audit◈NIS2 OnlyMandatory incident reporting to authorities (24h / 72h)Board-level personal liability for cybersecuritySupply chain security obligations for essential entitiesSector-specific regulatory obligations⬡Shared RequirementsInformation security risk managementAccess control and identity managementBusiness continuity and disaster recoverySecurity awareness and training◇ISO 27001 OnlyInternal audit and management review cyclesStatement of Applicability (SoA) documentationFormal certification and third-party auditThe centre column shows requirements that both NIS2 and ISO 27001 share
Suppliers are not regulated — and are in scope anyway
The NCCS binds designated entities, not their vendors. But Article 33 forces those entities to push cybersecurity requirements across the full ICT lifecycle: background checks on supplier personnel where legally permitted, secure-by-design development, zero-trust architecture, access restrictions, contractual safeguards, audit rights, and traceability of security requirements down the chain. Entities must also weigh lock-in risk and supplier diversification.
Critical-impact entities go one step further: under Article 33(4), critical ICT components must be verified through an EU certification scheme or equivalent internal assurance.
Those controls become binding for any procurement launched six months after their adoption or update. So the practical trigger for a supplier is not a regulator — it is a tender document.
If you sell SCADA integration, remote monitoring, or managed detection to grid operators, you will be answering these questions whether or not you are designated. It is the dynamic covered in NIS2 supply chain security and supplier contracts under Article 21, one tier sharper.
NIS2 Penalty Escalation — Beyond the Fine
!Trigger event
Non-Compliance Detected or Incident Occurs
A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements
Authorities can impose▼Non-Monetary Penalties1Compliance orders with binding deadlines
2Mandatory security audits at your expense
3Public disclosure of violations
4Binding instructions on specific security measures
Escalates to▼Operational & Personal Consequences1Suspension of certifications or operating licences
2Temporary ban on management functions for individuals
3Public naming of responsible natural persons
TriggerNon-monetaryOperational / personal
What to do in the next 90 days
For every electricity-sector client on your books:
- Check candidacy. Compare installed capacity and role — TSO, DSO, NEMO, balancing responsible party, aggregator, recharging operator, ICT provider — against the provisional ECII threshold for the country of operation. Do it per legal entity, not per group.
- Identify the authority. Member States had to designate an NCCS competent authority by 13 December 2024, often the energy regulator (BNetzA in Germany), working alongside the national CSIRT. Confirm who supervises your client and whether candidate notifications have gone out.
- Map before you build. Take the existing NIS2 gap analysis and mark which artefacts already satisfy NCCS Articles 26–34. Recital 15 lets evidence travel in both directions, but nobody gets that benefit without a mapping matrix.
- Define the perimeter. High-impact and critical-impact perimeters decide which control tier applies where. Get it wrong and you either over-scope the programme or leave a critical asset outside the fence.
- Fix procurement now. Add the Article 33 clauses — audit rights, secure development, certification evidence, personnel screening — to the client's supplier template before the next tender, not after.
The energy clients who will struggle in 2027 are the ones who treated NIS2 as the end of the conversation. The NCCS was already in force while they were still arguing about Article 21 documentation.
If you want a fast, structured view of where an energy client actually stands against NIS2 before you layer the NCCS on top, run a NIS2 quick scan and start from an evidenced baseline.
Still have a question?
Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.
