#32024R1366R(04)Corrigendum to EU Electricity Cybersecurity Network Code
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
This corrigendum fixes incorrect internal references in the EU network code on cybersecurity for cross-border electricity flows. It does not create new cybersecurity duties or change the substance of the framework. The changes mainly matter to electricity transmission system operators, distribution system bodies, ENTSO for Electricity, Regional Coordination Centres, and regulators using the regulation. They should rely on the corrected article references when applying rules on voting, regional cybersecurity risk assessments, and publication of public reports.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Corrects Article 7(3) so the voting rule refers to plans listed in Article 6(3), while keeping the qualified majority reference to Article 6(2).
- Corrects Article 21(1) so regional cybersecurity risk assessments use methodologies developed under Article 18, not Article 19.
- Corrects Article 23(4) so the public report provision refers to Article 12(4), not Article 10(4).
Obligations
What this law requires
Where TSOs in a system operation region cannot agree on proposals for plans listed in Article 6(3), and the region is composed of more than five Member States, the TSOs must decide by qualified majority voting using the corrected internal reference.
ENTSO for Electricity, in cooperation with the EU DSO entity and after consulting the relevant Regional Coordination Centre, must perform a regional cybersecurity risk assessment for each system operation region using methodologies developed under Article 18 and approved under Article 8.
Regional cybersecurity risk assessments must identify, analyse, and evaluate risks of cyber-attacks affecting electricity system operational security and disrupting cross-border electricity flows, and must not consider legal, financial, or reputational damage from cyber-attacks.