Your cybersecurity authority
The national cybersecurity authority: the BSI, ANSSI, ACN, or their peer in your member state, with the national CSIRT taking your incident notifications.
Cybersecurity risk management under Directive (EU) 2022/2555 (NIS2). Annex I lists energy, including electricity, gas, district heating and cooling, and hydrogen, alongside drinking water and waste water as sectors of high criticality, so most operators are essential entities. Article 21 sets the risk-management measures, supply chain security included, and Article 23 sets the reporting regime. The CER Directive runs in parallel for physical resilience: designated critical entities in the same sectors owe risk assessments and resilience plans.
What they can ask for
- The Article 21 risk-management measures and their approval by the management body under Article 20
- Supply chain security assessments covering SCADA vendors, cloud forecasting services, and AI suppliers
- Incident notifications on the Article 23 timeline
- Risk assessments and the resilience plan, where you are a designated critical entity under the CER Directive
The clock
- 24h
- early warning after becoming aware of a significant incident
- 72h
- incident notification with an initial assessment
- 1 month
- final report