NIS2 Energy Sector Checklist: Article 21 Controls Mapped to ENTSO-E Guidelines for Grid Operators, Gas TSOs, and Renewables
Who in the Energy Sector Must Comply with NIS2
NIS2 Directive (EU) 2022/2555 Annex I identifies the energy sector as high-criticality, placing most energy operators in the essential entity tier — the one carrying the highest supervision intensity and the largest penalty exposure. The full list of covered subsectors:
| Subsector | Entity types covered | Default classification |
|---|---|---|
| Electricity | Generators, TSOs, DSOs, supply undertakings, aggregators, demand response providers, energy storage operators | Essential (large) / Important (medium) |
| Gas | Supply undertakings, DSOs, TSOs, storage system operators, LNG system operators, natural gas undertakings | Essential (large) / Important (medium) |
| Oil | Pipeline operators, production/refining/processing facilities, storage and transmission operators | Essential (large) / Important (medium) |
| Hydrogen | Producers, distributors, and suppliers (added under NIS2; absent from NIS1) | Essential (large) / Important (medium) |
| District heating/cooling | Network operators | Essential (large) / Important (medium) |
Classification turns on size thresholds: essential entities are organisations with 250 or more employees or annual turnover above €50 million; important entities have 50 or more employees or turnover above €10 million. Member States may designate medium-sized energy operators as essential where systemic risk analysis supports it — TSOs operating critical cross-border infrastructure are particularly likely to receive that designation regardless of headcount.
The two classifications carry different consequences. Essential entities face proactive supervision — audits and inspections before any incident occurs. Important entities face reactive supervision, triggered by incidents or non-compliance evidence. Penalty exposure: essential entities up to €10 million or 2% of global annual turnover; important entities up to €7 million or 1.4%.
Under NIS2 Article 20, management bodies bear personal accountability for cybersecurity compliance. Approval of the Article 21 risk management measures and oversight of their implementation are not delegable obligations — they sit with the board.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
For detailed scope guidance, see the NIS2 scope and classification overview.
The Dual Compliance Framework: NIS2 Article 21 and the ENTSO-E NCCS
Electricity operators face a compliance reality that gas TSOs and renewables do not: two binding cybersecurity frameworks operating simultaneously.
NIS2 Article 21(1) establishes the proportionality principle — measures must be “appropriate and proportionate” given the state of the art, implementation cost, entity size, risk exposure, and the potential societal or economic impact of an incident. For most grid operators and TSOs, the proportionality analysis points toward higher-end implementation: electricity failures cascade across borders in ways that few other sectors can match.
Article 21(2) then specifies ten mandatory measure categories that apply regardless of proportionality. Every energy operator — essential or important, electricity or gas — must address all ten.
The NCCS layer for electricity operators: Commission Delegated Regulation (EU) 2024/1366, the Network Code on Cybersecurity (NCCS), was adopted in March 2024 under Article 59 of Regulation (EU) 2019/943. It applies to electricity entities with a “critical or high impact on cross-border electricity flows.” For those entities, the NCCS adds requirements beyond Article 21:
- A cybersecurity management system (CSMS) must be established — the electricity-sector equivalent of an ISMS, formalising governance, risk management, and control implementation.
- NCCS Article 18 requires a harmonised cybersecurity risk assessment framework, developed at EU, regional, and national level, with TSOs as primary responsible parties.
- Cyberattacks affecting cross-border electricity flows trigger a separate reporting obligation under NCCS Articles 38.3–38.4, running in parallel to NIS2 Article 23 notifications.
- During the designation transition period, critical- and high-impact entities may apply the NCCS voluntarily; mandatory compliance follows formal designation.
Gas TSOs and renewables: The NCCS applies only to electricity. Gas transmission system operators and renewable energy operators are governed by NIS2 Article 21 alone. However, Commission Implementing Regulation (EU) 2024/2690 (CIR 2024/2690) — which sets detailed technical and methodological requirements for digital infrastructure operators — is treated by ENISA’s Technical Implementation Guidance (June 2025) as the reference specification for all NIS2 sectors. Supervisors across all energy subsectors will expect equivalent evidence depth.
OT Asset Inventory Template for Energy
Article 21(2)(i) requires “human resources security, access control policies and asset management.” For energy operators, this is consistently the hardest measure to evidence in an audit — and the most commonly cited gap. The reason is straightforward: most energy operators have robust IT asset inventories and virtually no documented OT inventory.
An electricity distribution operator running a substation SCADA system with 60 remote terminal units, 120 intelligent electronic devices, and a network of protection relays who inventories only laptops and servers has documented less than 5% of the network and information systems that directly affect service delivery. That gap fails Article 21(2)(i) and undermines every other measure that depends on knowing what assets exist.
Minimum asset categories for energy OT environments:
| Layer | Asset types | Common protocols | Zone |
|---|---|---|---|
| Field layer | Remote terminal units (RTUs), intelligent electronic devices (IEDs), protection relays, revenue meters, phasor measurement units (PMUs) | IEC 60870-5-101/104, IEC 61850, DNP3 | Field zone |
| Control layer | SCADA servers, EMS/SCADA workstations, distributed control system (DCS) servers, distributed energy resource management systems (DERMS) | IEC 60870-5-104, ICCP/TASE.2, OPC-UA | OT zone |
| Communications | Remote access gateways, serial-to-Ethernet converters, OT-layer 2/3 switches, OT firewalls and DMZ appliances | Various (carrier-level) | DMZ |
| Enterprise integration | Historian servers, PI/OPC-UA data interfaces, ERP-to-OT connectors | OPC-UA, REST APIs | IT/DMZ boundary |
Minimum data fields required per OT asset for Article 21(2)(i) compliance:
| Field | NIS2 measure served | Note |
|---|---|---|
| Unique asset ID | Art.21(2)(i) — asset management | Consistent across CMDB and OT documentation |
| Asset type | Art.21(2)(i) | From table above |
| Vendor and model | Art.21(2)(d) — supply chain risk | Required for vendor security assessments |
| Firmware/software version | Art.21(2)(e) — vulnerability handling | Baseline for patch management |
| Primary protocol(s) | Art.21(2)(b) — incident detection scope | Determines monitoring coverage |
| Zone placement | Art.21(2)(e) — system security | IT / DMZ / OT / Field |
| Criticality rating | Art.21(2)(a) — risk analysis | High/Medium/Low tied to business impact assessment |
| Patch status and last patched | Art.21(2)(e) | Or documented compensating control if un-patchable |
| Remote access method(s) | Art.21(2)(j) — access control | VPN, direct serial, vendor portal, etc. |
| Responsible owner | Art.21(2)(i) | Named individual or team accountable for the asset |
Handling legacy OT assets that cannot be patched: Article 21(2)(e) requires policies for vulnerability handling and disclosure. It does not require immediate patching of every OT asset. Where firmware updates are not technically possible without voiding equipment certification or disrupting continuous operations, the correct approach is to document the compensating control in the risk register — network isolation, enhanced anomaly monitoring, physical access controls, or scheduled manual inspection. The inability to patch is a risk to manage and document, not an automatic compliance failure.
For a deeper look at asset management obligations, see the NIS2 asset management requirements guide.
IT/OT Zone Architecture Checklist
CIR 2024/2690 Title I covers “policy on the security of network and information systems,” with documented network architecture and controlled data flows as central requirements. While the CIR is directly binding only on digital infrastructure operators, ENISA’s June 2025 Technical Implementation Guidance positions it as the reference specification for all NIS2 sectors. Energy supervisors applying the proportionality test will expect equivalent evidence of structured network segmentation.
The standard four-zone model for energy OT maps cleanly to Article 21 measure obligations:
Zone 1 — Enterprise/IT zone
- Segmented from OT by a monitored, stateful firewall with documented, business-justified rule sets (Art.21(2)(e): system security)
- MFA required for any privileged user whose access path could reach the DMZ or OT zone (Art.21(2)(j))
- No direct connectivity to OT zone — all communication mediated by the DMZ
Zone 2 — IT/OT Demilitarised Zone (DMZ)
- Only sanctioned, documented data flows cross the DMZ — read-only historian replication is permitted; reverse write paths from IT to OT are not
- Jump servers with privileged access management (PAM) for OT access; no direct connections from IT to OT zone
- Firewall rules reviewed at least annually, with written business justification retained for each permitted flow
- Remote vendor access (SCADA/ICS integrators) permitted only via PAM jump server, logged and time-limited
Zone 3 — OT zone
- SCADA servers, EMS workstations, and DCS reside here
- No direct internet access — all external connectivity routes through the DMZ
- Patch management policy in place; compensating control documentation for every un-patchable asset (Art.21(2)(e))
- Industrial anomaly detection or IDS/IPS deployed to support incident detection obligations (Art.21(2)(b))
- OT-specific incident response procedure maintained separately from the IT playbook — containment actions in OT often cannot follow IT shutdown logic
Zone 4 — Field zone
- RTUs, IEDs, protection relays, PMUs
- Where technically feasible: command validation for IEC 60870-5-104 (APDU integrity checks) and IEC 61850 GOOSE message authentication
- Physical security for all field cabinets, communication equipment, and remote access terminals — aligned with the environmental and physical security provisions in CIR 2024/2690
- Remote access via VPN with certificate-based authentication; all sessions logged and reviewed
NCCS Article 18 alignment for electricity operators: The NCCS risk assessment framework must cover all zones of the OT/IT architecture. The zone-by-zone structure above directly defines the scope of that assessment. Entities in the process of developing their CSMS should use the four-zone model as the organisational skeleton for the risk assessment.
NIS2 Article 21 Checklist for Energy Operators
The table below maps each Article 21(2) measure to the specific evidence an energy operator needs to demonstrate compliance. The NCCS column applies only to electricity entities with critical or high cross-border impact; gas TSOs and renewables should treat those cells as best-practice guidance.
| Measure | Article 21(2) text (summary) | Energy-specific evidence required | NCCS parallel obligation |
|---|---|---|---|
| (a) | Risk analysis and information security policies | OT + IT risk assessment covering all four zones; annual review cycle; management board sign-off on findings and risk acceptance decisions | NCCS Art.18: harmonised risk assessment framework for cross-border impact entities |
| (b) | Incident handling | Energy-specific incident classification criteria; OT-specific containment playbooks that separate “contain without shutdown” from IT-style isolation; 24h/72h/1-month notification procedures | NCCS Arts.38.3–38.4: additional reporting if cross-border flows could be affected |
| (c) | Business continuity, backup management, disaster recovery, crisis management | Grid restoration plans (black-start or cold-start procedures documented); backup energy management systems tested at least annually; documented RPO/RTO for SCADA restoration; crisis communication plan for multi-authority coordination | Not directly addressed in NCCS; Art.21(2)(c) applies in full |
| (d) | Supply chain security | SCADA/ICS vendor security assessments; contractual security clauses in integrator agreements; software bill of materials (SBOM) for critical OT systems; periodic review of vendor access rights | NCCS: cybersecurity requirements for ICT supply chain in cross-border electricity operations |
| (e) | Security in system acquisition, development, and maintenance; vulnerability handling and disclosure | Patch management policy covering IT and OT; compensating controls register for un-patchable OT assets (see Section 3); security acceptance testing for new OT systems and firmware updates before deployment | — |
| (f) | Policies and procedures to assess effectiveness of cybersecurity risk-management measures | Annual internal review or third-party audit; OT-specific penetration test of the DMZ at least every two years; metrics tracking (MTTD, MTTR); findings reported to management board | NCCS Art.37.8: cyber-attack classification scale methodology for tracking and reporting severity |
| (g) | Basic cyber hygiene practices and cybersecurity training | ICS-specific cybersecurity training for all OT-adjacent staff (content must differ from standard IT awareness — covers industrial protocol risks, physical console access, and vendor access procedures); documented training records; phishing simulation for IT-connected staff | — |
| (h) | Cryptography and encryption policies/procedures | Cryptographic policy covering IT and OT; IEC 61850 GOOSE message authentication implemented where technically feasible; TLS 1.2 or higher for all remote access sessions; key management procedures | — |
| (i) | Human resources security, access control policies, and asset management | OT asset inventory (see Section 3); role-based access control for SCADA with least-privilege enforcement; formal leavers process for OT access rights; background checks for staff with privileged OT access | — |
| (j) | MFA, continuous authentication, secured communications, emergency communications | MFA for all remote access to OT systems; certificate-based authentication for OT-to-field communications where technically feasible; emergency communications channel that does not depend on the primary IT infrastructure; privileged session recording for SCADA access | — |
Priority guidance for essential entities: All ten measures require audit-ready evidence. A “we plan to implement” statement against any Article 21(2) measure is not adequate — the directive requires implementation, not intent. For important entities, proportionality allows reduced scope where the risk assessment documents lower operational impact, but the documentation of that proportionality decision is itself an audit obligation.
Incident Notification Obligations for Energy Operators
NIS2 Article 23 establishes a three-stage notification process for significant incidents. Energy operators should treat the 24-hour early warning window as non-negotiable — it is the step most often missed, not through negligence but because the internal triage process has not been tested before a real incident occurs.
- Within 24 hours of awareness: early warning to the national competent authority (NCA) — incident identified, suspected malicious act, and any cross-border impact flag
- Within 72 hours: incident notification with initial assessment — nature, severity, indicators of compromise, preliminary impact estimate
- Within 1 month: final report — full description, root cause analysis, mitigation measures taken, cross-border impact if any
Energy-specific addition for electricity operators: If a cyberattack could affect cross-border electricity flows, NCCS Articles 38.3–38.4 require a separate notification through the relevant CSIRT and, for large-scale incidents, the CyCLONe network for EU-level coordination. This obligation runs in parallel to — not instead of — the Article 23 notification. Both must be completed.
What constitutes a “significant incident” in energy: NIS2 Article 23(3) defines a significant incident as one that has caused or is capable of causing severe operational disruption to the service, or has affected or is capable of affecting other natural or legal persons by causing considerable damage. For energy operators, a cyberattack that disrupts SCADA access, causes loss of telemetry from substations, triggers an unplanned transition to manual operating mode, or affects electricity or gas delivery to end users should be treated as significant pending full investigation. Under-reporting at the 24-hour stage and correcting at 72 hours is operationally preferable to missing the early warning window entirely.
For the full incident notification procedure, see the NIS2 Article 23 incident notification guide and the energy sector incident response page.
Conclusion
NIS2 compliance for energy operators is not a generic IT security checklist exercise. It requires documentation that covers the OT network — substations, SCADA servers, EMS workstations, RTUs, protection relays, and the communications infrastructure connecting them — alongside the corporate IT estate. For electricity TSOs and DSOs operating cross-border infrastructure, the ENTSO-E Network Code on Cybersecurity adds a second binding layer that must be managed in parallel with Article 21, not as a separate project.
The most efficient path to audit readiness runs through three sequential steps: build the OT asset inventory first, then establish the zone architecture and document the control gaps against the checklist in Section 5, then complete the policy documentation that makes each measure auditable. Generic policy templates written without the asset inventory as a foundation produce documentation that will not withstand a site visit by a supervisor who understands operational technology environments.
For supply chain obligations under Article 21(2)(d), see the NIS2 supply chain security requirements guide. For the full Article 21 requirements overview, see the NIS2 requirements guide.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
[1] NIS2 Directive Article 21: Cybersecurity risk-management measures — nis-2-directive.com
[2] Network Code on Cybersecurity (NCCS) — ENTSO-E
[3] New network code on cybersecurity for EU electricity sector — European Commission
[4] CIR 2024/2690: NIS2 Technical Measures — nisd2.eu
[5] Energy Sector Cybersecurity — ENISA
[6] NIS2 Technical Implementation Guidance (v1.0, June 2025) — ENISA
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
