KEY MESSAGES
Eurelectric supports the European Commission’s revision of the Cybersecurity Act
and its work on harmonising cybersecurity frameworks across the Union and
within the power sector. We welcome the opportunity to provide views on the
revised EU Cybersecurity Act and supports its efforts to strengthen cyber
resilience while improving harmonisation across the EU. In particular, we find that:
- The designation of high-risk suppliers should be based on the
combination of origin considerations based on the EU-level risk
assessment and the possibility to deploy objective, transparent and
verifiable mitigation measures. The process and timeline of such
designation should be clarified, alongside the launch of the union level
coordinated security risk assessment. - If a high-risk supplier is identified, the procuring entity should be given the
opportunity to demonstrate to the authorities that it can effectively
mitigate the risks through alternative appropriate technical measures. This
approach would help ensure robust and efficient cybersecurity practises. - The proposed introduction of a transition period under the ICT supply
chain framework is welcomed but must be calibrated based on the
sector’s procurement specificities and communicated well in
advance, given it could result in significant implementation challenges for
operators. The timeline should be extendable and coupled with financial
coverage due to the significant operational, financial, and system-level
impacts for operators managing long-lifecycle infrastructure. - Transition periods should be reflected and applied in the cyber-related
provisions of the IAA to ensure consistency and alignment between the
transversal legislation and sector-specific legislation. - Eurelectric supports the establishment of a single entry point as a
first step in achieving stronger harmonisation of reporting obligations
across EU legislation (NIS2, NCCS, DORA, CRA) to reduce regulatory
fragmentation, ensure interoperability, and streamline implementation. This
should be followed and complemented by deeper harmonisation of
reporting templates and timelines. - Eurelectric supports strengthening ENISA’s mandate in operational
coordination, incident response, and harmonised reporting, alongside the
continued development of the ECCF and its voluntary adoption as a
tool to harmonise cyber legislation.