Skip to content
You can now search across every topic, entity and event.What's new
ENISA
OrganisationEU

ENISA

EU Agency for Cybersecurity; NIS360 2026 placed railway, water and waste water newly in the risk zone.

ENISA's NIS360 report placed railway, drinking water and waste water in the EU's cyber risk zone for the first time on 28 May 2026, and from 1 June company directors in transposing member states can be fined personally for serious cybersecurity failures in those sectors.

Last refreshed: 3 August 2026 · Appears in 3 active topics

Key Question

Which EU sectors joined ENISA's cyber risk zone in May 2026?

Timeline for ENISA

#12 29 Jul
#11 16 Jul
#10 9 Jul

Mentioned in: NCSC names FSB Centre 16 over routers

Cybersecurity: Threats and Defences
#10 12 Jun

Lost access to Anthropic models weeks after joining Project Glasswing in April 2026

European Tech Sovereignty: US order pulls Anthropic's top models
#7 1 Jun

Identified water, rail and waste water as highest-risk sectors in NIS360 2026 maturity assessment

Cybersecurity: Threats and Defences: NIS2 fines now reach directors personally
View full timeline →

Background

The European Union Agency for Cybersecurity is the EU's central cybersecurity agency, responsible for developing cybersecurity certification schemes, threat-landscape assessments and supporting member-state CERTs. It publishes the annual ENISA Threat Landscape report, manages the EU cybersecurity certification framework under the Cybersecurity Act, and provides technical guidance to the European Commission on NIS2 and CRA implementation. It was established in 2004 and given a permanent, strengthened mandate under the Cybersecurity Act in 2019.

ENISA opened a public consultation on a draft EU Digital Identity Wallet certification scheme on 3 April 2026, a milestone in setting security-assurance requirements for wallet implementations under eIDAS2, and defining how the Wallet intersects with Cyber Resilience Act product-security requirements that apply from 11 December 2027. On 22 April 2026, it published the National Capabilities Assessment Framework v2, a structured member-state benchmarking tool for NIS2 maturity, alongside the European Commission's 19 reasoned opinions identifying transposition gaps.

NIS360 and NCAF 2.0 together give national regulators both a member-state maturity score and a sector-level risk map to anchor enforcement decisions; three sectors, trust services, aviation and financial market infrastructures, reached high maturity for the first time in the same report that flagged water and rail as newly at risk.

Key Issues
New risk sectors

Water joins rail in the risk zone

ENISA published its third annual NIS360 report on 28 May 2026. Railway, drinking water and waste water crossed into the formal EU cyber risk zone for the first time, placed there because their criticality now exceeds their assessed security maturity; one in three water-sector entities had never carried out a basic risk assessment.

The enforcement teeth arrived within days: from 1 June 2026, company directors in EU countries that have transposed NIS2 can be fined personally at the full statutory rate for serious cybersecurity failures, and the European Commission referred non-transposing member states to the EU Court of Justice. ENISA's risk-zone finding gives national regulators a documented maturity gap in exactly the sectors where that personal liability now bites hardest.

Common Questions
Which EU countries are behind on NIS2 implementation?
The European Commission issued 19 reasoned opinions in April 2026 identifying member states with NIS2 transposition gaps. ENISA's NCAF 2.0 provides the benchmarking framework against which those gaps are now formally assessed.Source: European Commission / ENISA April 2026
What is ENISA's National Capabilities Assessment Framework and why does it matter?
NCAF 2.0, published by ENISA on 22 April 2026, is a structured framework for EU member states to benchmark their national cybersecurity maturity against NIS2 obligations. It was released alongside the European Commission's 19 reasoned opinions on member states that have not fully transposed NIS2 into national law.Source: ENISA / European Commission, April 2026
What is ENISA and what does it regulate?
ENISA is the EU Agency for Cybersecurity, responsible for cybersecurity certification schemes, threat landscape reports and technical guidance to the European Commission on NIS2 and CRA implementation. It opened a consultation on EU Digital Identity Wallet certification in April 2026 and published the NCAF 2.0 NIS2 maturity framework on 22 April 2026.Source: ENISA
Which EU sectors are most at risk from cyber attacks according to ENISA?
ENISA's NIS360 2026 identifies railway, drinking water and waste water as newly in the risk zone because their criticality outstrips their security maturity. Public administrations draw 63 per cent of hacktivist attacks while being among the least well-trained tiers of government.Source: ENISA NIS360 2026
What did ENISA's NIS360 2026 report find?
ENISA's NIS360 2026 report, published 28 May 2026, placed railway, drinking water and waste water in the risk zone for the first time, because their criticality now exceeds their assessed security maturity. One in three water-sector entities has never run a risk assessment. Trust services, aviation and financial market infrastructures reached high maturity for the first time.Source: ENISA NIS360 2026