
ENISA
EU Agency for Cybersecurity; NIS360 2026 placed railway, water and waste water newly in the risk zone.
ENISA's NIS360 report placed railway, drinking water and waste water in the EU's cyber risk zone for the first time on 28 May 2026, and from 1 June company directors in transposing member states can be fined personally for serious cybersecurity failures in those sectors.
Last refreshed: 3 August 2026 · Appears in 3 active topics
Which EU sectors joined ENISA's cyber risk zone in May 2026?
Timeline for ENISA
Mentioned in: Water plants told to unplug controllers
Cybersecurity: Threats and DefencesMentioned in: TfL hackers jailed five and a half years
Cybersecurity: Threats and DefencesMentioned in: NCSC names FSB Centre 16 over routers
Cybersecurity: Threats and DefencesLost access to Anthropic models weeks after joining Project Glasswing in April 2026
European Tech Sovereignty: US order pulls Anthropic's top modelsIdentified water, rail and waste water as highest-risk sectors in NIS360 2026 maturity assessment
Cybersecurity: Threats and Defences: NIS2 fines now reach directors personallyBackground
The European Union Agency for Cybersecurity is the EU's central cybersecurity agency, responsible for developing cybersecurity certification schemes, threat-landscape assessments and supporting member-state CERTs. It publishes the annual ENISA Threat Landscape report, manages the EU cybersecurity certification framework under the Cybersecurity Act, and provides technical guidance to the European Commission on NIS2 and CRA implementation. It was established in 2004 and given a permanent, strengthened mandate under the Cybersecurity Act in 2019.
ENISA opened a public consultation on a draft EU Digital Identity Wallet certification scheme on 3 April 2026, a milestone in setting security-assurance requirements for wallet implementations under eIDAS2, and defining how the Wallet intersects with Cyber Resilience Act product-security requirements that apply from 11 December 2027. On 22 April 2026, it published the National Capabilities Assessment Framework v2, a structured member-state benchmarking tool for NIS2 maturity, alongside the European Commission's 19 reasoned opinions identifying transposition gaps.
NIS360 and NCAF 2.0 together give national regulators both a member-state maturity score and a sector-level risk map to anchor enforcement decisions; three sectors, trust services, aviation and financial market infrastructures, reached high maturity for the first time in the same report that flagged water and rail as newly at risk.
Water joins rail in the risk zone
ENISA published its third annual NIS360 report on 28 May 2026. Railway, drinking water and waste water crossed into the formal EU cyber risk zone for the first time, placed there because their criticality now exceeds their assessed security maturity; one in three water-sector entities had never carried out a basic risk assessment.
The enforcement teeth arrived within days: from 1 June 2026, company directors in EU countries that have transposed NIS2 can be fined personally at the full statutory rate for serious cybersecurity failures, and the European Commission referred non-transposing member states to the EU Court of Justice. ENISA's risk-zone finding gives national regulators a documented maturity gap in exactly the sectors where that personal liability now bites hardest.