
NIS360
NIS360 is ENISA's annual report assessing the cybersecurity maturity and risk exposure of sectors covered by the NIS2 Directive, flagging sectors where criticality outpaces assessed security capability.
The 2026 NIS360 assessment newly placed railway, drinking water and waste water into the formal risk zone on 28 May, its clearest signal yet that maturity in those sectors has fallen behind their criticality; a third of water operators had never completed a basic risk assessment.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Which EU critical sectors crossed into the ENISA risk zone for the first time in 2026?
Timeline for NIS360
Mentioned in: Water plants told to unplug controllers
Cybersecurity: Threats and DefencesMentioned in: NIS2 fines now reach directors personally
Cybersecurity: Threats and DefencesIdentified three new sectors crossing into the EU cyber risk zone and three reaching high maturity
Cybersecurity: Threats and Defences: ENISA puts water and rail in risk zoneBackground
NIS360 is ENISA's annual benchmark report assessing the cybersecurity maturity of sectors covered by the EU's NIS2 Directive. It scores each sector against a standard maturity model, then cross-references those scores against assessed criticality to identify where the gap between a sector's importance and its actual security has grown large enough to warrant regulatory focus; sectors that cross into the risk zone have a maturity score that no longer adequately reflects their criticality.
NIS360 is the direct sector-level companion to the NCAF 2.0 member-state maturity benchmark ENISA published in April 2026. Its significance is structural: it converts qualitative EU regulatory language into comparable sector scores that give national supervisory authorities, vendors and insurers a named basis for enforcement priorities. The water finding in the 2026 edition carries particular weight because an April 2026 CISA/NCSC advisory on Iranian-affiliated actors probing exposed water and energy programmable logic controllers had already named water as a live threat surface, giving the risk-zone designation immediate enforcement relevance.
Three sectors enter the risk zone
NIS360 scores each covered sector on maturity and separately on criticality, then flags any sector where maturity trails criticality as newly at risk. The 2026 edition, published 28 May, applied that test to railway, drinking water and waste water for the first time, and found a third of water operators had never completed even a basic risk assessment; the same run found 63 per cent of hacktivist attacks landing on public administrations, with roughly half of public bodies giving management no cybersecurity training .
Sector rank moves both ways in the same instrument: trust services, aviation and financial market infrastructures graduated to high maturity in the 2026 edition, evidence the risk-zone label tracks a moving assessment rather than a fixed reputation. Personal director liability for serious cybersecurity failures took effect in transposing EU states from 1 June, giving the newly flagged sectors an immediate practical stake in closing that maturity gap .