Skip to content
You can now search across every topic, entity and event.What's new
NIS360
ConceptEU

NIS360

NIS360 is ENISA's annual report assessing the cybersecurity maturity and risk exposure of sectors covered by the NIS2 Directive, flagging sectors where criticality outpaces assessed security capability.

The 2026 NIS360 assessment newly placed railway, drinking water and waste water into the formal risk zone on 28 May, its clearest signal yet that maturity in those sectors has fallen behind their criticality; a third of water operators had never completed a basic risk assessment.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Which EU critical sectors crossed into the ENISA risk zone for the first time in 2026?

Timeline for NIS360

#12 29 Jul
#7 1 Jun
#6 28 May

Identified three new sectors crossing into the EU cyber risk zone and three reaching high maturity

Cybersecurity: Threats and Defences: ENISA puts water and rail in risk zone
View full timeline →

Background

NIS360 is ENISA's annual benchmark report assessing the cybersecurity maturity of sectors covered by the EU's NIS2 Directive. It scores each sector against a standard maturity model, then cross-references those scores against assessed criticality to identify where the gap between a sector's importance and its actual security has grown large enough to warrant regulatory focus; sectors that cross into the risk zone have a maturity score that no longer adequately reflects their criticality.

NIS360 is the direct sector-level companion to the NCAF 2.0 member-state maturity benchmark ENISA published in April 2026. Its significance is structural: it converts qualitative EU regulatory language into comparable sector scores that give national supervisory authorities, vendors and insurers a named basis for enforcement priorities. The water finding in the 2026 edition carries particular weight because an April 2026 CISA/NCSC advisory on Iranian-affiliated actors probing exposed water and energy programmable logic controllers had already named water as a live threat surface, giving the risk-zone designation immediate enforcement relevance.

Key Issues
EU risk scoring

Three sectors enter the risk zone

NIS360 scores each covered sector on maturity and separately on criticality, then flags any sector where maturity trails criticality as newly at risk. The 2026 edition, published 28 May, applied that test to railway, drinking water and waste water for the first time, and found a third of water operators had never completed even a basic risk assessment; the same run found 63 per cent of hacktivist attacks landing on public administrations, with roughly half of public bodies giving management no cybersecurity training .

Sector rank moves both ways in the same instrument: trust services, aviation and financial market infrastructures graduated to high maturity in the 2026 edition, evidence the risk-zone label tracks a moving assessment rather than a fixed reputation. Personal director liability for serious cybersecurity failures took effect in transposing EU states from 1 June, giving the newly flagged sectors an immediate practical stake in closing that maturity gap .

Common Questions
What is ENISA NIS360 and what does it measure?
NIS360 is ENISA's annual report that scores the cybersecurity maturity of every sector covered by the EU's NIS2 Directive, then maps those scores against each sector's criticality. When a sector's maturity fails to keep pace with how critical it is, NIS360 places it in the risk zone, signalling to EU regulators where enforcement should focus.Source: ENISA / SecurityAffairs
Which sectors are in the ENISA NIS360 risk zone in 2026?
The 2026 NIS360 report, published 28 May, placed railway, drinking water and waste water in the risk zone for the first time. One in three water-sector entities had never run a risk assessment, and these sectors were judged to have criticality that now outpaces their security maturity.Source: SecurityAffairs / ENISA NIS360 2026
What enforcement powers does ENISA's NIS360 risk-zone designation give EU regulators?
NIS360 does not itself impose penalties, but it gives national supervisory authorities under NIS2 a documented, evidence-based gap to enforce against. The NIS2 Directive allows fines and corrective orders for non-compliant critical entities; a NIS360 risk-zone designation strengthens the regulator's position when directing audits or enforcement at sectors with a named maturity gap.Source: ENISA / NIS2 Directive
How does NIS360 2026 differ from NIS360 2025?
The 2026 edition is the third annual NIS360 report. It marks the first time railway, drinking water and waste water entered the risk zone, reflecting deteriorating relative maturity in those sectors rather than new findings about 2025. It also reports that three sectors reached high maturity for the first time: trust services, aviation, and financial market infrastructures.Source: ENISA NIS360 2026
Source Material