What happened
The ENISA NIS360 report released on 28 May 2026 indicates that cybersecurity maturity across EU critical sectors has improved, while sector criticality remains relatively stable. The report identifies a risk zone of sectors with lower maturity but higher criticality, including health, railway, maritime, ICT management services, space, public administrations, drinking water and waste water.
Why it matters for trust and compliance
- Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
- The report tracks implementation of the NIS2 Directive and helps policymakers prioritize resources to boost cyber resilience across the EU.
- It relates to NIS2. The regulations library explains what that law requires.
Who is affected
healthcare financial services technology government energy telecommunications ENISA
Recommended actions
- Map the security requirements to existing controls and close gaps.
- Schedule or refresh the risk or impact assessments this calls for.