REGULATORY WATCH BRIEF Moderate 50 🧭 Regulatory Guidance published

ENISA releases NIS360 report showing improved cybersecurity maturity of EU critical sectors

The report tracks implementation of the NIS2 Directive and helps policymakers prioritize resources to boost cyber resilience across the EU.

ImpactModerate 50
Type🧭 Regulatory Guidance
Statuspublished enacted, check the effective date
JurisdictionEU

What happened

The ENISA NIS360 report released on 28 May 2026 indicates that cybersecurity maturity across EU critical sectors has improved, while sector criticality remains relatively stable. The report identifies a risk zone of sectors with lower maturity but higher criticality, including health, railway, maritime, ICT management services, space, public administrations, drinking water and waste water.

Why it matters for trust and compliance

  • Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
  • The report tracks implementation of the NIS2 Directive and helps policymakers prioritize resources to boost cyber resilience across the EU.
  • It relates to NIS2. The regulations library explains what that law requires.

Who is affected

healthcare financial services technology government energy telecommunications ENISA

Recommended actions

  1. Map the security requirements to existing controls and close gaps.
  2. Schedule or refresh the risk or impact assessments this calls for.