ENISA NIS360 2026: Maturity Improves, but Critical-Sector Gaps Remain
EU critical-sector maturity is improving, but health, rail, maritime, public administration, water and other services remain in ENISA’s risk zone where criticality exceeds preparedness.
ENISA NIS360 2026
REGULATION & POLICY · SECBRIEFS ANALYSISExecutive Takeaway
ENISA’s third NIS360 assessment finds improving cybersecurity maturity across EU critical sectors, while criticality remains relatively stable. Progress is uneven: several sectors moved into higher maturity bands, but the risk zone still includes essential services where preparedness trails systemic importance.
For leaders, NIS2 implementation should be judged through operational capability rather than compliance activity alone. Authorities and operators need to direct scarce resources toward sectors and organizations where disruption would matter most and maturity remains weakest.
Key Findings
- 01
ENISA reports steady improvement in cybersecurity maturity across EU critical sectors since the previous edition.
- 02
The 2026 risk zone includes health, railway, maritime, ICT management services, space, public administrations, drinking water and waste water.
- 03
Banking, electricity, aviation, space and digital-by-default services remain among the most critical sectors.
- 04
Trust services, aviation and financial market infrastructures moved into the high-maturity band.
- 05
Gas, road, maritime and health strengthened their maturity within the moderate band.
- 06
ENISA attributes uneven progress partly to skills shortages, sector characteristics and organizational size.
What the Data Says
What It Doesn’t Say / Limitations
NIS360 combines evidence from organizations, national authorities and EU-level sources using a structured methodology. Maturity and criticality scores aggregate complex sector conditions and cannot represent every entity within a sector.
Comparisons are influenced by available evidence, regulatory development and national reporting maturity. The framework is best used to prioritize deeper assessment, not to conclude that every organization in a higher-ranked sector is adequately protected.
Why It Matters
NIS2 creates a common regulatory direction, but the report shows that implementation capacity remains uneven. A sector can improve while still presenting systemic risk because dependency and disruption impact remain high.
Financial services should pay attention beyond their own relatively mature position. Banks depend on telecommunications, cloud, water, public administration and other services whose weaker resilience can become a shared operational risk.
Who Should Care
- EU national authorities and policymakers
- Critical-infrastructure operators
- CISOs and risk leaders
- NIS2 compliance teams
- Financial-services resilience leaders
- Boards overseeing essential services
SecBriefs Assessment
NIS360 is valuable because it combines preparedness with societal criticality instead of ranking sectors on controls alone. That makes it a practical resource-allocation tool for authorities and large operators.
The risk-zone concept should guide scenario selection and dependency mapping, not become a simplistic league table. Organizations need entity-level evidence and cross-sector exercises to translate the sector view into decisions.
What To Do Now
- Map critical dependencies on sectors identified in ENISA’s risk zone.
- Use NIS2 implementation evidence to test operational capability, not only policy completion.
- Prioritize joint exercises involving public administration, communications, cloud and essential-service providers.
- Address skills and implementation gaps with shared services, sector guidance and measurable support.
- Set resilience targets for critical suppliers according to disruption impact and recovery time.
- Reassess sector and entity maturity annually as regulation, threats and dependencies change.
ENISA NIS360 2026
- Publisher
- ENISA
- Published
- URL
- https://www.enisa.europa.eu/enisa-nis360-2026