Regulatory Watch  /  European Union  /  Guidance
Moderate impactGuidancePublished

ENISA releases NIS360 report showing improved cybersecurity maturity of EU critical sectors

The ENISA NIS360 report released on 28 May 2026 indicates that cybersecurity maturity across EU critical sectors has improved, while sector criticality remains relatively stable. The report identifies a risk zone of sectors with lower maturity but higher criticality, including health, railway, maritime, ICT management services, space, public administrations, drinking water and waste water.

Why it matters: The report tracks implementation of the NIS2 Directive and helps policymakers prioritize resources to boost cyber resilience across the EU.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
NIS360: The bigger picture on maturity and criticality of NIS critical sectors
ENISA news · primary source · May 28, 2026
Details
JurisdictionEuropean Union
RegulatorENISA
LegislatureEuropean Union
LawNIS2 Directive
StatusPublished
PublishedMay 28, 2026
Effectivenot stated
OrganisationsENISA
Topicscybersecurity, risk assessments, cybersecurity audit