ENISA (European Union Agency for Cybersecurity)

Government & open data

ENISA (European Union Agency for Cybersecurity)

ENISA is the EU agency for cybersecurity, established in 2004 and given a permanent mandate by the Cybersecurity Act, Regulation (EU) 2019/881. The agency supports EU cyber policy, prepares European certification schemes, builds capacity and knowledge, and facilitates cooperation between member states and Union bodies at strategic, operational and technical level. It also develops and maintains the European vulnerability database and publishes analyses of the state of cybersecurity in the Union, sectoral guidance and practical playbooks.

Go to the publisher’s website

Which products consult this source

  • BEVER — Direct consultation

    The source is consulted directly while the work is being done.

  • IRMA — Direct consultation

    The source is consulted directly while the work is being done.

Availability depends on your organisation’s configuration and access rights.

What this source does not give you

ENISA is not a supervisor and not a legal source: it does not supervise organisations and imposes no measures. Under NIS2, supervision rests with the competent authorities that each member state designates or establishes under Article 8. ENISA publications are aids, not norms: they create no obligations and do not demonstrate that an obligation has been met.

Frequently asked questions

Can ENISA guidance demonstrate that I comply with NIS2?
No. ENISA material helps in designing measures, but the norm sits in the NIS2 Directive and above all in the national law transposing it. Whoever assesses compliance is the national competent authority, not ENISA. So use ENISA documents to substantiate the choices you made, not as the normative framework itself.
So who does supervise NIS2?
Article 8 of NIS2 requires each member state to designate or establish one or more competent authorities responsible for cybersecurity and for the supervisory tasks in Chapter VII of the directive. Those authorities monitor implementation at national level. Each member state also designates a single point of contact for cross-border cooperation. Supervision and enforcement are therefore organised nationally, even though the norm is European.
What is ENISA's European vulnerability database?
Article 12(2) of NIS2 tasks ENISA with developing and maintaining a European vulnerability database, after consulting the cooperation group, including the necessary information systems, policies and procedures. The aim is that entities and their suppliers can consult publicly known vulnerabilities in ICT products and services, including entities that do not themselves fall under the directive. Paragraph 1 of the same article governs coordinated vulnerability disclosure through a CSIRT designated by the member state as coordinator.
Does ENISA adopt the European cybersecurity certification schemes?
ENISA prepares them; it does not adopt them. Under Article 49 of the Cybersecurity Act, ENISA drafts a candidate scheme following a request from the European Commission, or on request from the European Cybersecurity Certification Group. This is done through an open, transparent consultation and an ad hoc working group. The candidate scheme then goes to the Commission, which adopts it. Referring to 'the ENISA scheme' is therefore imprecise once the scheme in force is what matters.
What is the ENISA threat picture actually useful for?
For context and substantiation. The analyses of the state of cybersecurity in the Union, the sectoral threat pictures and the playbooks for specific audiences give a picture of what is happening and of what counts as good practice. That is useful in risk assessments, in justifying measures and in assessing suppliers. It says nothing about the situation in a specific organisation and produces no finding that binds a supervisor or a court.
All sourcesLooking for the full picture? The knowledge-source map shows every source at once: view all knowledge sources.