ENISA signed a Contribution Agreement with the European Commission for the Agency to support the health sector in building robust cybersecurity defenses against cyber threats. Today, ENISA publishes the updated procurement guidelines for the cybersecurity of hospitals and healthcare providers as one of the first deliverables under the Health Action Plan.
Launched in 2025 by the European Commission, the EU Action Plan for the cybersecurity of hospitals and healthcare providers was a pivotal step towards enhancing the protection and resilience of the sector. Through the Action Plan, ENISA has been tasked with a series of actions, underscoring the EU’s confidence in its ability to deliver meaningful value to the sector.
A key output from ENISA is the support of the proposed European Cybersecurity Support Centre, a mechanism to provide tailored guidance, tools, and services to healthcare providers across Europe. Specifically, ENISA is responsible to develop a comprehensive service catalogue for the mechanism to assist the sector, drawing from previous experiences such as the ENISA Cybersecurity Support Action.
For the establishment of the Support Mechanism, a Contribution Agreement of EUR 6 million was signed between ENISA and the European Commission. This Contribution Agreement is set for three years and will support the following:
- Repackaging and expanding current service offer and architecture to strengthen the action and advance outcomes
- Create and enhance harmonised approaches
- Reusing established methodology, tools and procurement strategy
- Actions done to empower Member States and health entities
- Build service offer in consultation with relevant stakeholder groups
The primary objective of the agreement is the implementation of the service catalogue, which currently, the service catalogue of the Support Mechanism includes actions clustered under the following categories: preparedness, detection, response and governance.
Procurement guidelines
As part of its tasks under the Action Plan, ENISA publishes a new iteration of the procurement guidelines for the cybersecurity of hospitals and healthcare providers. This publication was prepared by ENISA, with the support of the NIS Cooperation Group, the EU Health ISAC (EH-ISAC) and the European Commission.
The document includes a series of procurement practices to support the integration of cybersecurity objectives in procurement processes for hospitals and healthcare providers. It covers all phases of the procurement life cycle, sets out cybersecurity requirements for suppliers and highlights the types of services and products where cybersecurity considerations are particularly important. Additionally, a practical checklist of cybersecurity measures tailored for healthcare procurement is included, each of them linked with specific threats for the different procurement types.
The guidelines are in line with the relevant EU regulatory frameworks and can be used by a wide range of stakeholders, from senior technical professionals in healthcare to IT teams.
The Health Action Plan, including the revised procurement guidelines and cybersecurity for medical devices will be among the topics on the agenda of the 11th ENISA eHealth Security Conference organised in Nicosia, Cyprus on 7 October 2026.
- Procurement guidelines for the cybersecurity of hospitals and healthcare providers | ENISA
- 11th eHealth Security Conference | ENISA
- eHealth security in the spotlight: A good practice guide for a robust and resilient EU health sector | ENISA
- Cyber Hygiene in the Health Sector | ENISA
- Proposed ENISA role to safeguard cybersecurity of health sector | ENISA