Publications

Featured publications

ENISA NIS360

This edition of the ENISA NIS360 report is the third to assess the cybersecurity maturity and criticality of all sectors of high criticality as identified under Annex I of the NIS2 directive. The assessment covers the entire ecosystem of a sector…

NIS Investments 2025

The annual NIS Investments report presents the findings of a study conducted by ENISA to explore how cybersecurity policy translates in practice across organisations in the EU and its effects on their investments, resources, and operations.

NIS2 Technical Implementation Guidance

This report provides technical guidance to support the implementation of the NIS2 Directive for several types of entities in the NIS2 digital infrastructure, ICT service management and digital providers sectors. The cybersecurity requirements for…

All publications

Publish Date

Assessing a simplified Information Security approach

Feedback from RA/RM Pilot

Emerging and Future Risks Executable Workflow, UML Description

This document refines the contents of the Emerging Risk Workflow and provides details that allow for the implementation (both manual and automated) of the EFR process. It is based on UML specification.

Technology-induced challenges in Privacy & Data Protection in Europe

The ENISA Working Group on Privacy & Technology has been established to analyse the problems posed by these technology trends and the implications for the current EU legal framework. The main task of the Working Group is to propose actions to…

Technology-induced challenges in Privacy & Data Protection in Europe [French Version]

In this page you will find the French version of the report.

Technology-induced challenges in Privacy & Data Protection in Europe [German Version]

In this page you will find the German version of the report.

Technology-induced challenges in Privacy & Data Protection in Europe [Spanish Version]

In this page you will find the Spanish version of the report.

Emerging and Future Risks Workflow

This document provides an initial description of the activities, steps, information flow and roles involved in the scenario based assessment process of Emerging Risk.