Critical Sectors

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Critical Sectors

The protection of critical sectors is an integral part of many cyber and information security strategies. Cybersecurity covers a broad spectrum of ICT-related security issues, of which the protection of critical sectors is an essential part. National strategies should include objectives and priorities related to the protection of critical sectors in particular those referred to Annexes I and II of the NIS2 Directive. In addition, as part of their national strategy, Member States shall also adopt specific policies, related to sustaining the general availability, integrity and confidentiality of the critical sectors including, the public core of the internet and where relevant, the cybersecurity of undersea communications cables.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

Protection of essential and important entities under the Cybersecurity Act & Regulation (ZKS/NIS2): The cybersecurity protection regime for critical sectors. The Cybersecurity Act (NN 14/24) and Regulation (NN 135/24) classify operators across the Annex I/II sectors (energy, transport, banking, financial market infrastructure, health, drinking & waste water, digital infrastructure, ICT management, public administration, space, plus postal, waste, chemicals, food, manufacturing, digital providers, research) as "essential" or "important" entities. Following a criticality-based categorisation run by the competent authorities (notifications issued from 2025), these entities must implement the binding risk-management measures (Regulation Annex II) and report significant incidents. Essential entities face proactive ex-ante supervision; important entities ex-post supervision. NCSC-HR coordinates centrally, with sectoral competent authorities (HNB, HANFA, HAKOM, HACZ, ministries) overseeing their domains. 

Sources: https://ncsc.hr/hr/uredba-o-kibernetickoj-sigurnosti 
https://ncsc.hr/en/nis2-transposition 

Related objective Protect Critical Sectors
Denmark flag
Denmark

CER Act (Critical Entities Resilience): Implements the CER Directive and establishes resilience requirements for critical entities operating in essential sectors. Critical entities must assess risks, implement resilience measures and strengthen their ability to withstand and recover from disruptions affecting essential services. The Danish Resilience Agency (SAMSIK) acts as the coordinating authority in the implementation of CER. The agency translates the Ministry's strategic framework into practical implementation across sectors, and must, among other things, advise and support the cooperation between the sector-responsible authorities.

Sources: https://samsik.dk/cer/

Legislation to strengthen preparedness in the energy sector: The energy sector is regulated by sector-specific emergency preparedness legislation designed to increase resilience and emergency preparedness against natural, man-made and technological threats to Denmark’s energy supply.

Sources: https://ens.dk/en/supply-and-consumption/new-legislation-strengthen-preparedness-energy-sector
https://www.retsinformation.dk/eli/lta/2025/258
https://www.retsinformation.dk/eli/lta/2025/261

Act on Security and Preparedness in the Telecommunications Sector: Establishes security, preparedness and risk-management requirements for telecommunications providers, including cybersecurity measures, incident reporting obligations and continuity requirements to protect critical communications infrastructure.

Sources: https://www.retsinformation.dk/eli/lta/2025/435/pdf

Related objective Protect Critical Sectors
Hungary flag
Hungary

Protection of essential and important entities under the Cybersecurity Act (NIS2): The Cybersecurity Act (Act LXIX of 2024) and Government Decree 418/2024 classify operators across the covered sectors (energy, transport, health, water, digital infrastructure, ICT management, public administration, space, plus postal, waste, chemicals, food, manufacturing, digital providers, research) as essential or important entities, with mandatory registration, security classification, protective measures, audit, and incident reporting. Banking/financial market infrastructure under DORA.

Sources: https://sztfh.hu/supervision-of-cybersecurity/?lang=en
https://en.nki.gov.hu/
https://nki.gov.hu/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00

Sector-specific OT/ICS security guidance - electricity (SeConSys handbook): Hungary's dedicated cybersecurity guidance for operational-technology/industrial control systems in the electric power sector, the "Cybersecurity Handbook for Electric Power Industrial Control Systems," published and recommended by by the National Cyber Security Centre of Hungary (NCSC HU) within the SeConSys (Security for Control Systems) collaboration of Hungarian energy, control-engineering and cybersecurity experts, the National University of Public Service and state bodies. First issued December 2020 and updated annually (current edition 2023), it covers IT/OT/ICS distinctions, a threat map, the Zero Trust model, an incident list, and mandatory/recommended measures per cybersecurity level for the sector treated as the "most critical" critical infrastructure.

Sources: https://seconsys.eu/
https://nki.gov.hu/it-biztonsag/kiadvanyok/segedletek/seconsys-harmadik-alkalommal-kerult-aktualizalasra-a-kiberbiztonsagi-kezikonyv/
https://seconsys.eu/wp-content/uploads/2023/02/SeConSys_kezikonyv_aktual_2023_jan.pdf

Related objective Protect Critical Sectors
Malta flag
Malta

Malta transposed the NIS2 Directive into national legislation with Legal Notice 71 of 2025, known as the Measures for a High Common Level of Cybersecurity Across the European Union (Malta) Order (Subsidiary Legislation 460.41). https://legislation.mt/eli/sl/460.41/eng

Attachments:
Related objective Protect Critical Sectors

Malta has transposed the CER Directive into its national legislation through a new legal instrument titled the Resilience of Critical Entities and Infrastructures (Identification, Designation and Protection) Order, 2026. The Order was first published on 16 January 2026 as L.N. 5 of 2026. The text of the Order has been formally brought into force as Subsidiary Legislation 460.43. The Order’s provisions are fully in force from 23 January 2026, following the publication of Legal Notice 23 of 2026 (Commencement Notice). This means Malta’s CER framework, which identifies, designates and protects critical entities and infrastructures, is now officially effective and enforceable.  https://legislation.mt/eli/ln/2026/5/eng

Attachments:
Related objective Protect Critical Sectors

Malta published Legal Notice 166 of 2024 titled “Malta Financial Services Authority Act (Digital Operational Resilience Act (DORA)) Regulations, 2024” under the Malta Financial Services Authority Act (Cap. 330). This legal notice locally implements the key provisions of the DORA Regulation and designates the MFSA as the competent supervisory authority for DORA-related compliance. These Malta DORA Regulations came into force on 17 January 2025, matching the Regulation’s EU-wide applicability date. They largely mirror the EU Regulation without adding or reducing material obligations — but provide the national legal basis for enforcement and supervisory powers. https://legislation.mt/eli/ln/2024/166/eng

Related objective Protect Critical Sectors

The implementation of Regulation (EU) 2024/1366 n cybersecurity aspects of cross-border electricity flows will take place through the implementation of the NIS2 Directive. Malta CIP, as the supervisory authority for the NIS2 Directive will act as the competent authority for Regulation (EU) 2024/1366.

Attachments:
Related objective Protect Critical Sectors

Obligations arising from EU Regulation (EU) 2019/1583 – Cybersecurity Measures in Aviation Security are reflected in Malta’s National Civil Aviation Security Programme through the Aviation Security Directorate within the Ministry For Home Affairs that issues guidance and instructions to industry accordingly. https://www.transport.gov.mt/aviation/regulation-policy/european-legislation-702

Related objective Protect Critical Sectors

In Malta, the Civil Aviation Directorate (TM-CAD) is responsible for applying and enforcing Part-IS requirements (EASA Part-IS – Information Security for Aviation Safety) for entities certificated/approved in Malta. https://www.transport.gov.mt/aviation/regulation-policy/european-legislation-702

Related objective Protect Critical Sectors
Netherlands flag
Netherlands

Cyber protection of essential and important entities under the Cbw: The Cyber Security Act protects essential and important entities through mandatory risk management, incident reporting and supervision. NCSC-NL provides national CSIRT support, while competent authorities monitor compliance in their sectors. The model ties incident response to compliance, so protection of critical services is both supported and enforceable. 

Source: https://www.ncsc.nl/cyberbeveiligingswet-nis2 

Resilience of critical entities under the Wwke: The Wwke requires designated critical entities to assess threats and maintain the continuity of essential services. Its physical and organisational resilience duties address disruptions that may interact with or amplify cyber incidents. It broadens protection from network security to continuity of the services society relies on. 

Source: https://www.nctv.nl/onderwerpen/n/nederlandse-cybersecuritystrategie-2022-2028 

Related objective Protect Critical Sectors