Cybersecurity risk-management measures

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Cybersecurity risk-management measures

Member States must ensure that essential and important entities take suitable steps to protect the security of the systems they use for operations or service delivery. These steps should reduce risks and minimize the impact of incidents on their services and their users.

Member States should promote the integration of relevant advanced technologies aiming to implement state-or-the-art cybersecurity risk-management measures. The measures should be based on the latest technology and relevant European or international standards, considering the cost of implementation. They must provide a level of security that matches the risks faced by the entity. When deciding on the right measures, factors such as the entity’s risk exposure, size, and the potential severity of incidents, including their wider impact, should be taken into account.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

Cybersecurity risk-management measures (Regulation Annex II – 13 measures): Croatia's binding risk-management measures under the Cybersecurity Regulation (NN 135/24), transposing NIS2 Art. 21. Annex II defines 13 measures (technical, personnel, procedural and administrative), each with an objective, sub-sets, IT/OT applicability and a table mapping sub-sets. All essential/important entities must implement all 13, but at graduated levels - the competent authority assesses each entity's risk level (low/medium/high) during categorisation and assigns a required security level (basic/intermediate/advanced), which sets each sub-set as mandatory ("A"), conditionally mandatory ("B") or voluntary ("C"). 

Sources: https://ncsc.hr/hr/uredba-o-kibernetickoj-sigurnosti 
https://ncsc.hr/en/nis2-transposition 
https://ncsc.hr/UserDocsImages/ostalo/Regulation_on_Cybersecurity.pdf?vel=1041993 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 

Cybersecurity self-assessment framework (ZSIS): The official framework through which important entities assess their compliance with the risk-management measures. Issued by the Information Systems Security Bureau (ZSIS) under Art. 36 of the Act and Art. 57 of the Regulation, the "Guidelines for conducting cybersecurity self-assessment" come with Annex A; self-assessment calculator, Annex B; framework for evaluating risk-management measures, and Annex C; catalogue of controls. Croatia give a systematic, structured method to evaluate resilience, identify weak points and file the Statement of Compliance. 

Sources: https://www.zsis.hr/default.aspx?id=652 
https://www.zsis.hr/default.aspx?id=30 
https://www.uvns.hr/UserDocsImages/dokumenti/informacijska-sigurnost/Uredba-o-kibernetičkoj-sigurnosti-NN-2024-135.pdf 

Denmark flag
Denmark

Effective Cyber Defence (Cyberforsvar der virker): National guidance providing practical measures for organisations to establish cyber defence capabilities, strengthen resilience, identify risks, prioritise security efforts and improve protection against cyber threats.

Sources: https://samsik.dk/cyb-publikationer/cyberforsvar-der-virker/
https://samsik.dk/wp-content/uploads/2025/09/vejledning-cyberforsvar-der-virker-2023.pdf

Cyber Security in Supplier Relationships (Cybersikkerhed i leverandørforhold): Guidance helping organisations identify, assess and manage cybersecurity risks arising from outsourcing and supplier relationships

Sources: https://samsik.dk/cyb-publikationer/cybersikkerhed-i-leverandoerforhold/
https://samsik.dk/wp-content/uploads/2025/10/Vejledning-cybersikkerhed-i-leverandorforhold_cfsc_digst-2022.pdf

Hungary flag
Hungary

Cybersecurity risk-management / protective-measures catalogue: Hungary's binding risk-management measures, transposing NIS2 Art. 21. Under the Cybersecurity Act (Act LXIX of 2024) and Ministerial Decree 7/2024 (VI. 24.), every in-scope organisation must apply the protective measures assigned to its system's security class (Basic / Significant / High). The Protective Measures Catalogue (Decree Annex 2) is built on the NIST SP 800-53 Rev. 5 control catalogue, organised into control families covering administrative, logical and physical safeguards, with each control marked as required or not per security class. Where an organisation's own risk analysis justifies deviating from a control, it must document and justify this. Measures are "closed, comprehensive, continuous and risk-proportionate," as required by the Act.

Sources: https://nki.gov.hu/intezet/kozlemenyek/elektronikus-informacios-rendszerek-es-szervezetek-kiberbiztonsagi-kovetelmenykatalogusanak-alkalmazasi-utmutatoja/
https://net.jogtar.hu/jogszabaly?docid=a2400007.mkf
https://net.jogtar.hu/jogszabaly?docid=a2400418.kor
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00

National Cyber Security Centre of Hungary (NCSC HU) application guide and mandatory cybersecurity audit

The practical compliance-and-verification layer. The National Cyber Security Centre of Hungary (NCSC HU) issues an official Application Guide to the protective-measures catalogue, explaining the risk-management framework, the security-classification process and how to tailor and implement each control in the Hungarian legal context, control-family by control-family. Compliance is verified through a mandatory cybersecurity audit: in-scope entities must contract an accredited cybersecurity auditor and complete a first audit, then repeat at least every two years or as directed by SZTFH.

Sources: https://nki.gov.hu/it-biztonsag/kiadvanyok/segedletek/eir-utmutato/
https://sztfh.hu/tevekenysegek/kiberbiztonsagi-tanusitasok/
https://sztfh.hu/supervision-of-cybersecurity/?lang=en

Netherlands flag
Netherlands

Cbw duty of care (zorgplicht) and NCSC baseline guidance: The Cyber Security Act imposes a statutory duty of care: entities in scope must take appropriate technical and organisational measures to manage cyber risks, prevent incidents and limit their impact, including supply-chain risks. Management bodies must approve and be trained on these measures and can be held personally liable. The strengthened NCSC-NL provides the practical baseline (basismaatregelen / digital basic principles), scans and tools that organisations use to implement the duty of care. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 
https://www.ncsc.nl/cyberbeveiligingswet-nis2