National Level Risk Assessment

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

National Level Risk Assessment

One of the key elements of a cyber security strategy is that Member States need to establish a mechanism to identify relevant assets and perform a national risk assessment, with a specific focus on critical information infrastructures. Risk assessment is a scientific and technologically based process consisting of three steps: risk identification, risk analysis and risk evaluation. The scope of the assessment is to coordinate the use of resources and to monitor, control, and minimize the probability and/or impact of unfortunate events that might put at risk the critical services and ultimately the objectives of the vision. Risk assessments can provide valuable information for developing, executing and evaluating a strategy. The assessment can be conducted on different levels. Risk assessment on a national level allows gaining a holistic understanding about risk to the nation as a whole. By carrying out a national risk assessment and aligning the objectives of the strategy with national security needs, it is possible to focus on the most important challenges with regard to cyber security. 

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Belgium flag
Belgium

 CyTRIS: CyTRIS collects, analyses and distributes information on threats, vulnerabilities and attacks affecting Belgium's vital sectors, and produces the national cyber-threat picture.

Sources: https://ccb.belgium.be/cytris

Croatia flag
Croatia

National Cybersecurity Risk Assessment: Formal national-level risk assessment carried out by NCSC-HR within the entity categorisation process, for every entity classified as essential or important. It sets the level of risk-management measures each entity must apply. The methodology is based on entity size and sector and selects typical attack types (business disruption/sabotage, data theft/espionage, cybercrime such as ransomware and fraud, content vandalism, political influence and disinformation) and typical threat-actor profiles (state-sponsored APT groups, terrorists, cybercrime groups, hacktivists, competitor attackers), then assesses likelihood and severity per sector. 

Sources: https://ncsc.hr/en/nis2-transposition 
https://narodne-novine.nn.hr/clanci/sluzbeni/2024_11_135_2217.html 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 
https://ncsc.hr/UserDocsImages/kategorizacija/SmjerniceNacionalnaProcjenaRizika_28022025.pdf 

Denmark flag
Denmark

National Risk Profile 2025 (Nationalt Risikobillede 2025): Denmark publishes a national risk profile identifying the major risks and threats facing the country and providing a basis for preparedness planning across public authorities and operators of societal functions.

Sources: https://samsik.dk/wp-content/uploads/2025/04/NATIONALT-RISIKOBILLEDE-2025.pdf

Annual Cyber Threat Assessment (Cybertruslen mod Danmark): Denmark publishes an annual national cyber threat assessment describing the cyber threat landscape, threat levels and attack patterns affecting public authorities, businesses and citizens.

Sources: https://samsik.dk/publikation/cybertruslen-mod-danmark/
https://samsik.dk/wp-content/uploads/2025/11/Cybertruslen-mod-Danmark-2025.pdf

Cyber threat assessments portal: Denmark publishes dedicated cyber threat assessments for different sectors. These assessments support sector-specific risk assessment and preparedness activities.

Sources: https://samsik.dk/cybersikkerhed/trusselsvurderinger/

National Risk-Preparedness Plan for the Electricity Sector: Establishes national risk preparedness and crisis-response arrangements for the electricity sector, including risk assessments, crisis scenarios, preventive measures, coordination procedures and emergency response mechanisms designed to ensure continuity of electricity supply.

Sources: https://energy.ec.europa.eu/system/files/2022-06/DK_%20RPP%20electricity.pdf
https://ens.dk/

Estonia flag
Estonia

Publish the national cyber-threat and risk picture: RIA consolidates incident statistics, major attack patterns, vulnerabilities and strategic risks into the annual Cyber Security in Estonia assessment. Public and private organisations can use it to update risk registers, exercise scenarios and investment priorities. 

Sources: https://www.ria.ee/en/cyber-security/cyberspace-analysis-and-prevention/situation-cyberspace

Maintain continuous operational situation awareness: CERT-EE and RIA monitor incidents, malicious infrastructure and major campaigns and publish regular situation updates. Security teams should subscribe to these updates and map relevant indicators and attack methods to their own environment.

Sources: https://www.ria.ee/en/cyber-security/cyberspace-analysis-and-prevention/situation-cyberspace

National Risk Assessment (Riiklik riskianalüüs): The National Risk Assessment is coordinated by the Government Office and reviewed annually. It includes a dedicated cyber-threat section assessing the likelihood and impact of a significant cyberattack on national defence, internal security and vital services. Public and private organisations can use the assessment to update risk registers, exercise scenarios, continuity plans and investment priorities. 

Sources: https://www.riigikantselei.ee/en/national-risk-analysis/national-risk-analysis
https://riigikantselei.ee/en/riskid/cyber-threats

Finland flag
Finland

NCSC-FI situational awareness and national threat assessment: The NCSC-FI is responsible for compiling and distributing the national cyber situation picture. Cybersecurity scenarios 2035, the purpose of this scenario work is to provide a tool for understanding these possible alternative development paths and their consequences for various organisations and actors. National Emergency Supply Agency to publish scenario on use of military force to support preparedness of businesses

Sources: https://traficom.fi/en/publications/cybersecurity-scenarios-2035
https://www.huoltovarmuuskeskus.fi/en/a/national-emergency-supply-agency-to-publish-scenario-on-use-of-military-force-to-support-preparedness-of-businesses 

Germany flag
Germany

Annual report on the state of IT security in Germany (BSI-Lagebericht): The BSI’s annual report provides a national assessment of Germany’s cybersecurity situation. The 2025 edition reviews developments across threats, attack surfaces, hazards, impacts and resilience, using statistics and selected incidents from the reporting period to inform government, businesses and the public.

Sources: https://www.bsi.bund.de/EN/Service-Navi/Publikationen/Lagebericht/lagebericht_node.html 
https://medien.bsi.bund.de/lagebericht/en/ 
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Lageberichte/Lagebericht2025_Achtseiter.pdf?__blob=publicationFile&v=7 

National IT Situation Centre (Nationales IT-Lagezentrum): The National IT Situation Centre continuously monitors Germany’s cybersecurity situation, assesses incident information and provides situation reports and early warnings. It integrates incident management, warnings and the responsibilities für critical infrastructure operators with internal officers on duty and the military cyber command and the Federal Information Technology Centre with external officers in duty. It cooperates with the National Cyber Response Centre and other situation centre at federal level and in the federal states.

Sources: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Reaktion/Nationales-IT-Lagezentrum/nationales-it-lagezentrum_node.html 

Hungary flag
Hungary

National security-classification methodology & threat catalogue: Hungary's national-level cyber risk-assessment framework, set by MK Decree 7/2024 (VI. 24.) under the Cybersecurity Act (Act LXIX of 2024 on the Cybersecurity of Hungary). Every organisation in scope must run a risk analysis of each electronic information system and classify it into one of three national security classes - Basic, Significant or High - identifying and documenting threats to confidentiality, integrity and availability using the national threat catalogue (Annex 3). The assigned class then determines the mandatory protective measures (Annex 2 The National Cyber Security Centre of Hungary (NCSC HU), the national CSIRT within the Special Service for National Security (SSNS),issues the official Application Guide covering the risk-management framework and classification process; the Supervisory Authority of Regulated Activities (SZTFH) supervises compliance for private-sector entities.

Sources: https://nki.gov.hu/intezet/kozlemenyek/elektronikus-informacios-rendszerek-es-szervezetek-kiberbiztonsagi-kovetelmenykatalogusanak-alkalmazasi-utmutatoja/
https://en.nki.gov.hu/
https://sztfh.hu/tevekenysegek/kiberbiztonsagi-tanusitasok/
https://sztfh.hu/supervision-of-cybersecurity/?lang=en
https://net.jogtar.hu/jogszabaly?docid=a2400007.mkf

Liechtenstein flag
Liechtenstein

Cyber risk analysis  for Liechtenstein: Between February 2023 and February 2024, the National Cyber Security Unit prepared a cyber risk analysis  for Liechtenstein. The results of this analysis were incorporated in the “Hazard and Risk Analysis for Civil  Protection 2024” in the form of twelve specific cyber threats.

Sources: https://www.llv.li/serviceportal2/amtsstellen/amt-fuer-bevoelkerungsschutz/2024-08-22_bericht_update_gefaehrdungsanalyse_fl-kombiniert_t7neu.pdf

Measures for Implementing the National Cyber Security Strategy 2025: The 2026 Implementation and Measures Plan contains 41 implementation measures. The plan establishes information gathering and assessment of the national cyber situation as the starting point for identifying cyber threats, vulnerabilities and concrete cyber risks. The National Cyber Security Unit coordinates the implementation and ongoing development of these measures.

Sources: https://www.llv.li/de/landesverwaltung/stabsstelle-cybersicherheit/nationale-cyber-strategie/massnahmen
https://www.llv.li/serviceportal2/amtsstellen/stabstelle-cyber-sicherheit/nis-strategie/20260610_massnahmen-zur-umsetzung-der-nationalen-cybersicherheitsstrategie-2025.pdf
https://www.llv.li/serviceportal2/amtsstellen/stabstelle-cyber-sicherheit/nis-strategie/20260730_massnahmen-zur-umsetzung-der-nationalen-cybersicherheitsstrategie-2025-en-.pdf

Malta flag
Malta

National cyber risk analysis and situational awareness: CSIRT Malta monitors cyber incidents at national level and provides dynamic risk and incident analysis, alerts, warnings, and situational awareness to relevant stakeholders. The service supports national understanding of cyber risks and threat developments. 

Sources: https://maltacip.gov.mt/dipartimenti/disclamer/ 
https://maltacip.gov.mt/en/the-department/csirtmalta/ 

Cyber Assess Scheme – Risk Assessment Service: The scheme provides organisations with structured cybersecurity risk assessments using recognised risk assessment methodologies. 

Sources: https://ncc-mita.gov.mt/cyber-assess/ 

Malta's National Risk Assessment 2023: Malta's National Risk Assessment assesses national threats and vulnerabilities related to money laundering, terrorist financing, proliferation financing and targeted financial sanctions. The assessment identifies fraud, including cybercrime, as one of the higher-risk threat categories and provides a risk-based framework for authorities and regulated entities to review controls, policies and mitigation measures. 

Sources: https://fiaumalta.org/app/uploads/2024/03/PublicNRA_Dec2023.pdf 

Netherlands flag
Netherlands

Cybersecurity Assessment Netherlands (Cybersecuritybeeld Nederland (CSBN)): The CSBN is the annual national cyber threat and risk assessment, produced by the National Coordinator for Security and Counterterrorism (NCTV). It analyses threats, interests and resilience in relation to national security. The CSBN 2025 reports that cyber threats are becoming more varied and harder to predict, and highlight a growing cooperation between state-backed and criminal groups. In 2024, at least 121 separate ransomware incidents were recorded in the Netherlands through Project Melissa. The assessment was published alongside an update on the implementation of the national cybersecurity strategy. 

Source: https://www.ncsc.nl/dienstverlening/cybersecuritybeeld-nederland-csbn 
 

Assessment of vital entities (vitaalbeoordeling) under the Wwke: A government-wide process, coordinated by the NCTV with sector ministries, that determines which entities are 'vital' (critical) and therefore in scope of the strengthened obligations. It is anchored in the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke), which transposes the EU CER Directive. 

Source: https://www.nctv.nl/onderwerpen/n/nederlandse-cybersecuritystrategie-2022-2028 

Poland flag
Poland

National cybersecurity landscape report for 2025: The Government Plenipotentiary for Cybersecurity and the Ministry of Digital Affairs publish the national annual report using data from the national-level CSIRTs and other KSC institutions. It presents incident volumes, threat trends and the state response, with a classified annex for non-public information.

Sources:https://www.gov.pl/web/cyfryzacja/krajobraz-cyberprzestrzeni-sprawozdanie-o-stanie-cyberbezpieczenstwa-polski-za-rok-2025

Financial-sector cyber-threat landscape 2026: The Polish Financial Supervision Authority publishes a dedicated assessment of cyber threats affecting the financial sector, covering threat monitoring, organisational processes, information exchange and resilience testing.

Sources: https://www.knf.gov.pl/dla_rynku/CSIRT_KNF/Krajobraz_cyberzagrozen_w_polskim_sektorze_finansowym

Portugal flag
Portugal

Cybersecurity Observatory (Observatório de Cibersegurança): The Cybersecurity Observatory gathers and analyses cybersecurity data to support understanding of the national cyber threat landscape. It publishes indicators, studies and recurring assessments covering risks, incidents, capacity, law, economy, emerging technologies and trends in cybersecurity. The Observatory provides a practical mechanism for monitoring national cyber risks and supporting evidence based policymaking. 

Sources: https://www.cncs.gov.pt/pt/observatorio/ 
https://www.cncs.gov.pt/en/observatory/ 

Cybersecurity in Portugal – Risks & Conflicts Report (Cibersegurança em Portugal – Riscos & Conflitos): The National Cybersecurity Centre (CNCS)  publishes annual national reports analysing cyber incidents, threat actors, cybercrime trends, vulnerabilities and emerging risks affecting Portugal. These reports provide a recurring national level cyber risk assessment and contribute to understanding the evolution of the threat landscape. Findings are made publicly available to organisations, researchers and policymakers. 

Sources: https://digital.gov.pt/pt/noticias/cncs-publica-6-a-edicao-do-relatorio-de-ciberseguranca-riscos-conflitos 
https://www.cncs.gov.pt/docs/rel-riscosconflitos2025-obcibercncs.pdf 

National Cybersecurity Authority Functions: The National Cybersecurity Centre (CNCS) is designated as the national cybersecurity authority and is responsible for producing knowledge on the state of national cybersecurity, supporting threat monitoring and contributing to the national cyber alert level. These responsibilities support national cyber risk assessment and situational awareness activities. 

Sources: https://www.cncs.gov.pt/en/ 
https://www.cncs.gov.pt/ 

National Risk Assessment and the National Strategy for the Resilience of Critical Entities: Council of Ministers Resolution No. 135/2026 approves the first National Risk Assessment and the National Strategy for the Resilience of Critical Entities, under Decree-Law No. 22/2025 (transposing Directive (EU) 2022/2557). The instruments aim to strengthen the prevention of and response to risks affecting critical entities. 

Sources: https://diariodarepublica.pt/dr/detalhe/resolucao-conselho-ministros/135-2026-1139191708  

Slovakia flag
Slovakia

Annual Report on Cybersecurity in the Slovak Republic (Správa o kybernetickej bezpečnosti v Slovenskej republike): The annual report provides a national overview of the cybersecurity situation, key trends, security incidents, threat developments, and the preparedness of individual sectors to meet the growing demands of the digital environment. The 2025 report also evaluates implementation of the 2021–2025 National Cybersecurity Strategy Action Plan and identifies issues expected to affect cybersecurity in 2026.

Sources: https://www.nbu.gov.sk/narodny-bezpecnostny-urad-zverejnil-spravu-o-kybernetickej-bezpecnosti-v-slovenskej-republike-za-rok-2025/
https://www.nbu.gov.sk/data/files/625_sprava-o-kybernetickej-bezpecnosti-2025.pdf

Cybersecurity Risk Analysis Methodology (Metodika analýzy rizík kybernetickej bezpečnosti): The methodology provides instructions for cybersecurity risk assessment by essential service operators under the National Cybersecurity Act. It covers risk context, identification of assets, threats and vulnerabilities, assessment of likelihood and consequences, risk scenarios, risk treatment, residual-risk acceptance and risk reporting. It is designed for use across sectors, while allowing an organisation with a more mature approach to retain its own method if the results can be mapped to the national methodology.

Sources: https://www.nbu.gov.sk/riadenie-rizik/
https://www.nbu.gov.sk/data/att/3446.pdf

Slovenia flag
Slovenia

National Cybersecurity Threat Assessment of the Republic of Slovenia (Ocena ogroženosti kibernetske varnosti v Republiki Sloveniji): This is Slovenia’s national strategic process for assessing exposure to cybersecurity threats and vulnerabilities. The process analyses information on detected incidents, threat trends and cybersecurity risks, and supports the preparation of recommendations for the public and private sectors. Its purpose is to determine the national level of exposure and identify state level measures to strengthen the resilience of key information and communication systems, networks and services. The published assessment rates the current national cybersecurity threat level as medium. 

Sources: https://www.gov.si/teme/oceno-ogrozenosti-kibernetske-varnosti-v-republiki-sloveniji/  

Annual Cybersecurity Report (SI-CERT: Cybersecurity in 2025 in figures): The annual report provides operational evidence on incidents and threat developments observed in Slovenia and therefore constitutes a practical supporting input for national threat and risk analysis. The report covering 2025 presents incident data, affected sectors, major threat trends, vulnerabilities and observations. 

Sources: https://www.cert.si/kibernetska-varnost-2025-v-stevilkah/ 

Spain flag
Spain

National Cybersecurity Council risk and threat assessment: The National Cybersecurity Council assesses cyber risks and threats, analyses possible crisis scenarios, keeps response plans updated and proposes exercises in coordination with the competent authorities. 

Sources: https://www.dsn.gob.es/es/estructuras-de-seguridad-nacional/comites-especializados/consejo-nacional-de-ciberseguridad 

Annual National Security Report 2025: Spain’s annual national-security reporting consolidates contributions from ministries and the intelligence community, covers cybersecurity among the national-security domains and includes short-, medium- and long-term risk and threat analysis. 

Sources: https://www.dsn.gob.es/es/actualidad/sala-de-prensa/IASN2025