National-level Risk Assessment

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

National-level Risk Assessment

One of the key elements of a cyber security strategy is that Member States need to establish a mechanism to identify relevant assets and perform a national risk assessment, with a specific focus on critical information infrastructures. Risk assessment is a scientific and technologically based process consisting of three steps: risk identification, risk analysis and risk evaluation. The scope of the assessment is to coordinate the use of resources and to monitor, control, and minimize the probability and/or impact of unfortunate events that might put at risk the critical services and ultimately the objectives of the vision. Risk assessments can provide valuable information for developing, executing and evaluating a strategy. The assessment can be conducted on different levels. Risk assessment on a national level allows gaining a holistic understanding about risk to the nation as a whole. By carrying out a national risk assessment and aligning the objectives of the strategy with national security needs, it is possible to focus on the most important challenges with regard to cyber security. 

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

National Cybersecurity Risk Assessment: Formal national-level risk assessment carried out by NCSC-HR within the entity categorisation process, for every entity classified as essential or important. It sets the level of risk-management measures each entity must apply. The methodology is based on entity size and sector and selects typical attack types (business disruption/sabotage, data theft/espionage, cybercrime such as ransomware and fraud, content vandalism, political influence and disinformation) and typical threat-actor profiles (state-sponsored APT groups, terrorists, cybercrime groups, hacktivists, competitor attackers), then assesses likelihood and severity per sector. 

Sources: https://ncsc.hr/en/nis2-transposition 
https://narodne-novine.nn.hr/clanci/sluzbeni/2024_11_135_2217.html 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 
https://ncsc.hr/UserDocsImages/kategorizacija/SmjerniceNacionalnaProcjenaRizika_28022025.pdf 

Denmark flag
Denmark

National Risk Profile 2025 (Nationalt Risikobillede 2025): Denmark publishes a national risk profile identifying the major risks and threats facing the country and providing a basis for preparedness planning across public authorities and operators of societal functions.

Sources: https://samsik.dk/wp-content/uploads/2025/04/NATIONALT-RISIKOBILLEDE-2025.pdf

Annual Cyber Threat Assessment (Cybertruslen mod Danmark): Denmark publishes an annual national cyber threat assessment describing the cyber threat landscape, threat levels and attack patterns affecting public authorities, businesses and citizens.

Sources: https://samsik.dk/publikation/cybertruslen-mod-danmark/
https://samsik.dk/wp-content/uploads/2025/11/Cybertruslen-mod-Danmark-2025.pdf

Cyber threat assessments portal: Denmark publishes dedicated cyber threat assessments for different sectors. These assessments support sector-specific risk assessment and preparedness activities.

Sources: https://samsik.dk/cybersikkerhed/trusselsvurderinger/

National Risk-Preparedness Plan for the Electricity Sector: Establishes national risk preparedness and crisis-response arrangements for the electricity sector, including risk assessments, crisis scenarios, preventive measures, coordination procedures and emergency response mechanisms designed to ensure continuity of electricity supply.

Sources: https://energy.ec.europa.eu/system/files/2022-06/DK_%20RPP%20electricity.pdf
https://ens.dk/

Hungary flag
Hungary

National security-classification methodology & threat catalogue: Hungary's national-level cyber risk-assessment framework, set by MK Decree 7/2024 (VI. 24.) under the Cybersecurity Act (Act LXIX of 2024 on the Cybersecurity of Hungary). Every organisation in scope must run a risk analysis of each electronic information system and classify it into one of three national security classes - Basic, Significant or High - identifying and documenting threats to confidentiality, integrity and availability using the national threat catalogue (Annex 3). The assigned class then determines the mandatory protective measures (Annex 2 The National Cyber Security Centre of Hungary (NCSC HU), the national CSIRT within the Special Service for National Security (SSNS),issues the official Application Guide covering the risk-management framework and classification process; the Supervisory Authority of Regulated Activities (SZTFH) supervises compliance for private-sector entities.

Sources: https://nki.gov.hu/intezet/kozlemenyek/elektronikus-informacios-rendszerek-es-szervezetek-kiberbiztonsagi-kovetelmenykatalogusanak-alkalmazasi-utmutatoja/
https://en.nki.gov.hu/
https://sztfh.hu/tevekenysegek/kiberbiztonsagi-tanusitasok/
https://sztfh.hu/supervision-of-cybersecurity/?lang=en
https://net.jogtar.hu/jogszabaly?docid=a2400007.mkf

Netherlands flag
Netherlands

Cybersecurity Assessment Netherlands (Cybersecuritybeeld Nederland (CSBN)): The CSBN is the annual national cyber threat and risk assessment, produced by the National Coordinator for Security and Counterterrorism (NCTV). It analyses threats, interests and resilience in relation to national security. The CSBN 2025 reports that cyber threats are becoming more varied and harder to predict, and highlight a growing cooperation between state-backed and criminal groups. In 2024, at least 121 separate ransomware incidents were recorded in the Netherlands through Project Melissa. The assessment was published alongside an update on the implementation of the national cybersecurity strategy. 

Source: https://www.ncsc.nl/dienstverlening/cybersecuritybeeld-nederland-csbn 
 

Assessment of vital entities (vitaalbeoordeling) under the Wwke: A government-wide process, coordinated by the NCTV with sector ministries, that determines which entities are 'vital' (critical) and therefore in scope of the strengthened obligations. It is anchored in the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke), which transposes the EU CER Directive. 

Source: https://www.nctv.nl/onderwerpen/n/nederlandse-cybersecuritystrategie-2022-2028