ENISA

European Union Agency for Cybersecurity

Agentur der Europäischen Union für Cybersicherheit

ENISA is the European Union's cybersecurity agency. It supports member states and institutions with expertise, coordinates Europe-wide cooperation and plays a central role in implementing Network and Information Security Directive 2 (NIS2), the Cyber Resilience Act and the European certification schemes. It is the technical bracket of EU cybersecurity policy.

History & facts. ENISA has existed since 2004; with the European Union (EU) Cybersecurity Act of 2019 it received a permanent mandate and expanded tasks, particularly in European certification. It publishes situation reports and guidelines, fosters exchange among national bodies and contributes to the concrete shaping of the major legal acts. Unlike national authorities, it acts primarily in a coordinating and supporting role rather than enforcing itself.

Outlook & recommendation. With Network and Information Security Directive 2 (NIS2) and the Cyber Resilience Act (CRA), ENISA's role as a link between European Union (EU) law and national practice grows — for instance in reporting actively exploited vulnerabilities. For companies its publications are a reliable, vendor-neutral orientation, especially where national interpretations are still in flux.

ENISA — European Union Agency for Cybersecurity