Glossary · NIS2

ENISA

The European Union Agency for Cybersecurity, which supports NIS2 implementation with guidance, coordination, and reporting.

Explained in depth: NIS2 overview

ENISA is the EU's cybersecurity agency, headquartered in Athens. Under NIS2, ENISA has several concrete roles: it publishes technical implementation guidance for the Article 21 measures, maintains the European vulnerability database, supports the CSIRTs Network and the Cooperation Group, produces the biennial report on the state of cybersecurity in the Union, and maintains registries such as the one for certain digital-sector entities. For practitioners, ENISA's published guidance, particularly its technical implementation guidance on cybersecurity risk-management measures, is one of the most useful free resources for translating NIS2's legal language into concrete controls that auditors recognise.

Why it matters

When your national authority has not yet published detailed guidance, ENISA's documents are the closest thing to an official interpretation of what "appropriate and proportionate" measures look like. Referencing them strengthens any compliance documentation.

Used in

See also

← All glossary terms