The European Union Agency for Cybersecurity (ENISA) plays a crucial role in supporting the implementation and effectiveness of the NIS2 Directive. Its responsibilities cover various areas, from providing guidelines and developing methodologies to facilitating cooperation and maintaining key cybersecurity resources.
Below is a detailed overview of ENISA’s contributions based on available sources:
1. Guidelines and support:
- Article 3, paragraph 4: ENISA, in collaboration with the European Commission, is tasked with providing “guidelines and templates” to Member States regarding the information that essential and important entities must submit to competent authorities. This support simplifies the process of identifying and registering entities under the NIS2 Directive.
- Article 4, paragraph 3: ENISA assists the Commission in developing guidelines that clarify the relationship between the NIS2 Directive and other EU legal acts regarding risk management and cybersecurity incident reporting. These guidelines are fundamental to ensuring consistency and avoiding regulatory overlaps.
- Article 7, paragraph 4: ENISA provides support to Member States, upon their request, in developing or updating their national cybersecurity strategies. This support includes the creation of key performance indicators (KPIs) to assess the effectiveness of strategies in line with NIS2 objectives.
- Article 10, paragraph 12: ENISA can assist Member States in developing their Computer Security Incident Response Teams (CSIRTs), which are central to managing and responding to cybersecurity incidents.
- Article 24, paragraph 3: In cases where no appropriate European cybersecurity certification schemes exist, the Commission may request ENISA to prepare a proposal for such a scheme. This role underscores ENISA’s expertise in developing and promoting cybersecurity standards.
- Article 25, paragraph 2: ENISA, in collaboration with Member States and stakeholders, develops advisory documents and guidelines on technical standards and existing national and international standards for the security of network and information systems. This contributes to the harmonization of cybersecurity practices across the EU.
- Article 29, paragraph 5: ENISA provides support for the conclusion of cybersecurity information-sharing agreements between essential and important entities, offering guidelines and facilitating the exchange of best practices. This role promotes collaborative approaches to cybersecurity.
2. Facilitating cooperation and information sharing:
- Article 12, paragraph 2: ENISA develops and maintains the European vulnerability database, a central repository of information on publicly known vulnerabilities in ICT products and services. This database is accessible to all stakeholders, helping to improve threat intelligence and vulnerability management.
- Article 14, paragraph 2: ENISA is a member of the NIS Cooperation Group, a key body for strategic cooperation and information exchange between Member States, the Commission, and ENISA itself.
- Article 15, paragraph 2: ENISA provides the secretariat for the CSIRTs Network, facilitating operational cooperation between national CSIRTs and supporting a rapid and effective response to incidents.
- Article 16, paragraph 3: ENISA provides the secretariat for EU-CyCLONe (European cyber crisis liaison organisation network), supporting secure information exchange and cooperation between Member States during large-scale cybersecurity incidents and crises.
- Article 19, paragraphs 1 and 6: ENISA assists the Cooperation Group in developing the methodology and organizational aspects of peer reviews, which assess the cybersecurity capabilities of Member States and the implementation of policies. ENISA also collaborates on the development of codes of conduct for cybersecurity experts involved in peer reviews.
3. Reporting and analysis:
- Article 18, paragraphs 1 and 3: ENISA, in collaboration with the Commission and the Cooperation Group, publishes a biennial report on the state of cybersecurity in the EU. This report includes a cybersecurity risk assessment, an overview of national cybersecurity strategies, and recommendations for improvements. ENISA also develops the methodology for the aggregate assessment of national cybersecurity capabilities.
4. Indirect influence on SMEs:
Although not directly aimed at SMEs, ENISA’s activities under NIS2 indirectly influence their cybersecurity posture. For example, the European vulnerability database offers an advantage to all stakeholders, including SMEs, by providing valuable threat intelligence information. Furthermore, larger companies subject to NIS2 must address cybersecurity risks within their supply chains, which encourages SMEs to adopt more robust cybersecurity practices.
In summary, ENISA plays a multifunctional and crucial role in supporting the implementation and effectiveness of the NIS2 Directive. Its responsibilities include providing guidelines and support to Member States and entities, facilitating cooperation and information exchange, and contributing to the overall improvement of cybersecurity across the EU. For organizations that need to verify or build their NIS2 Directive compliance path, knowing the institutional framework in which ENISA operates is a useful starting point — as is understanding which entities fall under the ACN list and which deadlines apply. The official text of the NIS2 Directive remains the basic regulatory reference for delving deeper into any cited article.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
