The report is ENISA's annual assessment of the cybersecurity maturity and criticality of the high-criticality sectors defined under Annex I of NIS2. It measures each sector's maturity across legislation and effectiveness, company preparedness, institutional capacity of authorities, and sectoral ecosystem structures, and separately ranks criticality by systemic relevance, exposure, and impact of disruption. It identifies a "risk zone" of sectors combining lower maturity with above-average criticality — this year comprising health, railway, maritime, ICT management services, space, public administration, and drinking/waste water — and tracks how sectors move in and out of that zone over time.
Author: ENISA
Status: Adopted / Published
Adoption date: 2026-05-28
Last updated: 19 Aug 2026
Category: Miscellaneous
Subcategory: Report