The guidelines help hospitals and healthcare providers integrate cybersecurity objectives across all phases of the procurement life cycle, setting out cybersecurity requirements and the information suppliers must provide. With respect to the European Health Data Space Regulation, the guidelines align procurement practices with security requirements for electronic health record systems and health data exchange infrastructure.
Author: ENISA
Status: Adopted / Published
Adoption date: 2026-07-22
Last updated: 19 Aug 2026
Category: Guidance
Subcategory: Official recommendations