The guidelines help hospitals and healthcare providers integrate cybersecurity objectives across all phases of the procurement life cycle, setting out cybersecurity requirements and the information suppliers must provide. With respect to NIS2, the guidelines align procurement practices with the Directive's security-measure and supply-chain risk-management obligations for essential and important healthcare entities.
Author: ENISA
Status: Adopted / Published
Adoption date: 2026-07-22
Last updated: 19 Aug 2026
Category: Guidance
Subcategory: Official recommendations