European Union Agency for Cybersecurity (ENISA) Created byGalina MISHEVA|Updated23 August 2026The European Union Agency for Cybersecurity (ENISA) is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure.ENISA deals with a wide range of technological topics related to cybersecurity, such as cloud computing, Internet of Things (IoT), technological and network infrastructure availability, Big Data and security of databases, and CSIRT Services (alerts and warnings, incident and vulnerability handling, tools development, knowledge-sharing, and community-driven projects). It is responsible for the development of a European cybersecurity certification programme and is behind key policy documents the EU Cybersecurity Act and the NIS2 (Network and Information Security) Directive. NIS2 enhances cybersecurity across the EU by establishing a cyber crisis management structure (CyCLONe), harmonizing security requirements and reporting obligations, and encouraging Member States to address new areas such as supply chain security, vulnerability management, core internet services, and cyber hygiene in their national cybersecurity strategies. Additionally, NIS2 introduces peer reviews to improve collaboration and knowledge sharing among Member States and expands coverage to more sectors, thereby requiring more entities to implement cybersecurity measures.The Nis which aims to achieve a high common level of cybersecurity across the Union by improving the cybersecurity capabilities of member states and enhancing cooperation among them. The NIS Directive sets out security and incident reporting requirements for operators of essential services and digital service providers, ensuring that critical infrastructure and key digital services are better protected from cyber threatsENISA also undertakes a wide range of short- and long-term actions: enhancing and strengthening cybersecurity skills across all levels, from people with little technological background to digital professionals and experts in various fields; providing quality cybersecurity education, targeting ICT professionals, companies and SMEs. ENISA also supports and works together with businesses to develop trainings tailored to operational and organisational needs. ensuring the safe and secure development of IoT and Smart Infrastructures, with their increased connectivity and dependence on safe and secure cyber networks. provision of threat landscape analysis and risk management and foresight of potential cyber threats. In particular, ENISA continues to raise citizens’ awareness of cybersecurity and potential cyber threats (phishing attacks, botnets, financial and banking frauds, data fraud) by providing guidance on good practices to promote safer online behaviour (such as cyber-hygiene and cyber-literacy). Furthermore, aligning its actions with the European Digital Education Action Plan, ENISA is promoting and analysing cybersecurity education, in order to tackle the cybersecurity professional shortfall. Initiative DetailsWebsite linkENISA Target audienceDigital skills for the labour force.Digital skills for ICT professionals and other digital experts.Digital skills in education.Digital skills for allDigital technology / specialisationCybersecurityDigital skill levelAdvancedDigital ExpertGeographic scope - CountryAustriaBelgiumBulgariaCyprusRomaniaSloveniaCroatiaCzech republicDenmarkEstoniaFinlandFranceGermanyGreeceHungaryItalyIrelandMaltaLatviaLithuaniaLuxembourgNetherlandsPortugalPolandSwedenSpainSlovakiaShow moreShow lessIndustry - field of education and trainingInformation and Communication Technologies (ICTs) not further definedSoftware and applications development and analysisGeographical sphereEU institutional initiativeLog in to comment
New Cybersecurity Package strengthens EU cyber resilience and capabilities, addresses security risks News
Towards organisational cyber resilience: strategies for cybersecurity skills training and enhancing awareness of cyber threats Deep-dives