Back to glossaryLaw & regulation

ENISA (EU Agency for Cybersecurity)

The European Union's dedicated cybersecurity agency, which publishes technical frameworks and guidance for national authorities and regulated entities.

Definition

The European Union Agency for Cybersecurity, known by its acronym ENISA, was founded in 2004 and its mandate was strengthened by the Cybersecurity Act of 2019, which gave it a permanent and expanded role. Its mandate covers several complementary dimensions. It assists the European Commission and member states in developing cybersecurity policy, publishes technical frameworks that guide the practices of regulated entities, and runs the EU Cybersecurity Certification Scheme, known as EUCS, designed to harmonize requirements for cloud service providers. In the NIS2 context, ENISA plays a decisive role, as its June 2025 technical implementation guidance on Article 21 measures constitutes the reference guide linking legal obligations to existing standards, including ISO 27001, allowing entities to rely on recognized certifications to demonstrate compliance. For the insurance market, these frameworks have a dual value: prescriptive, since they define the expected standard, and informational, since they constitute a homogeneous basis for assessing the security level of policyholders across Europe.

Example

A large German industrial group, designated an essential entity under NIS2, decides to rely on its existing ISO 27001 certificate to demonstrate compliance with Article 21 measures. ENISA's 2025 technical guidance explicitly maps ISO 27001 controls to NIS2 requirements, enabling it to present its cyber insurer with a structured and recognized compliance dossier. The insurer reduces the policy deductible by 20 per cent for ISO-27001-certified entities whose NIS2 compliance is documented in accordance with the ENISA framework.

Related terms
Related articles
Also known as

Agence de l'Union européenne pour la cybersécurité, European Union Agency for Cybersecurity