Skip to content

9 June 2026 | 12 min

ENISA NIS360 2026: Why NIS2 Maturity Assessment Is Now a GRC Priority

With NIS360 2026, ENISA has published the third edition of its report on the cybersecurity maturity of critical EU sectors. The report assesses how mature individual sectors of high criticality are in managing cyber risks and how critical they are to society, the economy and public safety.

For companies, this is more than just another industry analysis. NIS360 indicates where NIS2 implementation is heading: away from simply determining whether an organisation falls within the scope of NIS2 and towards measurable cybersecurity maturity. The decisive question is no longer only whether a company is subject to NIS2. What increasingly matters is how transparently and systematically risks, controls, responsibilities and evidence are managed.

This moves NIS2 even further into the core of governance, risk and compliance. Companies that do not know their maturity level will struggle to set priorities, explain weaknesses clearly and meet audit or regulatory requirements without significant effort.

ENISA NIS360 2026 assesses the cybersecurity maturity and criticality of sectors of high criticality under NIS2.

The report shows that cybersecurity maturity in Europe is improving, but significant differences between sectors remain.

The comparison between criticality and maturity is particularly relevant. Sectors with high importance but comparatively low maturity are likely to face increased attention.

For GRC professionals, this means that NIS2 is becoming increasingly measurable. Maturity models, control evidence, risk registers, responsibilities and management reporting are becoming more important.

Companies should not treat their NIS2 implementation merely as a compliance project, but as a permanent governance framework for cyber resilience.

What Is ENISA NIS360 2026?

ENISA NIS360 is a report published by the European Union Agency for Cybersecurity. It assesses the cybersecurity maturity of sectors that fall within the sectors of high criticality covered by the NIS2 Directive.

The assessment goes beyond technical security. ENISA considers the entire sectoral context, including competent authorities, affected entities, regulatory requirements, operational capabilities, maturity levels, dependencies and societal importance.

NIS360 therefore provides an overview of how well individual sectors are prepared for cyber risks. At the same time, the report identifies areas that are particularly critical because disruptions could have significant consequences for society and the economy.

For companies, this is important because it provides an indication of the expectations that regulators, customers, auditors and business partners may increasingly impose in the future.

Why NIS360 Is Relevant for Companies

At first glance, NIS360 assesses entire sectors rather than individual companies. Nevertheless, the report is highly relevant to organisations.

It shows which industries are receiving greater regulatory, political and operational attention. When a sector is considered particularly critical, pressure on individual companies within that sector generally increases as well. This does not only affect operators of critical infrastructure, but also service providers, suppliers and digital partners.

Companies therefore need to prepare for increasing demand for evidence. Simply describing individual security measures is no longer sufficient. Organisations are increasingly expected to provide a clear picture of how cyber risks are managed, which controls are effective and how their cybersecurity maturity improves over time.

NIS360 therefore makes one point particularly clear: NIS2 compliance is not a one-time status. It is becoming a continuous maturity process.

From NIS2 Compliance to Cybersecurity Maturity

Many companies initially approached NIS2 by asking one question: Are we affected or not? This question remains important, but it is no longer sufficient.

The next phase of NIS2 implementation is about maturity and effectiveness. Companies must not only understand the requirements but also demonstrate how these requirements have been implemented in practice.

This includes clear governance structures, documented risks, defined measures, effective controls, verifiable evidence and regular management reporting. These elements determine whether an organisation can credibly demonstrate its cybersecurity maturity.

A low maturity level does not automatically mean that a company is non-compliant. However, it highlights where gaps exist, where priorities need to be set and where risks may not yet be managed adequately.

Why Maturity Assessment Is Becoming Critical for GRC Professionals

GRC professionals increasingly need to build bridges between regulatory requirements, technical security measures, operational risks and management decisions.

NIS360 shows that cybersecurity cannot be viewed in isolation. Cyber risks affect supply chains, business processes, crisis management, responsibilities, internal controls and strategic investments.

A maturity assessment helps bring these areas together in a structured way. It answers key questions:

How well prepared is the company for cyber risks?

Which controls are in place, and how effective are they?

Which risks have been accepted, mitigated or remain unresolved?

Which measures should be prioritised?

What evidence is available in the event of an audit?

How does the organisation’s maturity develop over time?

This makes maturity assessment a management and governance tool. It makes progress visible and helps organisations justify investments more effectively.

What Companies Can Learn from NIS360 2026

The key message from NIS360 2026 is clear: cybersecurity maturity is improving, but not evenly. Some sectors are already comparatively advanced, while others remain vulnerable despite their high criticality.

For companies, this means that their own maturity should not only be assessed internally. It also needs to be understood within the context of the relevant industry. A company operating in a particularly critical sector is likely to face stricter expectations than one operating in a less sensitive environment.

This is not only about technical security measures. The decisive factor is whether cybersecurity is embedded within the organisation. Are responsibilities clearly defined? Are risks assessed regularly? Can measures be tracked? Are incidents managed systematically? Is senior management involved? Are supplier risks considered?

Companies that cannot answer these questions clearly have a governance problem, even if individual technical controls are already in place.

The Role of Governance in NIS2

NIS2 makes cybersecurity a management responsibility. This means that cyber risks cannot remain solely within the IT department. They must become part of corporate governance and management.

Governance provides the framework that defines responsibilities, decision-making processes and control mechanisms. Without clear governance, typical weaknesses emerge: unclear responsibilities, fragmented documentation, incomplete tracking of measures and insufficient transparency for management.

Effective NIS2 governance should define who is responsible for cyber risks, how risks are assessed, which controls apply, how measures are prioritised and how progress is reported.

NIS360 reinforces this perspective. Organisations that want to demonstrate their maturity need more than individual security projects. They need a system for managing, monitoring and continuously improving cybersecurity.

Why Evidence Is Becoming a Bottleneck

Many companies already have security policies, risk assessments, training programmes, technical controls and incident management processes. The problem is often not that nothing exists. The problem is being able to prove it.

Information is frequently distributed across different tools, Excel files, email threads, ticketing systems, audit folders and departments. In day-to-day operations, this may work to some extent. During an audit or regulatory request, however, it can quickly become a major challenge.

NIS2 and the associated focus on maturity increase the pressure for centralised evidence management. Companies need to demonstrate which risks have been assessed, which measures resulted from those assessments, who is responsible, which controls have been implemented and when those controls were reviewed.

Evidence therefore becomes a fundamental component of cybersecurity maturity. Without evidence, maturity remains merely a claim.

Which Areas Companies Should Review Now

Companies should use NIS360 2026 as an opportunity to systematically assess their NIS2 readiness. This should go beyond a legal assessment of whether the company falls within the scope of NIS2. The more important question is how robust the organisation’s governance and management framework actually is.

Five areas are particularly important:

First: governance and responsibilities. Companies should clearly define who monitors cyber risks, who approves measures and how senior management is involved.

Second: risk management. Cyber risks should be assessed regularly, prioritised and linked to specific measures.

Third: control management. Security measures must not only exist; they need to be documented transparently and reviewed regularly.

Fourth: incident management and crisis preparedness. Companies should understand how they detect, assess, report and follow up on incidents.

Fifth: supplier and third-party risks. Many cyber risks originate outside the organisation itself. Critical service providers, dependencies and supporting evidence therefore need to be integrated into NIS2 governance.

What an Effective NIS2 Maturity Process Needs to Achieve

A strong maturity process begins with transparency. Companies need to understand which requirements apply, which risks exist and which controls are already in place.

The next step is assessment. Not every gap has the same level of criticality. A maturity model helps organisations classify weaknesses and set priorities. The focus should not only be on formal compliance, but also on actual effectiveness.

Connecting information is equally important. Risks, controls, measures, responsibilities and evidence must not be managed in isolation. Only when these elements are linked can an organisation develop a realistic picture of its cybersecurity maturity.

Finally, regular updates are essential. Cyber risks, threats, systems, supply chains and regulatory expectations continuously change. A maturity assessment is therefore not a one-time check, but part of a continuous improvement process.

Common Mistakes in NIS2 Implementation

One common mistake is focusing exclusively on requirement catalogues. Companies may check which requirements exist while losing sight of effectiveness, prioritisation and evidence.

Another mistake is separating compliance from cybersecurity. If compliance teams only document requirements while IT teams only implement technical measures, there is often no common governance framework. NIS2, however, requires an integrated approach combining risk, controls, technology, organisation and management.

Decentralised documentation is another problem. When risks, measures and evidence are distributed across multiple locations, it becomes difficult to establish a reliable picture of maturity.

A fourth mistake is underestimating supplier risk. Critical digital dependencies in particular can significantly affect an organisation’s own cybersecurity maturity. Companies that do not understand these dependencies cannot credibly manage their cyber resilience.

Why NIS2 Maturity Assessment Also Matters for Companies Not Directly Subject to NIS2

Not every company falls directly within the scope of NIS2. Nevertheless, NIS360 2026 can also be highly relevant for organisations that are only indirectly affected.

Many companies are part of supply chains, provide services to regulated customers or offer digital services. In such cases, customers may increasingly demand evidence of cybersecurity maturity even when there is no direct legal obligation.

This is particularly relevant for IT service providers, cloud providers, software companies, consultancies, managed service providers and specialised suppliers. Companies serving critical customers will increasingly need to explain how they manage cyber risks.

NIS2 therefore extends beyond its direct legal scope. Its requirements are increasingly finding their way into contracts, supplier assessments, procurement processes and customer audits.

Conclusion

ENISA NIS360 2026 clearly shows that NIS2 is evolving from a regulatory obligation into a measurable maturity framework for cybersecurity and GRC.

For companies, this means that cybersecurity can no longer be treated solely as a technical issue or temporary project. What increasingly matters is whether risks, controls, responsibilities and evidence can be managed centrally and systematically.

The most important step is transparency. Companies need to understand where they currently stand, which gaps exist and which measures will have the greatest impact. Maturity assessment provides the foundation for this.

Companies that treat NIS2 merely as a checklist are likely to face increasing pressure over time. Organisations that understand NIS2 as a governance and maturity process can connect regulatory requirements, cyber resilience and management oversight in a meaningful way.

FAQ: ENISA NIS360 2026 and NIS2 Maturity

What is ENISA NIS360 2026?

ENISA NIS360 2026 is a report published by the European Union Agency for Cybersecurity. It assesses the cybersecurity maturity and criticality of sectors of high criticality covered by the NIS2 Directive.

Why is NIS360 important for companies?

The report shows how expectations around cybersecurity and NIS2 implementation are evolving. For companies, it demonstrates that maturity, evidence and governance structures are becoming increasingly important.

What does cybersecurity maturity mean?

Cybersecurity maturity describes how advanced an organisation or sector is in managing cyber risks. It includes risk management, controls, processes, responsibilities, incident management and continuous improvement.

How is NIS360 related to NIS2?

NIS360 examines sectors that fall within the sectors of high criticality covered by the NIS2 Directive. The report helps organisations better understand the maturity and criticality of these sectors.

Why is an NIS2 gap analysis not enough?

A gap analysis identifies which requirements have not yet been fulfilled. However, it often provides limited information about how effective controls are, how well risks are managed and whether evidence is available in an audit-ready format.

What role does governance play in NIS2?

Governance ensures that responsibilities, decision-making processes, controls and reporting are clearly defined. Without effective governance, NIS2 often remains an isolated technical project rather than becoming a manageable business process.

Why is evidence so important?

Evidence demonstrates that risks have been assessed, measures have been implemented and controls have been reviewed. Without evidence, it is difficult to credibly demonstrate maturity to management, auditors, customers or regulators.

Does NIS2 also affect suppliers?

Yes. Suppliers and service providers play an important role. Even if a company does not fall directly within the scope of NIS2, it may be indirectly affected through customer requirements, contractual obligations or audits.

What should companies do now?

Companies should assess their NIS2 maturity, identify key risks, clarify responsibilities, document controls, structure their evidence and incorporate supplier risks into their governance framework.

Is NIS2 compliance a one-time project?

No. NIS2 compliance is a continuous process. Threats, systems, supply chains and regulatory expectations are constantly evolving. Cybersecurity maturity therefore needs to be assessed and improved on a regular basis.

Related posts