ENISA NIS360 Risk Zone: How Regulators Decide Which Clients Get Audited First

In May 2026, ENISA published the third edition of NIS360. Most people read it as a scoreboard. Supervisory authorities read it as a work plan.
That difference matters. NIS360 maps every NIS2 sector against two axes: how critical it is, and how mature its cybersecurity actually is. Where criticality outruns maturity, ENISA draws a "risk zone". National regulators use that map to decide where to spend limited inspection capacity — and in 2026 they finally have the staff to spend it.
If you advise organisations on NIS2, the ENISA NIS360 risk zone tells you which of your clients will hear from a regulator first. Here is what changed this year and what to do about it.
The risk zone is a supervisory priority list, not a grade
ENISA scores criticality on digitalisation, socio-economic impact of an incident, time criticality, and dependency from other sectors. Those inputs move slowly, so criticality scores are broadly stable year to year.
Maturity is the moving part. It covers risk management practice, incident preparedness, information sharing, national authority capability, and sector-level coordination.
A sector lands in the risk zone when its maturity sits below average and below its own criticality. In plain terms: society depends on it more than it can currently defend itself.
Supervisors do not have the headcount to audit every registered entity. They triage. A sector flagged by ENISA as high-criticality with lagging maturity is the cheapest possible justification for a targeted inspection programme — the regulator can point at an EU agency's assessment instead of building the case itself.
Rail, drinking water and wastewater entered the risk zone without getting worse
This is the finding most people misread.
Rail, drinking water and wastewater all moved into the risk zone in the 2026 edition. None of them regressed. Rail actually improved its maturity score, and its criticality was revised upward to reflect how heavily other sectors now depend on it and how often it is being targeted.
They crossed the line because the average moved. Banking, electricity, telecommunications and core internet services kept improving. Aviation, trust services and financial market infrastructures climbed into the high-maturity band. When the top of the distribution rises, the bar for "average" rises with it.
The practical consequence for consultants: a client that did nothing wrong can still find itself reclassified into a supervisory priority sector. "We passed last year's readiness review" is not a defence. Compliance posture is relative to a moving baseline.
Gas is the counter-example worth studying. It started moving out of the risk zone, driven by three unglamorous things: better information sharing, stronger sector-level collaboration, and risk management measures that were actually implemented rather than documented. That is a repeatable playbook, not luck.
Does NIS2 Apply to Your Organisation?
1Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?
Yes▼No▼2Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?
✗NIS2 does not directly apply to your organisation.
Yes▼No▼✓NIS2 applies to your organisation as an Essential or Important Entity.
3Is your organisation a critical infrastructure provider or a qualified trust service provider?
Yes▼!NIS2 may apply to your organisation — seek legal advice to confirm your status.
1Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?
Yes ↓No →2Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?
Yes ↓No →3Is your organisation a critical infrastructure provider or a qualified trust service provider?
Yes ↓No →✗NIS2 does not directly apply to your organisation.
✓NIS2 applies to your organisation as an Essential or Important Entity.
!NIS2 may apply to your organisation — seek legal advice to confirm your status.
AppliesPossibly appliesDoes not apply
ICT service management is in the risk zone — and that includes you
ENISA has flagged ICT service management as a concern in every NIS360 edition so far, and 2026 is no different. The sector has adjusted to NIS2 requirements, but ENISA describes its security measures and operational preparedness as inconsistent.
Read that carefully if you run an MSP or MSSP. This is not a comment about your clients. It is a comment about your own sector.
Two things follow.
First, you are a regulated entity in your own right. Managed service providers and managed security service providers are named in Annex I of NIS2 as essential or important entities depending on size. Your own Article 21 measures are in scope. We covered this double obligation in detail in NIS2 for MSPs and MSSPs.
Second, you are the supply chain risk. ENISA explicitly notes the consequences for the many sectors that depend on managed providers. When a hospital or a water utility is audited, the auditor will ask what security requirements are contractually imposed on its IT provider and how they are verified. That question lands on your desk, phrased as a client request, weeks before you ever meet a regulator yourself.
Expect to be asked for evidence, not assurances: your own risk assessment, your incident response plan, your patching SLAs, your access control model, your subcontractor list. If you are building those requirements into client contracts, supplier contract obligations under Article 21 is the place to start.
NIS2 Penalty Escalation — Beyond the Fine
!Trigger event
Non-Compliance Detected or Incident Occurs
A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements
Authorities can impose▼Non-Monetary Penalties1Compliance orders with binding deadlines
2Mandatory security audits at your expense
3Public disclosure of violations
4Binding instructions on specific security measures
Escalates to▼Operational & Personal Consequences1Suspension of certifications or operating licences
2Temporary ban on management functions for individuals
3Public naming of responsible natural persons
TriggerNon-monetaryOperational / personal
Public administration, space and health each lag for different reasons
The risk zone is not homogeneous. The causes differ, and so do the fixes.
Public administration sits at low-to-moderate maturity. It is newly regulated, and practice varies enormously between national ministries, regional bodies and small municipalities. A national authority may run a mature SOC while a municipality of 12,000 residents has one part-time IT contractor. Same directive, same obligations, wildly different starting points. If you serve public sector clients, assume the gap analysis is genuinely from zero.
Space sits at the lower end of moderate maturity despite rising criticality. Oversight is fragmented, regulatory obligations differ by member state, and adoption of cybersecurity standards is uneven. The strategic importance is climbing faster than the governance.
Health improved measurably and remains in the moderate band, propped up by stronger performers such as pharmaceutical manufacturers. Hospitals and care providers are the drag: legacy systems, exploding IoMT device counts, heavy third-party dependency, thin budgets. We wrote about what this means operationally in NIS2 for healthcare providers.
Maritime and rail share a structural problem — long-lived OT alongside IT, and coordination across infrastructure operators, transport providers and technology suppliers. Nobody owns the whole estate, which makes accountability hard to evidence.
Drinking water and wastewater are the least mature sectors ENISA assessed. Security is largely reactive, environments are fragmented, legacy is everywhere, and information sharing is weak.
What a risk-zone client needs before the regulator calls
Being in the risk zone does not change your obligations. Every Article 21 measure applies identically to a bank and to a wastewater treatment plant. It changes the probability and the timing of scrutiny.
So the sequencing changes. For a risk-zone client, work in this order:
- Registration. Confirm the entity is actually registered with the national authority. Tens of thousands of EU entities still are not, and it is the first thing a supervisor checks.
- The two governance documents. A written risk management policy and an information security policy approved at management level. These are requested first in almost every inspection.
- Evidence of effectiveness. Article 21(2)(f) requires you to assess whether your measures work. Most teams skip it. Auditors do not.
- Incident handling that has been tested. Not a document — a process with a named owner, a 24-hour early warning path, and at least one exercise on record.
- Supply chain register. Who your critical suppliers are, what security requirements bind them, and how those are verified.
If you are not sure where a client stands against all ten measures, our step-by-step NIS2 gap analysis guide walks through the process, and the ten Article 21 measures explained covers what each one actually demands.
Article 21 — 10 NIS2 Cybersecurity Measures
Article 21
10 Cybersecurity Measures
Governance & Strategy
1Risk analysis & information security policies6Effectiveness assessment of security measuresIncident & Continuity
2Incident handling & notification3Business continuity & disaster recoverySupply Chain & Systems
4Supply chain security5Security in network & information systems developmentTechnical Controls
8Cryptography & encryption10Multi-factor authentication & secure communicationsPeople & Assets
7Cyber hygiene & training9HR security & access control
Use NIS360 as a client conversation, not a report
The uncomfortable version of this conversation with a client goes: "you may be inspected soon and you are not ready." The useful version goes: "an EU agency has published where your sector sits, and here is the specific gap between your posture and your sector's exposure."
The second version sells work. It is also more accurate.
Three angles that land with boards:
- Criticality is not something you control. Your sector's dependency profile was assigned by ENISA based on how the rest of the economy relies on you. The only variable you control is maturity.
- Improvement is visible. Sectors moved bands this year. The gas sector's exit path — information sharing, collaboration, implemented controls — is documented and cheap relative to a fine or a suspension.
- The bar keeps rising. Standing still means moving backwards relative to peers. This is now measured annually and published.
If you want a structured starting point for a risk-zone client, run a free NIS2 quick scan. It takes a few minutes and produces a gap overview you can put in front of a management team without a week of prep work.
The short version
ENISA NIS360 2026 shows real progress: maturity is rising across almost every NIS2 sector, and three sectors climbed into the high-maturity band. But the risk zone did not empty out. Rail, drinking water and wastewater joined it because the average moved, ICT service management stayed in it, and public administration, space and health continue to lag for structural reasons.
For consultants and MSPs, NIS360 is the closest thing available to a published supervisory heat map. Read it as one.
And check where your own sector sits. ICT service management is on the list.
Still have a question?
Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.
