sota.io
Join the waitlist
2026-09-15·11 min read·sota.io team

ENISA's NIS360 2026: The Sectors Actually Falling Behind on NIS2 (Not the '16% Compliant' Stat You've Seen)

ENISA's NIS360 2026: The Sectors Actually Falling Behind on NIS2 (Not the '16% Compliant' Stat You've Seen)

If you've read anything about NIS2 compliance in the past few months, you've probably seen this line: "only 16% of entities are fully NIS2-compliant, according to ENISA." It shows up in security newsletters, LinkedIn posts, and more than a few vendor blogs — usually right next to a mention of ENISA's flagship NIS360 2026 report, published 28 May 2026.

There's just one problem: that number isn't in the NIS360 report. We pulled the actual 82-page PDF directly from ENISA and read it. It contains zero self-reported compliance percentages — its entire methodology is built differently, and it never asks a single organization "are you compliant?" The 16% figure comes from somewhere else entirely, and the real NIS360 findings are arguably more useful for anyone building software for a NIS2-regulated sector: three sectors just crossed into ENISA's formal "risk zone," and one finally got out.

Where the 16% number actually comes from

Trace the "16% compliant" claim back through enough coverage and it eventually points to The CyberSmart NIS2 Survey — a report commissioned by CyberSmart, a UK managed-security-services vendor, not by ENISA or any EU body. CyberSmart's own report describes its method plainly: a survey of 670 business leaders across the UK, Poland, the Netherlands, Ireland, France, Germany, Denmark and Belgium, fielded via OnePoll in late 2025. It's a perception survey — it asks executives whether they consider themselves fully compliant, and 16% said yes.

That's a legitimate data point about how confident business leaders feel. It is not the same thing as ENISA's own structured cybersecurity-maturity assessment, and treating it as an ENISA finding gives a private vendor's marketing survey the institutional authority of an EU cybersecurity agency it never claimed for itself. To be clear, CyberSmart's report doesn't misrepresent its own methodology — it's upfront that it's a commissioned OnePoll survey. The misattribution happens downstream, in the secondary coverage that cites "16%" next to "ENISA" without checking which document the number actually sits in.

ENISA NIS360 2026CyberSmart NIS2 Survey
Who produced itEuropean Union Agency for CybersecurityCyberSmart (UK MSP vendor)
What it measuresStructured maturity score (4 dimensions) per Annex I sector, built from national-authority supervisory data, company surveys, and EU-level dataSelf-reported perception, 670 business leaders, OnePoll fielding
Unit of analysisSectors (health, energy, transport, etc.)Individual businesses' self-assessment
Publication28 May 2026 (third edition)Late 2025 fieldwork, published Q1 2026
Says "16% compliant"?No — not a self-report instrument at allYes, this is the actual source

What NIS360 2026 actually measures

ENISA's own description of the methodology is specific: NIS360 scores each NIS2 Annex I sector across four maturity dimensions — policy frameworks (legislation effectiveness), cyber risk management (company implementation plus supervisory insight), information sharing and collaboration, and operational preparedness (incident response testing, business continuity). It separately scores each sector's criticality (digitalization level, socioeconomic impact of incidents, time-criticality). Comparing the two gives ENISA what it calls the risk zone: sectors "characterised by lower-than-average maturity but higher criticality relative to their maturity" — in plain terms, sectors more important to society than their current cybersecurity posture can support.

This is the third edition of the report. The headline direction is genuinely positive: overall maturity is "steadily improving," and three sectors — trust services, aviation, and financial market infrastructures — moved into the high-maturity band this year, joining the long-standing leaders (banking, electricity, telecommunications). Four more sectors strengthened within the moderate band: gas, road, maritime, and health.

But "steadily improving on average" hides a widening split, and that split is exactly what the risk-zone concept is built to surface.

Seven sectors, and three that just got worse relative to their own risk

As of this edition, ENISA lists seven sectors in the risk zone: health, railway, maritime, ICT service management, space, public administrations, and drinking and waste water. The report is explicit that this list changed since the last edition — and not in the direction the "steadily improving" headline might suggest:

"Three sectors previously at the risk zone boundary — rail, drinking water, and waste water — are now within the risk zone. The positive development is that the gas sector has started moving out of the risk zone."

Gas is the one sector that improved enough to exit — ENISA attributes it to "improved information sharing, stronger collaboration, and better implementation of risk management measures." Rail, drinking water and waste water moved the other way, from the boundary into the zone itself.

Here's what ENISA says about the sectors most relevant if you build software, run infrastructure, or sell into any of them:

ICT service management — the sector that includes managed service providers and the vendors many of the other sectors depend on — is still stuck at "moderate level, with modest and mostly ad hoc progress over the past year due to its inconsistent application of security measures and limited improvements in operational preparedness." ENISA adds a detail that matters for anyone selling into this space: "many national authorities remain relatively new to overseeing the sector, often lacking the sector-specific and cybersecurity expertise that would enable them to do so effectively." Supervisory scrutiny here is still catching up to the law — which usually means it's about to intensify, not stay light.

Public administrations are described as "still at an early stage of cybersecurity maturity, as it is a newly regulated sector," with "reactive and uneven risk management and limited collaboration across entities." If your customer is a municipality, agency, or public-sector body, this is your customer's own regulator describing them as early-stage.

Drinking water and waste water remain "amongst the least mature sectors assessed," with approaches "largely reactive and ad-hoc," hindered by "heterogeneity, resource constraints, and the prevalence of legacy systems" — a direct description of the OT/ICS environments this sector runs on.

Maritime and railway face a structural problem ENISA calls out directly: they depend on "long-lived OT and IT systems" and are exposed through "supply chain and third-party providers," while their "increasing role in military logistics raises their strategic importance and potential attractiveness" as targets.

Health stays in the risk zone despite genuine progress, driven by "increasing digitalisation (including the use of IoT and IoMT), growing dependence on third parties and suppliers, [and] prevalence of legacy and obsolescence."

Why risk-zone status matters if you sell into one of these sectors

A sector landing in ENISA's risk zone isn't just a research footnote — it's a structural signal about where NIS2 enforcement pressure is heading next, and it lands squarely on vendors, not just the regulated entities themselves.

NIS2's Article 21(2) risk-management measures require essential and important entities to address supply chain security — Article 21(2)(d) — and security in the acquisition, development, and maintenance of network and information systems, including vulnerability handling, under Article 21(2)(e). We've covered what Article 21(2)(d) actually requires from suppliers and what secure-development-lifecycle evidence looks like under 21(2)(e) in more depth elsewhere. The mechanism that matters here: an entity in a low-maturity sector can't demonstrate strong supply-chain risk management on its own — it has to demonstrate it through its vendors, because that's where a meaningful share of its actual risk-management measures are enforced contractually. If your customer's regulator has just told them, in an official EU report, that their sector is behind, expect that pressure to show up in your next security questionnaire, not just theirs.

The supervision gap compounds this. For essential entities — which most risk-zone-sector organizations of any size are — Article 32 gives national authorities an ex-ante and ex-post regime: on-site inspections, audits, and security scans, not just after-the-fact enforcement. We wrote about what proactive Article 32 supervision looks like in practice. ENISA's own report notes that authorities overseeing ICT service management, space, and several other risk-zone sectors are themselves "relatively new" to the job — which means audit programs in these sectors are still ramping up, not settling into a steady state. If you're a vendor to a risk-zone customer today, the audit rigor you're seeing now is closer to the floor than the ceiling.

A short checklist if a risk-zone sector is your customer

If your users or customers sit in health, rail, maritime, ICT service management, space, public administration, or water/wastewater, three things are worth doing now rather than after your next enterprise deal stalls in security review:

  1. Get your own Article 21(2) risk-management measures documented before you're asked. Risk assessment, incident handling, business continuity, supply chain security, secure development, effectiveness review, cyber hygiene, cryptography, access control, and MFA — the ten measures under Article 21(2)(a)-(j) map almost directly onto what a risk-zone customer's own auditor will ask their vendors to demonstrate.
  2. Align your incident-reporting SLA to the actual NIS2 cascade, not a generic 24-hour promise: a 24-hour early warning, a 72-hour notification, and a one-month final report under Article 23(4). If your contract commits to notifying a risk-zone customer "immediately" without matching this structure, you're either over-promising or leaving them unable to meet their own regulator's clock.
  3. Expect vendor security questionnaires to get longer, not shorter, over the next year in these seven sectors specifically — supervisory capacity is visibly still being built, and new capacity tends to translate into new documentation requests. We keep a running NIS2 vendor security questionnaire reference if you want to see the shape these typically take.

Check the source, not just the number

The broader lesson here isn't really about NIS2 — it's about how to handle any statistic that gets attached to a regulator's name in secondary coverage. Two checks would have caught this one before it spread as far as it did: first, does the organization named in the headline actually publish the number, or is it being quoted about a topic the organization also covers? Second, is the underlying data a structured assessment (built from supervisory records, audits, or verified evidence) or a self-report (people describing their own confidence level)? ENISA's NIS360 is the former. The 16% figure is the latter — a real, disclosed, methodologically sound survey result from a UK vendor, just not the EU regulator's own assessment it keeps getting attached to.

The real ENISA numbers — three sectors sliding into the risk zone, one climbing out, and a public admission that several sectors' own regulators are still building the expertise to oversee them — are the more useful signal if you're deciding where to harden your compliance posture next. They're also the ones you can actually point back to a primary source.

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.