ENISA
ENISA is the European Union Agency for Cybersecurity, headquartered in Athens, Greece. It serves EU member states, EU institutions, and approximately 28,700 NIS2 in-scope entities with free cybersecurity frameworks, certification schemes, exercises, and incident response coordination.
- Company typePublic
- Founded2004
- HeadquartersHeraklion, Greece
- Headcount51–100
- GTM typeB2B
- OfferingServices
What ENISA does
ENISA is the European Union Agency for Cybersecurity, established in 2004 and headquartered in Chalandri, Athens, Greece. It operates as a permanent EU agency under Regulation 2019/881 (Cybersecurity Act), serving the 27 EU member states, EU institutions, and the private-sector entities that operate essential and important services within the European single market. Its functional remit covers EU-level cybersecurity coordination, capacity building, certification, vulnerability management, and operational support to member states during cross-border incidents.
Its product and service portfolio spans multiple categories: the European Cybersecurity Skills Framework and associated training programs; NIS2 implementation guidance and the NIS360 annual report; the Cyber Resilience Act Single Reporting Platform; vulnerability management (including its November 2025 designation as a CVE Program Root); certification schemes (including the new EU Digital Identity Wallet certification under eIDAS2); operational tools such as the €36M EU Cybersecurity Reserve; pan-European exercises (Cyber Europe); threat-intelligence reporting (ETL, NIS360); and sectoral initiatives spanning energy, health, transport, digital infrastructure, and (as of 2025) the space sector. The platform architecture is fundamentally policy-and-framework-driven rather than product-software-driven, with technical operations concentrated in incident response coordination, reporting infrastructure, and exercises.
ENISA operates as a non-commercial public agency funded through the EU general budget; it does not sell products or charge fees, and pricing is not a go-to-market dimension. With 51-100 staff and a distributed mandate across all EU member states, its growth mechanism is regulatory mandate expansion rather than revenue capture. Recent mandate expansions under NIS2 (covering ~28,700 entities), the Cyber Resilience Act, and eIDAS2 have materially enlarged its operational surface since 2024.
ENISA firmographics
Firmographics- Name
- ENISA
- Legal name
- European Union Agency for Cybersecurity
- Website
- https://enisa.europa.eu
- Company type
- Public
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- ENISA is the European Union Agency for Cybersecurity, headquartered in Athens, Greece. It serves EU member states, EU institutions, and approximately 28,700 NIS2 in-scope entities with free cybersecurity frameworks, certification schemes, exercises, and incident response coordination.
- Ownership category
- akta.pro rank
ENISA industry classification
Industry- Product category
- Public Cybersecurity Agency Services
- NAICS
- National Security (928110), National Security and International Affairs (928), Regulation and Administration of Communications, Electric, Gas, and Other Utilities (92613)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Industrial Endpoint Protection (PLC/HMI/Engineering Workstation EDR) (HDADAJAD)
Keywords
Where ENISA is headquartered
LocationHeadquarters
- HQ city
- Heraklion
- HQ country
- Greece
- HQ region
- Europe
Offices1 record
Markets served
ENISA business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Distribution channels3 records
Marketing channels7 records
ENISA product offering
Product offeringCore offering
ENISA is the European Union Agency for Cybersecurity, operating digital platforms (European Vulnerability Database, Single Reporting Platform, NCAF 2.0 tool, CyberEducation Platform, CYBERHEAD), publishing technical guidance and reports, coordinating incident response networks (EU CSIRTs Network, EU-CyCLONe), managing EU cybersecurity certification schemes, and running exercises and training programs. All outputs are provided free of charge and funded through the EU budget via the Digital Europe Programme.
Product overview
ENISA (European Union Agency for Cybersecurity) operates as a platform of interconnected tools, reports, frameworks, certification schemes, exercises, and networks rather than a single unified product. The core portfolio includes: the European Vulnerability Database and Single Reporting Platform for vulnerability management and incident reporting; the National Capabilities Assessment Framework Tool for maturity assessment; the EU Cybersecurity Reserve (€36 million) for incident response support; and the EU Cybersecurity Certification Framework including EUCC and EUDI Wallet schemes. Supporting these are training and competition programs including Cyber Europe exercises, European and International Cybersecurity Challenges, the Cybersecurity Skills Framework, CYBERHEAD higher education database, and CyberEducation Platform. Operational coordination is delivered through CSIRTs Network and EU-CyCLONe crisis liaison network, complemented by sector-specific forums for telecom, eHealth, and energy security. The portfolio also includes technical guidance documents such as NIS2 Implementation Guidance, Handbook for Cyber Stress Tests, Security by Design Playbook, and Technical Advisory on Package Managers.
Differentiator
Problem solved
Functional benefit
Products and services
- European Vulnerability Database (EUVD) Provides aggregated, reliable, and actionable information on cybersecurity vulnerabilities affecting ICT products and services, including mitigation measures and exploitation status. Operated by ENISA under NIS2 mandate.
- National Capabilities Assessment Framework (NCAF) Tool 2.0 Methodology and online tool supporting national authorities to assess and strengthen cybersecurity capabilities and evaluate the maturity of national cybersecurity frameworks across EU member states.
- Single Reporting Platform (SRP) Centralized digital platform managed by ENISA for security incident reporting under the Cyber Resilience Act and other EU legal frameworks, providing a harmonized reporting interface.
- ENISA CyberEducation Platform Central hub for cybersecurity educational resources tailored for primary and secondary schools in each Member State.
- CYBERHEAD - Cybersecurity Higher Education Database Largest validated cybersecurity higher education database in EU and EFTA countries, providing reference for citizens seeking to upskill in cybersecurity and helping universities attract students.
- Cybersecurity Maturity Assessment Tool for SMEs Tailored assessment tool for small and medium-sized enterprises to evaluate cybersecurity maturity and prepare for the EU Cyber Resilience Act.
- ISAC-in-a-Box Toolkit Toolkit supporting the establishment and operation of sectoral Information Sharing and Analysis Centres (ISACs) across EU critical sectors.
- EU Cybersecurity Reserve €36 million reserve managed by ENISA to support responses to major cyber incidents across EU and associated third countries, funded through the Digital Europe Programme under the Cyber Solidarity Act.
- EU Cybersecurity Certification Framework Framework established under the EU Cybersecurity Act for certifying ICT products and services, including the published EUCC scheme and schemes under development for cloud, 5G, and digital identities.
- EU Digital Identity (EUDI) Wallet Certification Scheme Draft certification scheme for European Digital Identity Wallets under development by ENISA, with public consultation launched in 2026 and supported by a €1.6 million contribution agreement.
- Cyber Europe Exercise Pan-European biennial cybersecurity exercise simulating large-scale cybersecurity incidents that escalate to EU-wide cyber crises, testing response coordination across EU Member States.
- European Cybersecurity Challenge (ECSC) Annual competition for young cyber talents across EU and EFTA countries, featuring technical challenges in web security, crypto puzzles, reverse engineering, forensics, and attack/defense scenarios.
- International Cybersecurity Challenge (ICC) Global cybersecurity competition where Team Europe competes against teams from around the world, testing advanced cybersecurity skills.
- European Cybersecurity Skills Framework (ECSF) Framework identifying and defining key cybersecurity roles and competencies needed in the field, helping organizations align training and recruitment with industry demands.
- BlueOLEx Exercise Annual executive-level cyber exercise testing cooperation among cybersecurity crisis management executives and directors across EU Member States.
- CySOPex Exercise Annual exercise for EU-CyCLONe officers testing standard operating procedures and information sharing processes for incident response.
- ENISA NIS360 Report Annual assessment report evaluating cybersecurity maturity and criticality of all sectors of high criticality under the NIS2 Directive, covering the entire ecosystem of assessed sectors.
- ENISA NIS Investments Report Annual report exploring how cybersecurity policy translates into practice across EU organizations and effects on investments, resources, and operations.
- NIS2 Technical Implementation Guidance Technical guidance supporting implementation of NIS2 Directive for digital infrastructure, ICT service management and digital providers sectors.
- Handbook for Cyber Stress Tests Guidance document for national or sectoral authorities overseeing cybersecurity and resilience of critical sectors under NIS2 Directive, providing a methodology for cyber stress tests.
- Security by Design Playbook Playbook emphasizing integration of security by design and default across the entire product lifecycle, focusing on architectural foundations and operational integrity.
- ENISA Technical Advisory on Package Managers Guidance document helping developers securely use third-party packages, outlining supply chain risks and secure practices.
- Cyber Hygiene in the Health Sector Guidance document providing practical measures for health entities to mitigate cybersecurity risks, safeguard sensitive data, and strengthen cyber resilience.
- ENISA Cyber Partnership Programme (CPP) Programme enhancing information sharing between ENISA and the private sector on cybersecurity threats and situational awareness.
- ENISA Cybersecurity Exercise Methodology Updated framework providing organizations and governments with a structured approach for planning, executing, and evaluating cybersecurity exercises.
Quantifiable outcome
- 5 consecutive victories for Team Europe in International Cybersecurity Challenge (2022-2026)
- +3 more outcomes
Companies that use ENISA
Customer profileNamed customers4 records
Segments3 records
Ideal customer profiles2 records
ENISA technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
ENISA partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered major, core and supporting.
- Anthropic (Project Glasswing)majorENISA was invited by Anthropic to join Project Glasswing, giving the EU cybersecurity agency access to the Mythos AI model capable of identifying software vulnerabilities. A meeting was scheduled in San Francisco on June 18, 2026. However, following a U.S. export control directive, ENISA was informed it would no longer receive access to the Glasswing program.
- European Cybersecurity Competence Centre (ECCC)coreENISA collaborates with the European Cybersecurity Competence Centre on initiatives including the Woman International Cybersecurity Challenge (WICC) in Dublin and the 10th eHealth Security Conference co-organized with the Romanian National Cyber Security Directorate (DNSC).
- EU CSIRTs NetworkcoreENISA serves as the secretariat for the EU CSIRTs Network, a cooperative framework for Computer Security Incident Response Teams across EU member states and CERT-EU. The network facilitates information exchange, coordinated incident response, and development of trust between national CSIRTs. ENISA provides infrastructure, tools, and coordination support to enable effective cooperation on cross-border incidents.
- European Supervisory Authorities (ESAs)majorENISA signed a Memorandum of Understanding with the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) to strengthen cooperation and information exchange, particularly regarding digital operational resilience under DORA.
- EU-CyCLONe (European Cyber Crisis Liaison Organisation Network)coreENISA serves as the secretariat for EU-CyCLONe, formally established by NIS2 for supporting coordinated management of large-scale cybersecurity incidents and crises. ENISA provides support and tools to the network which is chaired by the Presidency of the Council of the EU. EU-CyCLONe cooperates with the European Commission during significant incidents affecting NIS2 entities.
- Europol European Cybercrime Centre (EC3)coreENISA and Europol's EC3 have conducted annual workshops on CSIRT-Law Enforcement cooperation since 2011, celebrating the 10th anniversary in 2021. The partnership enables synergies between incident response teams and law enforcement communities across EU member states, facilitating joint operations and cooperation frameworks such as the EMOTET takedown.
- Association of European Distribution System Operators (E.DSO)majorENISA jointly organizes the annual Cybersecurity Forum with E.DSO, European Energy - Information Sharing & Analysis Centre (EE-ISAC), and European Network for Cyber Security (ENCS). The 9th edition scheduled for October 8, 2026 in Brussels focuses on grid cyber resilience and bridging regulation with innovation.
- Team Europe Supporters (Accenture, Ubitech)supportingAccenture and Ubitech have generously supported Team Europe activities including training bootcamps, qualifier events, and preparation activities for the International Cybersecurity Challenge. The companies provided specialized training and authored challenges during the selection process.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
ENISA competitors and assessment
Company assessmentDirect peers
- NCSC UK (National Cyber Security Centre): UK's national cybersecurity authority responsible for incident response, technical guidance, and critical infrastructure protection, with a mandate, structure, and product portfolio (vulnerability disclosure, certification, exercises) closely aligned to ENISA's.
- BSI (Bundesamt für Sicherheit in der Informationstechnik): Germany's federal cybersecurity authority, responsible for cybersecurity standards, certification, and incident response with a comparable mandate to ENISA at the national level, including the IT-Grundschutz certification framework that parallels ENISA's EUCC.
- ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information): France's national cybersecurity agency, performing cybersecurity regulation, certification (CSPN), incident response coordination, and technical guidance — operating as ENISA's national-level counterpart in the largest EU member state.
- CISA (Cybersecurity and Infrastructure Security Agency): US federal agency performing the closest functional analog of ENISA's role — national cybersecurity coordination, vulnerability management, critical infrastructure protection, and incident response — making it the most directly comparable national cybersecurity agency peer.
- European Cybersecurity Competence Centre (ECCC): EU body managing cybersecurity competence and innovation funding under the Digital Europe Programme; ENISA and ECCC jointly organize the WICC and eHealth Security Conference, with overlapping mandates in skills development and community building.
- NIST (National Institute of Standards and Technology): US agency producing cybersecurity frameworks and standards (NIST CSF, NICE) that serve as functional parallels to ENISA's NIS2 implementation guidance, ECSF skills framework, and EU certification schemes.
Others
- FIRST (Forum of Incident Response and Security Teams): Global association of incident response and security teams coordinating CSIRT cooperation and standards; ENISA's CSIRTs Network operates as a complementary regional coordination layer in the same ecosystem.
- MITRE Corporation: Operates the CVE Program and ATT&CK framework; ENISA's CVE Root designation places it in a co-stewardship relationship with MITRE for global vulnerability disclosure infrastructure, making MITRE a direct functional peer for the EUVD product line.
- Europol EC3 (European Cybercrime Centre): EU agency within Europol focused on cybercrime investigations, partnering with ENISA on CSIRT-Law Enforcement cooperation since 2011 and on joint operations like EMOTET takedown, with an adjacent but complementary mandate to ENISA's.
Regional players
- NATO CCDCOE (Cooperative Cyber Defence Centre of Excellence): NATO-affiliated cyber defense center in Tallinn focused on cybersecurity research, training, and exercises, with overlapping scope on cross-border incident coordination but distinct NATO defense-orientation versus ENISA's EU civilian focus.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
ENISA social profiles
Digital presenceENISA financial estimates
Financial estimateRevenue estimate
Valuation estimate
ENISA leadership team
Management profileNumber of profiles
Profiles2 records
ENISA funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ENISA M&A and investment
M&A and investmentM&A
Investments24 records
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ENISA
What does ENISA do?
ENISA is the European Union Agency for Cybersecurity, operating digital platforms (European Vulnerability Database, Single Reporting Platform, NCAF 2.0 tool, CyberEducation Platform, CYBERHEAD), publishing technical guidance and reports, coordinating incident response networks (EU CSIRTs Network, EU-CyCLONe), managing EU cybersecurity certification schemes, and running exercises and training programs. All outputs are provided free of charge and funded through the EU budget via the Digital Europe Programme.
Is ENISA a public or private company?
ENISA is a public company. It is classified as state government owned and is currently operating.
When was ENISA founded?
ENISA was founded in 2004. It employs 51 to 100 people.
Where is ENISA based?
ENISA is headquartered in Heraklion, Greece, in the Europe region.
Who are ENISA's main competitors?
Direct peers on record are NCSC UK (National Cyber Security Centre), BSI (Bundesamt für Sicherheit in der Informationstechnik), ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), CISA (Cybersecurity and Infrastructure Security Agency), European Cybersecurity Competence Centre (ECCC) and NIST (National Institute of Standards and Technology). Others are FIRST (Forum of Incident Response and Security Teams), MITRE Corporation and Europol EC3 (European Cybercrime Centre). NATO CCDCOE (Cooperative Cyber Defence Centre of Excellence) is listed as a regional player.
Does ENISA have an API?
No public API is recorded for ENISA.
What industry is ENISA in?
ENISA's product category is Public Cybersecurity Agency Services. Its primary akta.pro industry code is HDADAJAD, Industrial Endpoint Protection (PLC/HMI/Engineering Workstation EDR). Its NAICS code is 928110 and its SIC code is 8700.