Developer docs
API playgroundTry for free, no card

Search company profiles

ENISA

Full company profile

uuid0004fy4

Namestring
ENISA
Legal namestring
European Union Agency for Cybersecurity
Websiteurl
enisa.europa.eu
Company typeenum
Public
Founded yearint
2004
Descriptiontext

ENISA is the European Union Agency for Cybersecurity, established in 2004 and headquartered in Chalandri, Athens, Greece. It operates as a permanent EU agency under Regulation 2019/881 (Cybersecurity Act), serving the 27 EU member states, EU institutions, and the private-sector entities that operate essential and important services within the European single market. Its functional remit covers EU-level cybersecurity coordination, capacity building, certification, vulnerability management, and operational support to member states during cross-border incidents.

Its product and service portfolio spans multiple categories: the European Cybersecurity Skills Framework and associated training programs; NIS2 implementation guidance and the NIS360 annual report; the Cyber Resilience Act Single Reporting Platform; vulnerability management (including its November 2025 designation as a CVE Program Root); certification schemes (including the new EU Digital Identity Wallet certification under eIDAS2); operational tools such as the €36M EU Cybersecurity Reserve; pan-European exercises (Cyber Europe); threat-intelligence reporting (ETL, NIS360); and sectoral initiatives spanning energy, health, transport, digital infrastructure, and (as of 2025) the space sector. The platform architecture is fundamentally policy-and-framework-driven rather than product-software-driven, with technical operations concentrated in incident response coordination, reporting infrastructure, and exercises.

ENISA operates as a non-commercial public agency funded through the EU general budget; it does not sell products or charge fees, and pricing is not a go-to-market dimension. With 51-100 staff and a distributed mandate across all EU member states, its growth mechanism is regulatory mandate expansion rather than revenue capture. Recent mandate expansions under NIS2 (covering ~28,700 entities), the Cyber Resilience Act, and eIDAS2 have materially enlarged its operational surface since 2024.

Short descriptiontext

ENISA is the European Union Agency for Cybersecurity, headquartered in Athens, Greece. It serves EU member states, EU institutions, and approximately 28,700 NIS2 in-scope entities with free cybersecurity frameworks, certification schemes, exercises, and incident response coordination.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
51–100
akta.pro rankint
HeadquartersHeraklion, Greece
HQ citystring
Heraklion
HQ countrystring
Greece
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity agency, vulnerability database, cybersecurity certification, incident response coordination, cybersecurity exercises
Industry1 code
1Industrial Endpoint Protection (PLC/HMI/Engineering Workstation EDR)
CodeHDADAJADPrimaryYes
NAICS code3 codes
  • National Security928110
  • National Security and International Affairs928
  • Regulation and Administration of Communications, Electric, Gas, and Other Utilities92613
SIC code1 code
  • Services-Engineering, Accounting, Research, Management8700
Product category
Public Cybersecurity Agency Services
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

ENISA is the European Union Agency for Cybersecurity, operating digital platforms (European Vulnerability Database, Single Reporting Platform, NCAF 2.0 tool, CyberEducation Platform, CYBERHEAD), publishing technical guidance and reports, coordinating incident response networks (EU CSIRTs Network, EU-CyCLONe), managing EU cybersecurity certification schemes, and running exercises and training programs. All outputs are provided free of charge and funded through the EU budget via the Digital Europe Programme.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 5 consecutive victories for Team Europe in International Cybersecurity Challenge (2022-2026)
+3 more records
Product overview1 text field

ENISA (European Union Agency for Cybersecurity) operates as a platform of interconnected tools, reports, frameworks, certification schemes, exercises, and networks rather than a single unified product. The core portfolio includes: the European Vulnerability Database and Single Reporting Platform for vulnerability management and incident reporting; the National Capabilities Assessment Framework Tool for maturity assessment; the EU Cybersecurity Reserve (€36 million) for incident response support; and the EU Cybersecurity Certification Framework including EUCC and EUDI Wallet schemes. Supporting these are training and competition programs including Cyber Europe exercises, European and International Cybersecurity Challenges, the Cybersecurity Skills Framework, CYBERHEAD higher education database, and CyberEducation Platform. Operational coordination is delivered through CSIRTs Network and EU-CyCLONe crisis liaison network, complemented by sector-specific forums for telecom, eHealth, and energy security. The portfolio also includes technical guidance documents such as NIS2 Implementation Guidance, Handbook for Cyber Stress Tests, Security by Design Playbook, and Technical Advisory on Package Managers.

Product and service25 records
1European Vulnerability Database (EUVD)
CategoryVulnerability Management
Description

Provides aggregated, reliable, and actionable information on cybersecurity vulnerabilities affecting ICT products and services, including mitigation measures and exploitation status. Operated by ENISA under NIS2 mandate.

2National Capabilities Assessment Framework (NCAF) Tool 2.0
CategoryCapability Assessment
Description

Methodology and online tool supporting national authorities to assess and strengthen cybersecurity capabilities and evaluate the maturity of national cybersecurity frameworks across EU member states.

3Single Reporting Platform (SRP)
CategoryIncident Reporting Platform
Description

Centralized digital platform managed by ENISA for security incident reporting under the Cyber Resilience Act and other EU legal frameworks, providing a harmonized reporting interface.

4ENISA CyberEducation Platform
CategoryCybersecurity Education
Description

Central hub for cybersecurity educational resources tailored for primary and secondary schools in each Member State.

5CYBERHEAD - Cybersecurity Higher Education Database
CategoryCybersecurity Education Database
Description

Largest validated cybersecurity higher education database in EU and EFTA countries, providing reference for citizens seeking to upskill in cybersecurity and helping universities attract students.

6Cybersecurity Maturity Assessment Tool for SMEs
CategorySME Cybersecurity Tool
Description

Tailored assessment tool for small and medium-sized enterprises to evaluate cybersecurity maturity and prepare for the EU Cyber Resilience Act.

7ISAC-in-a-Box Toolkit
CategoryInformation Sharing
Description

Toolkit supporting the establishment and operation of sectoral Information Sharing and Analysis Centres (ISACs) across EU critical sectors.

8EU Cybersecurity Reserve
CategoryIncident Response Reserve
Description

€36 million reserve managed by ENISA to support responses to major cyber incidents across EU and associated third countries, funded through the Digital Europe Programme under the Cyber Solidarity Act.

9EU Cybersecurity Certification Framework
CategoryCybersecurity Certification
Description

Framework established under the EU Cybersecurity Act for certifying ICT products and services, including the published EUCC scheme and schemes under development for cloud, 5G, and digital identities.

10EU Digital Identity (EUDI) Wallet Certification Scheme
CategoryDigital Identity Certification
Description

Draft certification scheme for European Digital Identity Wallets under development by ENISA, with public consultation launched in 2026 and supported by a €1.6 million contribution agreement.

11Cyber Europe Exercise
CategoryCybersecurity Exercises
Description

Pan-European biennial cybersecurity exercise simulating large-scale cybersecurity incidents that escalate to EU-wide cyber crises, testing response coordination across EU Member States.

12European Cybersecurity Challenge (ECSC)
CategoryCybersecurity Competition
Description

Annual competition for young cyber talents across EU and EFTA countries, featuring technical challenges in web security, crypto puzzles, reverse engineering, forensics, and attack/defense scenarios.

13International Cybersecurity Challenge (ICC)
CategoryCybersecurity Competition
Description

Global cybersecurity competition where Team Europe competes against teams from around the world, testing advanced cybersecurity skills.

14European Cybersecurity Skills Framework (ECSF)
CategorySkills Framework
Description

Framework identifying and defining key cybersecurity roles and competencies needed in the field, helping organizations align training and recruitment with industry demands.

15BlueOLEx Exercise
CategoryExecutive Cyber Exercise
Description

Annual executive-level cyber exercise testing cooperation among cybersecurity crisis management executives and directors across EU Member States.

16CySOPex Exercise
CategoryCrisis Response Exercise
Description

Annual exercise for EU-CyCLONe officers testing standard operating procedures and information sharing processes for incident response.

17ENISA NIS360 Report
CategoryAnnual Cybersecurity Report
Description

Annual assessment report evaluating cybersecurity maturity and criticality of all sectors of high criticality under the NIS2 Directive, covering the entire ecosystem of assessed sectors.

18ENISA NIS Investments Report
CategoryAnnual Cybersecurity Report
Description

Annual report exploring how cybersecurity policy translates into practice across EU organizations and effects on investments, resources, and operations.

19NIS2 Technical Implementation Guidance
CategoryTechnical Guidance
Description

Technical guidance supporting implementation of NIS2 Directive for digital infrastructure, ICT service management and digital providers sectors.

20Handbook for Cyber Stress Tests
CategoryTechnical Guidance
Description

Guidance document for national or sectoral authorities overseeing cybersecurity and resilience of critical sectors under NIS2 Directive, providing a methodology for cyber stress tests.

21Security by Design Playbook
CategoryTechnical Guidance
Description

Playbook emphasizing integration of security by design and default across the entire product lifecycle, focusing on architectural foundations and operational integrity.

22ENISA Technical Advisory on Package Managers
CategoryTechnical Guidance
Description

Guidance document helping developers securely use third-party packages, outlining supply chain risks and secure practices.

23Cyber Hygiene in the Health Sector
CategorySectoral Guidance
Description

Guidance document providing practical measures for health entities to mitigate cybersecurity risks, safeguard sensitive data, and strengthen cyber resilience.

24ENISA Cyber Partnership Programme (CPP)
CategoryPublic-Private Partnership
Description

Programme enhancing information sharing between ENISA and the private sector on cybersecurity threats and situational awareness.

25ENISA Cybersecurity Exercise Methodology
CategoryExercise Methodology
Description

Updated framework providing organizations and governments with a structured approach for planning, executing, and evaluating cybersecurity exercises.

Scale indicator10 records

Each record includes

Type, Value, Description, Source

Partnership8 partners
Strategic tierMajorTypeStrategic or Co-development PartnerAnnounced on2026-06-17
Description

ENISA was invited by Anthropic to join Project Glasswing, giving the EU cybersecurity agency access to the Mythos AI model capable of identifying software vulnerabilities. A meeting was scheduled in San Francisco on June 18, 2026. However, following a U.S. export control directive, ENISA was informed it would no longer receive access to the Glasswing program.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-08
Description

ENISA collaborates with the European Cybersecurity Competence Centre on initiatives including the Woman International Cybersecurity Challenge (WICC) in Dublin and the 10th eHealth Security Conference co-organized with the Romanian National Cyber Security Directorate (DNSC).

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-11-20
Description

ENISA serves as the secretariat for the EU CSIRTs Network, a cooperative framework for Computer Security Incident Response Teams across EU member states and CERT-EU. The network facilitates information exchange, coordinated incident response, and development of trust between national CSIRTs. ENISA provides infrastructure, tools, and coordination support to enable effective cooperation on cross-border incidents.

4European Supervisory Authorities (ESAs)
Strategic tierMajorTypeStrategic or Co-development PartnerAnnounced on2024-06-05
Description

ENISA signed a Memorandum of Understanding with the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) to strengthen cooperation and information exchange, particularly regarding digital operational resilience under DORA.

enisa.europa.eu
5EU-CyCLONe (European Cyber Crisis Liaison Organisation Network)
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2022-10-17
Description

ENISA serves as the secretariat for EU-CyCLONe, formally established by NIS2 for supporting coordinated management of large-scale cybersecurity incidents and crises. ENISA provides support and tools to the network which is chaired by the Presidency of the Council of the EU. EU-CyCLONe cooperates with the European Commission during significant incidents affecting NIS2 entities.

enisa.europa.eu
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2021-10-19
Description

ENISA and Europol's EC3 have conducted annual workshops on CSIRT-Law Enforcement cooperation since 2011, celebrating the 10th anniversary in 2021. The partnership enables synergies between incident response teams and law enforcement communities across EU member states, facilitating joint operations and cooperation frameworks such as the EMOTET takedown.

7Association of European Distribution System Operators (E.DSO)
Strategic tierMajorTypeStrategic or Co-development Partner
Description

ENISA jointly organizes the annual Cybersecurity Forum with E.DSO, European Energy - Information Sharing & Analysis Centre (EE-ISAC), and European Network for Cyber Security (ENCS). The 9th edition scheduled for October 8, 2026 in Brussels focuses on grid cyber resilience and bridging regulation with innovation.

enisa.europa.eu
Strategic tierSupportingTypeStrategic or Co-development Partner
Description

Accenture and Ubitech have generously supported Team Europe activities including training bootcamps, qualifier events, and preparation activities for the International Cybersecurity Challenge. The companies provided specialized training and authored challenges during the selection process.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

UK's national cybersecurity authority responsible for incident response, technical guidance, and critical infrastructure protection, with a mandate, structure, and product portfolio (vulnerability disclosure, certification, exercises) closely aligned to ENISA's.

TypeOthers
Description

Global association of incident response and security teams coordinating CSIRT cooperation and standards; ENISA's CSIRTs Network operates as a complementary regional coordination layer in the same ecosystem.

3BSI (Bundesamt für Sicherheit in der Informationstechnik)
TypeDirect peer
Description

Germany's federal cybersecurity authority, responsible for cybersecurity standards, certification, and incident response with a comparable mandate to ENISA at the national level, including the IT-Grundschutz certification framework that parallels ENISA's EUCC.

TypeDirect peer
Description

France's national cybersecurity agency, performing cybersecurity regulation, certification (CSPN), incident response coordination, and technical guidance — operating as ENISA's national-level counterpart in the largest EU member state.

TypeDirect peer
Description

US federal agency performing the closest functional analog of ENISA's role — national cybersecurity coordination, vulnerability management, critical infrastructure protection, and incident response — making it the most directly comparable national cybersecurity agency peer.

TypeRegional player
Description

NATO-affiliated cyber defense center in Tallinn focused on cybersecurity research, training, and exercises, with overlapping scope on cross-border incident coordination but distinct NATO defense-orientation versus ENISA's EU civilian focus.

TypeDirect peer
Description

EU body managing cybersecurity competence and innovation funding under the Digital Europe Programme; ENISA and ECCC jointly organize the WICC and eHealth Security Conference, with overlapping mandates in skills development and community building.

TypeOthers
Description

Operates the CVE Program and ATT&CK framework; ENISA's CVE Root designation places it in a co-stewardship relationship with MITRE for global vulnerability disclosure infrastructure, making MITRE a direct functional peer for the EUVD product line.

TypeDirect peer
Description

US agency producing cybersecurity frameworks and standards (NIST CSF, NICE) that serve as functional parallels to ENISA's NIS2 implementation guidance, ECSF skills framework, and EU certification schemes.

TypeOthers
Description

EU agency within Europol focused on cybercrime investigations, partnering with ENISA on CSIRT-Law Enforcement cooperation since 2011 and on joint operations like EMOTET takedown, with an adjacent but complementary mandate to ENISA's.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers4 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment3 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile2 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature4 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment24 records

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

ENISA

Public Cybersecurity Agency Servicesenisa.europa.eu

ENISA is the European Union Agency for Cybersecurity, headquartered in Athens, Greece. It serves EU member states, EU institutions, and approximately 28,700 NIS2 in-scope entities with free cybersecurity frameworks, certification schemes, exercises, and incident response coordination.

What ENISA does

ENISA is the European Union Agency for Cybersecurity, established in 2004 and headquartered in Chalandri, Athens, Greece. It operates as a permanent EU agency under Regulation 2019/881 (Cybersecurity Act), serving the 27 EU member states, EU institutions, and the private-sector entities that operate essential and important services within the European single market. Its functional remit covers EU-level cybersecurity coordination, capacity building, certification, vulnerability management, and operational support to member states during cross-border incidents.

Its product and service portfolio spans multiple categories: the European Cybersecurity Skills Framework and associated training programs; NIS2 implementation guidance and the NIS360 annual report; the Cyber Resilience Act Single Reporting Platform; vulnerability management (including its November 2025 designation as a CVE Program Root); certification schemes (including the new EU Digital Identity Wallet certification under eIDAS2); operational tools such as the €36M EU Cybersecurity Reserve; pan-European exercises (Cyber Europe); threat-intelligence reporting (ETL, NIS360); and sectoral initiatives spanning energy, health, transport, digital infrastructure, and (as of 2025) the space sector. The platform architecture is fundamentally policy-and-framework-driven rather than product-software-driven, with technical operations concentrated in incident response coordination, reporting infrastructure, and exercises.

ENISA operates as a non-commercial public agency funded through the EU general budget; it does not sell products or charge fees, and pricing is not a go-to-market dimension. With 51-100 staff and a distributed mandate across all EU member states, its growth mechanism is regulatory mandate expansion rather than revenue capture. Recent mandate expansions under NIS2 (covering ~28,700 entities), the Cyber Resilience Act, and eIDAS2 have materially enlarged its operational surface since 2024.

ENISA firmographics

Firmographics
Name
ENISA
Legal name
European Union Agency for Cybersecurity
Website
https://enisa.europa.eu
Company type
Public
Founded year
2004
Operating status
Operating
Headcount range
51–100 employees
Short description
ENISA is the European Union Agency for Cybersecurity, headquartered in Athens, Greece. It serves EU member states, EU institutions, and approximately 28,700 NIS2 in-scope entities with free cybersecurity frameworks, certification schemes, exercises, and incident response coordination.
Ownership category
akta.pro rank

ENISA industry classification

Industry
Product category
Public Cybersecurity Agency Services
NAICS
National Security (928110), National Security and International Affairs (928), Regulation and Administration of Communications, Electric, Gas, and Other Utilities (92613)
SIC
Services-Engineering, Accounting, Research, Management (8700)
akta.pro primary industry
Industrial Endpoint Protection (PLC/HMI/Engineering Workstation EDR) (HDADAJAD)

Keywords

  • Cybersecurity agency
  • Vulnerability database
  • Cybersecurity certification
  • Incident response coordination
  • Cybersecurity exercises

Where ENISA is headquartered

Location

Headquarters

HQ city
Heraklion
HQ country
Greece
HQ region
Europe

Offices1 record

Markets served

ENISA business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure

Distribution channels3 records

Marketing channels7 records

ENISA product offering

Product offering

Core offering

ENISA is the European Union Agency for Cybersecurity, operating digital platforms (European Vulnerability Database, Single Reporting Platform, NCAF 2.0 tool, CyberEducation Platform, CYBERHEAD), publishing technical guidance and reports, coordinating incident response networks (EU CSIRTs Network, EU-CyCLONe), managing EU cybersecurity certification schemes, and running exercises and training programs. All outputs are provided free of charge and funded through the EU budget via the Digital Europe Programme.

Product overview

ENISA (European Union Agency for Cybersecurity) operates as a platform of interconnected tools, reports, frameworks, certification schemes, exercises, and networks rather than a single unified product. The core portfolio includes: the European Vulnerability Database and Single Reporting Platform for vulnerability management and incident reporting; the National Capabilities Assessment Framework Tool for maturity assessment; the EU Cybersecurity Reserve (€36 million) for incident response support; and the EU Cybersecurity Certification Framework including EUCC and EUDI Wallet schemes. Supporting these are training and competition programs including Cyber Europe exercises, European and International Cybersecurity Challenges, the Cybersecurity Skills Framework, CYBERHEAD higher education database, and CyberEducation Platform. Operational coordination is delivered through CSIRTs Network and EU-CyCLONe crisis liaison network, complemented by sector-specific forums for telecom, eHealth, and energy security. The portfolio also includes technical guidance documents such as NIS2 Implementation Guidance, Handbook for Cyber Stress Tests, Security by Design Playbook, and Technical Advisory on Package Managers.

Differentiator

Problem solved

Functional benefit

Products and services

  • European Vulnerability Database (EUVD) Provides aggregated, reliable, and actionable information on cybersecurity vulnerabilities affecting ICT products and services, including mitigation measures and exploitation status. Operated by ENISA under NIS2 mandate.
  • National Capabilities Assessment Framework (NCAF) Tool 2.0 Methodology and online tool supporting national authorities to assess and strengthen cybersecurity capabilities and evaluate the maturity of national cybersecurity frameworks across EU member states.
  • Single Reporting Platform (SRP) Centralized digital platform managed by ENISA for security incident reporting under the Cyber Resilience Act and other EU legal frameworks, providing a harmonized reporting interface.
  • ENISA CyberEducation Platform Central hub for cybersecurity educational resources tailored for primary and secondary schools in each Member State.
  • CYBERHEAD - Cybersecurity Higher Education Database Largest validated cybersecurity higher education database in EU and EFTA countries, providing reference for citizens seeking to upskill in cybersecurity and helping universities attract students.
  • Cybersecurity Maturity Assessment Tool for SMEs Tailored assessment tool for small and medium-sized enterprises to evaluate cybersecurity maturity and prepare for the EU Cyber Resilience Act.
  • ISAC-in-a-Box Toolkit Toolkit supporting the establishment and operation of sectoral Information Sharing and Analysis Centres (ISACs) across EU critical sectors.
  • EU Cybersecurity Reserve €36 million reserve managed by ENISA to support responses to major cyber incidents across EU and associated third countries, funded through the Digital Europe Programme under the Cyber Solidarity Act.
  • EU Cybersecurity Certification Framework Framework established under the EU Cybersecurity Act for certifying ICT products and services, including the published EUCC scheme and schemes under development for cloud, 5G, and digital identities.
  • EU Digital Identity (EUDI) Wallet Certification Scheme Draft certification scheme for European Digital Identity Wallets under development by ENISA, with public consultation launched in 2026 and supported by a €1.6 million contribution agreement.
  • Cyber Europe Exercise Pan-European biennial cybersecurity exercise simulating large-scale cybersecurity incidents that escalate to EU-wide cyber crises, testing response coordination across EU Member States.
  • European Cybersecurity Challenge (ECSC) Annual competition for young cyber talents across EU and EFTA countries, featuring technical challenges in web security, crypto puzzles, reverse engineering, forensics, and attack/defense scenarios.
  • International Cybersecurity Challenge (ICC) Global cybersecurity competition where Team Europe competes against teams from around the world, testing advanced cybersecurity skills.
  • European Cybersecurity Skills Framework (ECSF) Framework identifying and defining key cybersecurity roles and competencies needed in the field, helping organizations align training and recruitment with industry demands.
  • BlueOLEx Exercise Annual executive-level cyber exercise testing cooperation among cybersecurity crisis management executives and directors across EU Member States.
  • CySOPex Exercise Annual exercise for EU-CyCLONe officers testing standard operating procedures and information sharing processes for incident response.
  • ENISA NIS360 Report Annual assessment report evaluating cybersecurity maturity and criticality of all sectors of high criticality under the NIS2 Directive, covering the entire ecosystem of assessed sectors.
  • ENISA NIS Investments Report Annual report exploring how cybersecurity policy translates into practice across EU organizations and effects on investments, resources, and operations.
  • NIS2 Technical Implementation Guidance Technical guidance supporting implementation of NIS2 Directive for digital infrastructure, ICT service management and digital providers sectors.
  • Handbook for Cyber Stress Tests Guidance document for national or sectoral authorities overseeing cybersecurity and resilience of critical sectors under NIS2 Directive, providing a methodology for cyber stress tests.
  • Security by Design Playbook Playbook emphasizing integration of security by design and default across the entire product lifecycle, focusing on architectural foundations and operational integrity.
  • ENISA Technical Advisory on Package Managers Guidance document helping developers securely use third-party packages, outlining supply chain risks and secure practices.
  • Cyber Hygiene in the Health Sector Guidance document providing practical measures for health entities to mitigate cybersecurity risks, safeguard sensitive data, and strengthen cyber resilience.
  • ENISA Cyber Partnership Programme (CPP) Programme enhancing information sharing between ENISA and the private sector on cybersecurity threats and situational awareness.
  • ENISA Cybersecurity Exercise Methodology Updated framework providing organizations and governments with a structured approach for planning, executing, and evaluating cybersecurity exercises.

Quantifiable outcome

  • 5 consecutive victories for Team Europe in International Cybersecurity Challenge (2022-2026)
  • +3 more outcomes

Companies that use ENISA

Customer profile

Named customers4 records

Segments3 records

Ideal customer profiles2 records

ENISA technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature4 records

ENISA partnerships and signals

Strategic signal

Partnerships

Eight partnerships are on record, tiered major, core and supporting.

  • Anthropic (Project Glasswing)majorStrategic or Co-development Partner · 17 June 2026ENISA was invited by Anthropic to join Project Glasswing, giving the EU cybersecurity agency access to the Mythos AI model capable of identifying software vulnerabilities. A meeting was scheduled in San Francisco on June 18, 2026. However, following a U.S. export control directive, ENISA was informed it would no longer receive access to the Glasswing program.
  • European Cybersecurity Competence Centre (ECCC)coreStrategic or Co-development Partner · 8 June 2026ENISA collaborates with the European Cybersecurity Competence Centre on initiatives including the Woman International Cybersecurity Challenge (WICC) in Dublin and the 10th eHealth Security Conference co-organized with the Romanian National Cyber Security Directorate (DNSC).
  • EU CSIRTs NetworkcoreStrategic or Co-development Partner · 20 November 2025ENISA serves as the secretariat for the EU CSIRTs Network, a cooperative framework for Computer Security Incident Response Teams across EU member states and CERT-EU. The network facilitates information exchange, coordinated incident response, and development of trust between national CSIRTs. ENISA provides infrastructure, tools, and coordination support to enable effective cooperation on cross-border incidents.
  • European Supervisory Authorities (ESAs)majorStrategic or Co-development Partner · 5 June 2024ENISA signed a Memorandum of Understanding with the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) to strengthen cooperation and information exchange, particularly regarding digital operational resilience under DORA.
  • EU-CyCLONe (European Cyber Crisis Liaison Organisation Network)coreStrategic or Co-development Partner · 17 October 2022ENISA serves as the secretariat for EU-CyCLONe, formally established by NIS2 for supporting coordinated management of large-scale cybersecurity incidents and crises. ENISA provides support and tools to the network which is chaired by the Presidency of the Council of the EU. EU-CyCLONe cooperates with the European Commission during significant incidents affecting NIS2 entities.
  • Europol European Cybercrime Centre (EC3)coreStrategic or Co-development Partner · 19 October 2021ENISA and Europol's EC3 have conducted annual workshops on CSIRT-Law Enforcement cooperation since 2011, celebrating the 10th anniversary in 2021. The partnership enables synergies between incident response teams and law enforcement communities across EU member states, facilitating joint operations and cooperation frameworks such as the EMOTET takedown.
  • Association of European Distribution System Operators (E.DSO)majorStrategic or Co-development PartnerENISA jointly organizes the annual Cybersecurity Forum with E.DSO, European Energy - Information Sharing & Analysis Centre (EE-ISAC), and European Network for Cyber Security (ENCS). The 9th edition scheduled for October 8, 2026 in Brussels focuses on grid cyber resilience and bridging regulation with innovation.
  • Team Europe Supporters (Accenture, Ubitech)supportingStrategic or Co-development PartnerAccenture and Ubitech have generously supported Team Europe activities including training bootcamps, qualifier events, and preparation activities for the International Cybersecurity Challenge. The companies provided specialized training and authored challenges during the selection process.

Scale indicators10 records

Recent moves6 records

Expansion highlights6 records

ENISA competitors and assessment

Company assessment

Direct peers

  • NCSC UK (National Cyber Security Centre): UK's national cybersecurity authority responsible for incident response, technical guidance, and critical infrastructure protection, with a mandate, structure, and product portfolio (vulnerability disclosure, certification, exercises) closely aligned to ENISA's.
  • BSI (Bundesamt für Sicherheit in der Informationstechnik): Germany's federal cybersecurity authority, responsible for cybersecurity standards, certification, and incident response with a comparable mandate to ENISA at the national level, including the IT-Grundschutz certification framework that parallels ENISA's EUCC.
  • ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information): France's national cybersecurity agency, performing cybersecurity regulation, certification (CSPN), incident response coordination, and technical guidance — operating as ENISA's national-level counterpart in the largest EU member state.
  • CISA (Cybersecurity and Infrastructure Security Agency): US federal agency performing the closest functional analog of ENISA's role — national cybersecurity coordination, vulnerability management, critical infrastructure protection, and incident response — making it the most directly comparable national cybersecurity agency peer.
  • European Cybersecurity Competence Centre (ECCC): EU body managing cybersecurity competence and innovation funding under the Digital Europe Programme; ENISA and ECCC jointly organize the WICC and eHealth Security Conference, with overlapping mandates in skills development and community building.
  • NIST (National Institute of Standards and Technology): US agency producing cybersecurity frameworks and standards (NIST CSF, NICE) that serve as functional parallels to ENISA's NIS2 implementation guidance, ECSF skills framework, and EU certification schemes.

Others

  • FIRST (Forum of Incident Response and Security Teams): Global association of incident response and security teams coordinating CSIRT cooperation and standards; ENISA's CSIRTs Network operates as a complementary regional coordination layer in the same ecosystem.
  • MITRE Corporation: Operates the CVE Program and ATT&CK framework; ENISA's CVE Root designation places it in a co-stewardship relationship with MITRE for global vulnerability disclosure infrastructure, making MITRE a direct functional peer for the EUVD product line.
  • Europol EC3 (European Cybercrime Centre): EU agency within Europol focused on cybercrime investigations, partnering with ENISA on CSIRT-Law Enforcement cooperation since 2011 and on joint operations like EMOTET takedown, with an adjacent but complementary mandate to ENISA's.

Regional players

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights7 records

Customer concentration

ENISA social profiles

Digital presence

ENISA financial estimates

Financial estimate

Revenue estimate

Valuation estimate

ENISA leadership team

Management profile

Number of profiles

Profiles2 records

ENISA funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

ENISA M&A and investment

M&A and investment

M&A

Investments24 records

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about ENISA

What does ENISA do?

ENISA is the European Union Agency for Cybersecurity, operating digital platforms (European Vulnerability Database, Single Reporting Platform, NCAF 2.0 tool, CyberEducation Platform, CYBERHEAD), publishing technical guidance and reports, coordinating incident response networks (EU CSIRTs Network, EU-CyCLONe), managing EU cybersecurity certification schemes, and running exercises and training programs. All outputs are provided free of charge and funded through the EU budget via the Digital Europe Programme.

Is ENISA a public or private company?

ENISA is a public company. It is classified as state government owned and is currently operating.

When was ENISA founded?

ENISA was founded in 2004. It employs 51 to 100 people.

Where is ENISA based?

ENISA is headquartered in Heraklion, Greece, in the Europe region.

Who are ENISA's main competitors?

Direct peers on record are NCSC UK (National Cyber Security Centre), BSI (Bundesamt für Sicherheit in der Informationstechnik), ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), CISA (Cybersecurity and Infrastructure Security Agency), European Cybersecurity Competence Centre (ECCC) and NIST (National Institute of Standards and Technology). Others are FIRST (Forum of Incident Response and Security Teams), MITRE Corporation and Europol EC3 (European Cybercrime Centre). NATO CCDCOE (Cooperative Cyber Defence Centre of Excellence) is listed as a regional player.

Does ENISA have an API?

No public API is recorded for ENISA.

What industry is ENISA in?

ENISA's product category is Public Cybersecurity Agency Services. Its primary akta.pro industry code is HDADAJAD, Industrial Endpoint Protection (PLC/HMI/Engineering Workstation EDR). Its NAICS code is 928110 and its SIC code is 8700.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
ET Edge InsightsENISA’s Hans de Vries on Cyber Resilience and TrustENISA's Hans de Vries argues cyber resilience is essential for continuity and trust, citing the NIS2 Directive as a key step. He warns that AI shortens vulnerability exploitation from months to minutes, challenging traditional patching. He advises embedding resilience by design and adapting to evolving threats.Help Net SecurityEurope’s technology backbone is becoming a cyber targetENISA's Threat Landscape 2026 analysis of 8,257 EU incidents from 2025 shows DDoS attacks at 51.3% and public administration as the most targeted sector at 31.8%. Phishing led social engineering at 77.8%, and AI tools are increasingly used to accelerate attacks.Splash247China-linked hackers step up attacks on European shippingENISA warned that China-linked hackers are mounting sustained cyberespionage campaigns against European maritime organisations, with Mustang Panda targeting at least seven EU member states. Transport accounted for 8% of EU cyber events, and maritime incidents rose 103% in 2025. The warning comes as ship connectivity accelerates, with new vulnerabilities found in most shipboard systems.Trending TopicsEU gegen Cyber-Angriffe unzureichend geschützt - SonderberichtThe European Court of Auditors' special report finds EU cyber security cooperation only partially effective, citing limited information exchange and reporting gaps. Member states reported only 14 cross-border incidents in 2025, while ENISA identified 322 such attacks, and the EU warning system remains non-operational.AD HOC NEWSCyber Resilience Act: EU zwingt Hersteller zu 24-Stunden-MeldepflichtThe EU's Cyber Resilience Act now requires manufacturers to report exploited vulnerabilities within 24 hours to CSIRT and ENISA, with full reports within 72 hours and a 14-day closure report. Fines can reach 15 million euros or 2.5% of global annual revenue, and core CRA requirements take effect on 11 December 2027.AiThorityAISLE Partners with ENISA to Help Secure the Infrastructure Behind Europe’s Cyber Resilience ActAISLE partnered with ENISA to secure the EU's Cyber Resilience Act Single Reporting Platform, with AI-based secure code review completed ahead of the first reporting deadline of 11 September 2026. The platform, operated by ENISA, is the entry point for manufacturers to report actively exploited vulnerabilities and severe incidents. AISLE's full loop process will remain in place for continuous support.Techzine EuropeEU cyber watchdog: Make incident response within minutes a priorityENISA warns that cyberattacks now progress from compromise to exploitation within 10 minutes, driven by automated systems. It recommends reducing mean time to detect to under 10 minutes and mean time to response, with human intervention within 24 hours. The agency also calls for European AI systems to support cybersecurity sovereignty.CybernewsEU Cyber Resilience Act sets 24-hour breach reporting rulesThe EU Commission announced new breach reporting rules under the Cyber Resilience Act, requiring manufacturers to notify ENISA within 24 hours of exploited vulnerabilities or severe incidents. Full notification must follow within 72 hours, and a final report within 14 days of patching, with full requirements taking effect in December 2027.Help Net SecurityENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilitiesENISA launched the Cyber Resilience Act's Single Reporting Platform on 11 September 2026, the day reporting obligations began for manufacturers. The platform requires early warning within 24 hours, a 72-hour notification, and a final report within 14 days, with CSIRTs coordinating submissions. API functionality is planned for a future phase.IndustrialcyberENISA launches Single Reporting Platform as EU Cyber Resilience Act vulnerability reporting obligations take effectENISA deployed the initial operating capability of the Single Reporting Platform to help manufacturers and open-source software stewards meet Cyber Resilience Act reporting obligations for actively exploited vulnerabilities and severe incidents. The platform enables single reporting to all relevant authorities, with CSIRTs disseminating information to other Member States. Reporting obligations take effect Sept. 11, 2026, and main cybersecurity requirements from Dec. 11, 2027.