EU ENISA Issues New Hospital Cybersecurity Procurement Guidelines Under NIS2
The European Union Agency for Cybersecurity (ENISA) has published new guidelines aimed at hospitals and other health service providers to embed cybersecurity requirements throughout the procurement lifecycle. The guidance highlights the growing risk to the healthcare sector, which ENISA’s 2024 Threat Landscape reports accounts for 8 % of ransomware incidents, while only 27 % of organisations have dedicated ransomware‑defence programmes and 40 % lack staff awareness training.
Separately, Italy’s National Cybersecurity Agency (ACN) released an update to its frequently‑asked‑questions on the NIS2 Directive on 23 July 2026, adding three new clarifications (FAQ ODA 10‑12). The FAQ stresses that board members of essential and important entities must approve cybersecurity risk‑management measures, supervise their implementation and participate in specialised training, in line with article 20 of the EU NIS2 Directive and Italy’s implementing decree (d.lgs. 138/2024).
Entities: Agenzia per la Cybersicurezza Nazionale (ACN) · European Union Agency for Cybersecurity (ENISA) · Healthcare sector · Italian Government · NIS2 Directive
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] NIS2 requires board members of essential and important entities to approve, supervise, and train on cybersecurity risk‑management measures. (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] Only 27 % of healthcare organisations have a dedicated ransomware‑defence programme and 40 % lack staff security‑awareness training. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] ENISA released new guidelines for cybersecurity procurement in hospitals and health service providers. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] ENISA’s Threat Landscape 2024 reports the healthcare sector accounts for 8 % of ransomware incidents. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] The updated FAQ adds three new clarifications (FAQ ODA 10, ODA 11, ODA 12). (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] The Italian National Cybersecurity Agency (ACN) updated its FAQ on NIS2 responsibilities on 23 July 2026. (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] Italy’s implementing decree (d.lgs. 138/2024) incorporates NIS2 governance responsibilities into national law. (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] The guidelines emphasize integrating cybersecurity throughout the supply chain and procurement lifecycle. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)