Report on the Еvaluation of the EU Agency for Network and Information Security (ENISA)


The Commission published a Report to the European Parliament and the Council on the evaluation of the European Union Agency for Network and Information Security (ENISA).

The European Union Agency for Network and Information Security (ENISA) is a centre of expertise for cyber security in Europe. ENISA’s activities are focused on three key areas:

  • Recommendations
  • Activities that support policy making and implementation
  • ‘Hands On’ work, where ENISA collaborates directly with operational teams throughout the EU

ENISA was originally established in 2004 and had its mandate is renewed periodically. The current ENISA mandate is set out in Regulation EU No. 526/20131 (the 'ENISA Regulation') and is due to expire on 19 June 2020.

The assessment was based on evaluation of the effectiveness, efficiency, coherence, relevance and EU added value of the Agency, having regard to its performance, governance, internal organisational structure and working practices.

The main findings of the report indicate the Agency’s accomplishments achieved in the light of several challenges such as lack of resources and constant evolvement in the cybersecurity threats. It is concluded that the current mandate does not equip ENISA with the necessary tools to face the current and future cybersecurity challenges.

Continue to Commission’s report summary and recommendations provided to the current and new ENISA mandates.
Applied Research