The European Union Agency for Cybersecurity (ENISA) has published the ENISA NIS360 2026 report assessing the cybersecurity maturity and criticality of sectors of high criticality under the EU NIS 2 Directive (NIS2). The report finds that cybersecurity maturity across EU critical sectors has steadily improved, with banking, electricity and telecommunications remaining the most mature and critical sectors, while trust services, aviation and financial market infrastructures (FMI)s have moved into the high-maturity band. It attributes this progress to cybersecurity legislation, including the NIS2 and the Digital Operational Resilience Act (DORA), as well as increased political attention, stronger information sharing and collaboration and improved operational preparedness. However, maturity remains uneven across and within sectors, with health, railway, maritime, ICT service management, public administrations, space, drinking water and wastewater remaining in the NIS360 risk zone, where criticality exceeds cybersecurity maturity. The report also identifies artificial intelligence (AI), supply chain and third-party risks and geopolitical volatility as key factors shaping the cybersecurity maturity and resilience of high-criticality sectors.