The European Union Agency for Cybersecurity (ENISA) has signed a Contribution Agreement with the European Commission worth €6 million to support the health sector in building robust cybersecurity defenses, and published updated procurement guidelines for hospitals and healthcare providers as one of the first deliverables under the EU Action Plan for the cybersecurity of hospitals and healthcare providers. The agreement, set for three years, will fund the development of a comprehensive service catalogue for a proposed European Cybersecurity Support Centre, which aims to provide tailored guidance, tools, and services to healthcare providers across Europe. The service catalogue includes actions clustered under preparedness, detection, response, and governance.

The updated procurement guidelines, published on 22 July 2026, were prepared by ENISA with support from the NIS Cooperation Group, the EU Health ISAC, and the European Commission. They cover all phases of the procurement life cycle, set out cybersecurity requirements for suppliers, and include a practical checklist of cybersecurity measures linked to specific threats for different procurement types. The guidelines align with relevant EU regulatory frameworks and are intended for a wide range of stakeholders, from senior technical professionals to IT teams.

The Health Action Plan, launched in 2025 by the European Commission, tasked ENISA with a series of actions to enhance protection and resilience of the health sector. The new procurement guidelines and cybersecurity for medical devices will be among topics at the 11th ENISA eHealth Security Conference in Nicosia, Cyprus on 7 October 2026.

hospitals and healthcare providers will benefit from clearer cybersecurity procurement requirements, potentially reducing their vulnerability to cyber threats but also facing administrative and cost burdens to implement the guidelines. Medical device and IT suppliers will need to meet new cybersecurity requirements, which could increase compliance costs but also create opportunities for cybersecurity-focused products. EU regulatory bodies gain a tool to harmonize cybersecurity standards across member states, while national authorities receive a framework to support local healthcare entities. The €6 million agreement, funded by EU taxpayers, represents a moderate investment aimed at strengthening cybersecurity in a critical sector.

← Atlas › News › Health & Lifestyle