NIS222 Aug 2026
ENISA published procurement guidelines to help hospitals and healthcare providers build cybersecurity objectives into every phase of their procurement life cycle. The guidelines set cybersecurity requirements, specify information suppliers must provide, and are aligned with the NIS2 Directive, the medical device regulations, the GDPR and the European Health Data Space regulation.
What to do: If you are a hospital or healthcare provider, or supply ICT or medical devices to one, consider using the guidelines' requirements in tenders and supplier contracts.
Legal status: EU guidance · Jurisdiction: EU
Official source: ENISA ↗