Updated 8 Aug 2026
Own this investor? Claim the page to unlock editing and verified-owner badge.

The European Union Agency for Cybersecurity, an EU decentralised agency based in Athens that drives cybersecurity policy, certification, and resilience across the Union.

Funder analysis

Web-researched analysis· 8 Aug 2026· v7

Investment thesis

ENISA is the European Union’s dedicated agency for achieving a high common level of cybersecurity across Europe, established in 2004 and permanently reinforced by the EU Cybersecurity Act (Regulation 2019/881) [1]. It does not provide direct venture capital or equity funding to startups; instead, it functions as the EU’s expert centre for policy, certification, and capacity building [2]. Its strategic agenda is to boost trust in digital products, strengthen the resilience of critical infrastructure, and keep EU citizens digitally safe through knowledge sharing and awareness raising [3].

  • ICT Certification Schemes: ENISA develops and manages cybersecurity certification schemes for ICT products, services and processes under the Cybersecurity Act, creating a trusted market for compliant vendors [1].
  • Critical Sector Resilience: The agency supports the implementation of the NIS2 Directive and provides maturity assessments and procurement guidelines for critical sectors like healthcare and energy [3].
  • SME Cyber Resilience: ENISA offers dedicated frameworks, such as the SME Cyber Resilience Maturity Assessment Model and the SecureSME tool, to help micro, small and medium-sized enterprises evaluate and strengthen their cyber posture [3][4].
  • Workforce Development: Through the European Cybersecurity Skills Framework (ECSF) and skills platforms, ENISA addresses the EU-wide talent shortage by standardising competencies and supporting education [3].
Credibility: Mandated by Regulation (EU) 2019/881, managed by Executive Director Juhan Lepassaar, and operating with a budget of nearly €17 million and 109 statutory staff members [1].

Value add

ENISA provides foundational credibility, regulatory alignment, and operational frameworks that are essential for operating within the EU digital single market. While it does not offer direct equity or grants, its certification schemes and maturity models are increasingly becoming de facto requirements for public procurement and critical sector compliance. Access to ENISA’s expert networks, working groups, and publications allows companies to shape emerging regulations and demonstrate trustworthiness to enterprise and government clients.

Fit verdict: ENISA is a critical regulatory and standard-setting body for cybersecurity vendors, especially those targeting public sector or critical infrastructure clients in the EU. It is not a source of direct funding, but engagement with its certification schemes and guidelines is often a prerequisite for market access.

Founder diligence script:

  • Does my product or service fall under an active or upcoming ENISA certification scheme (e.g., EUMSS, cloud, IoT)?
  • How can I use the SME Cyber Resilience Maturity Assessment Model to benchmark my security posture for sales cycles?
  • Am I eligible to participate in ENISA’s ad hoc working groups or stakeholder consultations to influence upcoming regulations?
  • Does my target customer base (e.g., healthcare, energy) require compliance with ENISA’s procurement guidelines under NIS2?
  • How can I leverage ENISA’s publications and playbooks to strengthen my own security documentation and vendor risk assessments?

Portfolio focus

  • Cybersecurity Certification: ENISA’s work clusters around developing and implementing certification schemes for ICT products, services, and processes under the Cybersecurity Act [1].
  • Critical Infrastructure Protection: Significant effort is directed towards the NIS2 Directive, including maturity assessments and procurement guidelines for sectors like healthcare and energy [3].
  • SME Cyber Resilience: ENISA has produced dedicated tools and models, such as the SME Cyber Resilience Maturity Assessment Model and the SecureSME tool, to support smaller businesses [3][4].
  • Workforce Development: The agency focuses on the European Cybersecurity Skills Framework (ECSF) and skills platforms to address the EU-wide talent gap [3].
  • Threat Intelligence & Vulnerability Management: ENISA manages the European Vulnerability Database and scales its role in the CVE Program, supporting vulnerability disclosure and mitigation [3].

Sources

  1. en.wikipedia.org
  2. european-union.europa.eu
  3. enisa.europa.eu
2 more sources
  1. digikoalice.cz
  2. ctu.gov.cz

Co-investors

No co-investors named in this fund's research yet.

Signals & partners focus areas · graph signals · limited partners

Overview

cybersecurityICT trustworthinesscritical infrastructure resilienceSME cyber resilienceworkforce developmentAI securityIoT securitycloud computing