This ENISA maturity assessment model helps SMEs evaluate and strengthen their cyber resilience and product security practices in line with the Cyber Resilience Act (CRA). Primarily aimed at manufacturers of products with digital elements, the model provides a structured approach for assessing cybersecurity maturity and identifying areas for improvement. It can also support integrators, service providers and other organisations involved in the digital product lifecycle. An accompanying Excel-based assessment tool enables practical application of the model.
Repositories
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Cloud Security
Google Cloud Cybersecurity Certificate
- Published date:
- Author: Google Cloud
A beginner-level professional certificate providing practical training in securing Google Cloud environments. The five-course programme covers cybersecurity and cloud security fundamentals, cloud risk management and compliance frameworks, identity and access management, threat identification and protection, security monitoring, incident response and recovery. Interactive labs and a capstone activity allow learners to apply their knowledge to realistic cloud security scenarios and prepare for entry-level Cloud Security Analyst roles.
- DevSecOps / DevPrivSecOps
ENISA Secure by Design and Default Playbook for SMEs
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA Secure by Design and Default Playbook provides practical guidance for SMEs on integrating cybersecurity into the entire product development lifecycle. It presents clear principles, actionable recommendations, and repeatable practices for implementing secure-by-design and secure-by-default approaches throughout engineering, development, testing, release, and maintenance processes. The playbook helps organisations strengthen product security, reduce vulnerabilities, and support compliance with the Cyber Resilience Act (CRA).
- Application Security
Secure-by-Design System Development with UML
- Published date:
- Author: MERIT Project Consortium
This self-paced MOOC introduces system security from a design-oriented perspective, helping learners integrate security requirements during the early stages of system development. The course covers secure system architecture, security-focused requirements engineering, UML-based modelling, vulnerability identification, and secure-by-design methodologies. Through video lectures, practical modelling exercises, and assignments, participants learn how to build more robust and resilient systems before implementation begins.
- Network Security
Foundations of Zero Trust Cybersecurity
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The Zero Trust Cybersecurity Foundation course introduces the principles of Zero Trust (ZT) and Zero Trust Architecture (ZTA), providing learners with the knowledge required to design and implement modern security architectures based on the “never trust, always verify” approach. Following the guidance of NIST SP 800-207, the course covers Zero Trust concepts, implementation strategies, architecture options, planning considerations, and practical use cases to help organisations strengthen their cyber resilience and reduce the risk of data breaches and cyberattacks.
- Risk Management
ENISA Cybersecurity Maturity Assessment for SMEs
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA Cybersecurity Maturity Assessment for SMEs is an online self-assessment tool that helps small and medium-sized enterprises evaluate their cybersecurity maturity across people, technology, and organisational processes. Based on the assessment results, the tool provides a tailored action plan with practical recommendations to improve cyber resilience, strengthen security practices, and support the management of cybersecurity risks.
- AI Security
EU Action Plan on Cybersecurity and Artificial Intelligence
- Published date:
- Author: European Commission
The EU Action Plan on Cybersecurity and Artificial Intelligence outlines the European Commission’s strategy for promoting the safe and responsible use of AI while strengthening Europe’s cybersecurity and resilience. The Action Plan focuses on secure AI deployment, AI-assisted cyber defence, resilience of critical infrastructure, implementation of the AI Act, NIS2 Directive, and Cyber Resilience Act, and the development of European AI capabilities for cybersecurity through research, innovation, and secure testing environments.
- Endpoint Security
European Union Vulnerability Database (EUVD)
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The European Union Vulnerability Database (EUVD) is the official EU platform for collecting and publishing information on publicly disclosed cybersecurity vulnerabilities. Managed by ENISA under the NIS2 Directive, the database provides information on security flaws affecting software and hardware products, assigns EUVD identifiers, references CVE entries where applicable, and supports vulnerability management, risk assessment, and timely remediation for organisations across Europe.
- Introductory Courses to Cybersecurity
The Fundamentals of Cybersecurity (NERO)
- Published date:
- Author: NERO project
The Fundamentals of Cybersecurity (NERO) is a free, self-paced training module that introduces the core principles of cybersecurity for SMEs. The course covers cybersecurity domains, risk assessment, security frameworks, standards, compliance, threat landscapes, and emerging technologies, while promoting practical security hygiene and cybersecurity awareness through lectures, demonstrations, quizzes, and real-world examples. It equips learners with the knowledge needed to identify common cyber risks, apply fundamental security practices, and contribute to a stronger organisational security culture.
- Introductory Courses to Cybersecurity
CYRUS Cybersecurity Training Catalogue
- Published date:
- Author: CYRUS - Enhanced Cybersecurity Skills project
The CYRUS Cybersecurity Training Catalogue provides free online cybersecurity training courses covering topics such as cybersecurity fundamentals, incident response, phishing awareness, social engineering, password security, cybersecurity culture, and human behaviour. Designed for professionals across different sectors and skill levels, the platform offers self-paced e-learning resources that help learners improve their ability to identify, prevent, and respond to cyber threats in the workplace.