Decoding the world of cybersecurity

Hospitals get new EU cyber buying guide

ENISA’s first health action plan deliverable pushes hospital cybersecurity into procurement, supplier selection, contracts, and lifecycle management.

Hospitals get new EU cyber buying guide
Summary
  • ENISA has signed a €6 million agreement with the European Commission to support the EU health cyber action plan.
  • Updated procurement guidance urges hospitals and healthcare providers to build cybersecurity into supplier selection, contracts, and lifecycle management.
  • The practical test will be whether member states and health providers can turn guidance into funded supplier requirements.

ENISA has moved the European Union’s health cyber action plan from policy intent into procurement practice, signing a €6 million contribution agreement with the European Commission and publishing updated guidance for hospitals and healthcare providers.

The three-year agreement will support the proposed European Cybersecurity Support Centre for the health sector, with ENISA responsible for developing a service catalogue organised around preparedness, detection, response, and governance. Alongside that work, the agency has published updated procurement guidelines intended to help healthcare organisations build cybersecurity requirements into the way they buy products and services.

The guidance covers the procurement lifecycle, sets out requirements for suppliers, and identifies the types of products and services where cyber controls should carry particular weight. It also includes a checklist of measures linked to threat scenarios across different procurement types, giving hospitals and healthcare providers a practical route from general security expectations to buying decisions.

Healthcare cyber risk is often visible only after disruption, when ransomware hits clinical operations or sensitive data is exposed. Much of the exposure is created earlier, when hospitals buy and integrate medical technology, cloud services, diagnostics platforms, administration systems, managed IT, connected devices, and specialist software. Once those systems are embedded, weak logging, patching, access control, vulnerability handling, or incident notification terms become harder to correct.

The procurement focus also reflects the direction of European cyber regulation. NIS2 has increased expectations around risk management, supplier oversight, incident reporting, and governance across essential and important entities. Hospitals and healthcare providers cannot meet those obligations only through internal controls if critical suppliers sit outside comparable assurance processes.

The challenge now shifts to execution. Large health systems may be able to convert ENISA’s guidance into standard clauses, technical acceptance criteria, supplier questionnaires, evidence requirements, and lifecycle review processes. Smaller providers will need support from national authorities, shared templates, buying frameworks, and sector bodies if procurement guidance is to change actual contracts rather than sit as an optional reference document.

Suppliers will also face a more demanding market if the guidance takes hold. Security claims will need to be backed by evidence on vulnerability disclosure, patch support, access management, secure configuration, audit logging, incident cooperation, and end-of-life handling. Procurement teams will need to judge cyber resilience alongside clinical functionality, price, support, and integration complexity.

Healthcare procurement already sits across multiple regulatory regimes, including medical device rules, data protection, national health security requirements, and public procurement law. ENISA’s contribution will be most useful where it reduces friction for buyers and gives suppliers a clearer view of expected controls.

The health action plan, the revised procurement guidance, and cybersecurity for medical devices are due to be discussed at ENISA’s eHealth Security Conference in Cyprus in October. By then, the measure of progress will be whether procurement teams, hospital boards, and national health authorities have begun translating the guidance into buying power.

×