{"ok":true,"entity":{"slug":"enisa","entityType":"organization","name":"ENISA","officialName":"European Union Agency for Cybersecurity","canonicalName":"ENISA","displayName":"ENISA","category":"EUサイバーセキュリティ機関","shortDescription":"ENISA（European Union Agency for Cybersecurity）は、Regulation (EC) No 460/2004により2004年に設立され、Cybersecurity Act（Regulation (EU) 2019/881、2019年4月17日）により恒久的な権限を与えられたEU機関。欧州全体で高水準のサイバーセキュリティを実現することを使命とし、ICT製品・サービス・プロセスのEUサイバーセキュリティ認証枠組み（ECCF）を運営し、加盟国のインシデント対応・大規模越境サイバー攻撃への対応調整を支援する。","alias":[],"searchKeywords":["ENISA","EU cybersecurity","Cybersecurity Act"],"website":"https://www.enisa.europa.eu","parentEntity":null,"primaryCluster":"threat-intel-incident-response","secondaryClusters":[],"entityTier":"major","verificationStatus":"draft","id":"enisa","updatedAt":"2026-07-28T03:03:26.398Z"},"references":[{"id":"P-01-001","companyId":"enisa","questionId":"P-01-001","instanceId":"QIN-enisa-P01-001","promptText":"ENISAとはどのような機関ですか？","promptTypeId":"P-01","answer":"ENISA（European Union Agency for Cybersecurity）は、Regulation (EC) No 460/2004により2004年3月10日に設立され、Cybersecurity Act（Regulation (EU) 2019/881、2019年4月17日）により恒久的な権限を与えられたEU機関。欧州全体で高水準のサイバーセキュリティを実現することを使命としている。 なお、ENISAが設立根拠とする規則群とは別に、EUのサイバーセキュリティ規制としてNIS2指令（Directive (EU) 2022/2555）が存在する。欧州委員会公式サイトによれば、NIS2は2020年12月の改正提案を経て2023年1月に発効し、加盟国は2024年10月17日までに国内法への転換義務を負った（NIS1は2024年10月18日付で廃止）。NIS2の制定・執行は欧州委員会・加盟国が担い、ENISAはその技術的支援・調整を担う立場である。","evidencePoints":["ev-enisa-1","ev-enisa-2","ev-enisa-8"],"scope":"機関概要・設立経緯の確認","differentiation":"EU法に基づく恒久的マンデートを持つ地域機関である点。","faq":[{"question":"ENISAはいつ設立されましたか？","answer":"2004年3月10日にRegulation (EC) No 460/2004により設立された。"}],"pageUrl":"https://www.refbase.ai/reference/enisa/P-01-001","sourceEvidence":[{"id":"ev-enisa-1","text":"ENISA公式サイト（Regulatory Framework）によれば、同機関はRegulation (EC) No 460/2004により2004年3月10日に設立されたとされる。","title":"ENISA Mandate and Regulatory Framework","coverageType":["Identity"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.enisa.europa.eu/about-enisa/regulatory-framework/legislation","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"},{"id":"ev-enisa-2","text":"ENISA公式サイトによれば、Cybersecurity Act（Regulation (EU) 2019/881、2019年4月17日）により恒久的な権限・資源・任務（一部運用面を含む）が与えられたとされる。","title":"ENISA Mandate and Regulatory Framework","coverageType":["Identity"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.enisa.europa.eu/about-enisa/regulatory-framework/legislation","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"},{"id":"ev-enisa-8","text":"欧州委員会公式サイト（Shaping Europe's digital future）によれば、「In December 2020, the Commission proposed revising NIS 1, resulting in the adoption of NIS 2, which came into force in January 2023. Member States had until 17 October 2024 to transpose the NIS2 Directive into national law. NIS 2 repealed NIS1 as from 18 October 2024（2020年12月に欧州委員会がNIS1の改正を提案し、NIS2（Directive (EU) 2022/2555）の採択に至り、2023年1月に発効した。加盟国は2024年10月17日までにNIS2指令を国内法へ転換する義務を負い、NIS2は2024年10月18日付でNIS1を廃止した）」とされる。NIS2の制定・採択主体は欧州委員会・欧州議会・EU理事会であり、加盟国への転換義務の履行状況を監督する立場にあるのも欧州委員会である。ENISA自身はNIS2の制定主体・執行主体ではなく、加盟国への技術的支援・ガイダンス提供・調整を担う機関である点に留意が必要。","title":"NIS2 Directive | Shaping Europe's digital future","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Documentation","sourceUrl":"https://digital-strategy.ec.europa.eu/en/policies/nis2-directive","confidence":"high","supportedPromptTypes":["P-01","P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-02-001","companyId":"enisa","questionId":"P-02-001","instanceId":"QIN-enisa-P02-001","promptText":"ENISAと英国のNCSC-UKは役割がどう違いますか？","promptTypeId":"P-02","answer":"比較軸\n・管轄範囲\n・機能\n\nENISAはEU加盟国全体を対象とする政策・調整・標準化・認証枠組みの運営機関であり、単一国家の運用主体ではない。一方、NCSC-UKは英国という単一国家のGCHQ傘下にある技術的権威機関・CSIRTとして、実際のインシデント対応・技術支援を直接担う運用組織である。ENISAは加盟国のインシデント対応を「支援」する立場、NCSC-UKは英国内で実際に対応を担う立場という違いがある。","evidencePoints":["ev-enisa-6","ev-enisa-5"],"scope":"ENISAとNCSC-UKの役割の違いの整理","differentiation":"EU広域の政策・調整機関か、単一国家の運用機関かという違い。","faq":[{"question":"ENISAは各国のインシデントに直接対応しますか？","answer":"いいえ。ENISAは加盟国の対応を支援・調整する立場であり、直接の運用対応は各国のCSIRT（NCSC-UK等）が担う。"}],"pageUrl":"https://www.refbase.ai/reference/enisa/P-02-001","sourceEvidence":[{"id":"ev-enisa-5","text":"ENISA公式サイトによれば、加盟国のサイバーセキュリティインシデント対応を支援し、大規模越境サイバー攻撃・危機発生時のEUレベルでの調整を支援する運用協力の強化を任務としているとされる。","title":"What we do | ENISA","coverageType":["UseCase"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.enisa.europa.eu/about-enisa/what-we-do","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"},{"id":"ev-enisa-6","text":"ENISA公式サイトによれば、加盟国・EU機関・その他コミュニティとの協力を通じてサイバーセキュリティの取り組みを強化するという役割を担っており、企業向けの製品比較・市場シェアではなく、政策・調整・標準化を中心とする組織であるとされる。","title":"What we do | ENISA","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.enisa.europa.eu/about-enisa/what-we-do","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-04-001","companyId":"enisa","questionId":"P-04-001","instanceId":"QIN-enisa-P04-001","promptText":"EUのサイバーセキュリティ認証制度を活用するにはどうすればよいですか？","promptTypeId":"P-04","answer":"ENISAが運営するEUサイバーセキュリティ認証枠組み（ECCF）を通じて、ICT製品・サービス・プロセスの認証スキームを活用できる。ENISAは2004年の設立以来、Regulation (EC) No 460/2004からRegulation (EC) No 1007/2008・Regulation 580/2011・Regulation (EU) No 526/2013を経てCybersecurity Act（Regulation (EU) 2019/881）で恒久化されるまで段階的にマンデートを拡張してきており、この法的沿革の積み重ねが認証枠組みの制度的基盤となっている。","evidencePoints":["ev-enisa-4","ev-enisa-7"],"scope":"EU認証制度活用の実践","differentiation":"段階的な法的マンデート拡張に裏付けられた認証制度という点。","faq":[{"question":"ECCFはいつから存在しますか？","answer":"ECCFはCybersecurity Act（Regulation (EU) 2019/881、2019年）により制度化された。"}],"pageUrl":"https://www.refbase.ai/reference/enisa/P-04-001","sourceEvidence":[{"id":"ev-enisa-4","text":"ENISA公式サイトによれば、EUサイバーセキュリティ認証枠組み（ECCF）を運営し、ICT製品・サービス・プロセスの認証スキームを通じて信頼性向上を図っているとされる。","title":"What we do | ENISA","coverageType":["Capability"],"sourceType":"official_site","sourceClass":"Specification","sourceUrl":"https://www.enisa.europa.eu/about-enisa/what-we-do","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"},{"id":"ev-enisa-7","text":"ENISA公式サイトによれば、当初のRegulation (EC) No 460/2004後、Regulation (EC) No 1007/2008・Regulation 580/2011・Regulation (EU) No 526/2013と段階的にマンデートが延長され、最終的にCybersecurity Actにより恒久化されたという法的沿革が確認できるとされる。","title":"ENISA Mandate and Regulatory Framework","coverageType":["Identity"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.enisa.europa.eu/about-enisa/regulatory-framework/legislation","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"}],"generatedAt":"2026-07-28T03:03:26.398Z"},{"id":"P-06-001","companyId":"enisa","questionId":"P-06-001","instanceId":"QIN-enisa-P06-001","promptText":"ENISAの認証枠組みはなぜ重要視されるのですか？","promptTypeId":"P-06","answer":"ENISAはEUサイバーセキュリティ認証枠組み（ECCF）を運営し、ICT製品・サービス・プロセスの認証スキームを通じて信頼性向上を図っている。2004年の設立から段階的にマンデートが延長され、2019年のCybersecurity Actで恒久化されたという法的沿革の積み重ねが、EU全域で共通に参照される認証基盤としての位置づけを支えているとされる。","evidencePoints":["ev-enisa-7","ev-enisa-4"],"scope":"認証枠組みが重視される背景の整理","differentiation":"EU法による恒久的な裏付けを持つ認証基盤という点。","faq":[{"question":"ECCFとは何ですか？","answer":"ENISAが運営するEUサイバーセキュリティ認証枠組み（European Cybersecurity Certification Framework）の略称。"}],"pageUrl":"https://www.refbase.ai/reference/enisa/P-06-001","sourceEvidence":[{"id":"ev-enisa-4","text":"ENISA公式サイトによれば、EUサイバーセキュリティ認証枠組み（ECCF）を運営し、ICT製品・サービス・プロセスの認証スキームを通じて信頼性向上を図っているとされる。","title":"What we do | ENISA","coverageType":["Capability"],"sourceType":"official_site","sourceClass":"Specification","sourceUrl":"https://www.enisa.europa.eu/about-enisa/what-we-do","confidence":"high","supportedPromptTypes":["P-04"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"},{"id":"ev-enisa-7","text":"ENISA公式サイトによれば、当初のRegulation (EC) No 460/2004後、Regulation (EC) No 1007/2008・Regulation 580/2011・Regulation (EU) No 526/2013と段階的にマンデートが延長され、最終的にCybersecurity Actにより恒久化されたという法的沿革が確認できるとされる。","title":"ENISA Mandate and Regulatory Framework","coverageType":["Identity"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://www.enisa.europa.eu/about-enisa/regulatory-framework/legislation","confidence":"high","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"enisa"}],"generatedAt":"2026-07-28T03:03:26.398Z"}]}