Commission, supported by ENISA, CERT-EU and with the expertise of its Joint Research Centre, will facilitate the creation and ensure the sustainability of the hub. In addition, a regular high-level advisory group14 on cybersecurity – composed of experts and decision-makers from industry, academia, civil society and other relevant organisations – should be set up at EU level. The group would enable the Commission to get external expertise and input, in an open and transparent way, for its cybersecurity strategy policies and on potential regulatory or other public policy actions. It would complement and connect with other structures on cybersecurity15 . Moreover, the Commission is required to evaluate ENISA by 20 June 2018 and the possible modification or renewal of ENISA's mandate must be adopted by 19 June 202016. In view of the current cybersecurity landscape, the Commission aims to advance the evaluation and, subject to its results, present a proposal as soon as possible. When assessing the possible need to change ENISA’s mandate, the Commission will take into account the cybersecurity challenges described above and the overall effort to step up cooperation and knowledge sharing. This process will provide an opportunity to look into the possible enhancement of the Agency’s capabilities and capacities to support Member States in a sustainable manner in achieving cybersecurity resilience. The reflection on ENISA’s mandate would furthermore need to take into account the Agency’s new responsibilities under the NIS Directive, new policy objectives to support cybersecurity industry (the DSM strategy and in particular the cPPP), evolving needs in securing critical sectors, and new challenges linked to cross-border incidents, including coordinated response to cyber crises. The Commission will: - submit for consideration a cooperation blueprint to handle large-scale cyber incidents on the EU level in the first half of 2017; facilitate the creation of an ‘information hub’ to support the exchange of information between EU bodies and Member States; create a high-level advisory group on cybersecurity; and finalise the evaluation of ENISA by end of 2017. Such evaluation will address the need to modify or extend the mandate of ENISA, aiming for a possible proposal as soon as possible. 2.2 Increase efforts in cybersecurity education, training and exercises Adequate skills and training, related both to preventing cybersecurity incidents and to dealing with and mitigating their impacts, are some of the key aspects of achieving cybersecurity resilience. 14 Commission expert groups are subject to the horizontal rules established by Commission decision C(2016)3301. E.g. the NIS Platform, cPPP on cybersecurity and sectoral platforms such as the Energy Expert Cyber Security Platform (EECSP). It should also link to the high-level roundtable announced in the Communication on Digitising European Industry: COM(2016) 180. 16 Regulation (EU) No 526/2013 repealing Regulation (EC) No 460/2004. 15 5

Select target paragraph3