eu-LISA board adopts security plans for EES, VIS
Oct 9, 2026
Category: Border Security EES ETIAS EU News

The Management Board of eu-LISA has adopted security and continuity plans for two of the EU’s large-scale IT systems. The decisions came at its meeting in Strasbourg on 23–24 September 2026.
The Board approved the Security and Business Continuity Plans for the Visa Information System (VIS). It also adopted the Security, Business Continuity and Disaster Recovery Plans for the Entry/Exit System (EES).
Members met to review progress across the Agency’s IT systems portfolio. They also discussed implementing the interoperability architecture and addressed organisational, security, and governance matters.
Two systems, five plans
The VIS received two plans, covering security and business continuity. The EES received three, with a disaster recovery plan added to the same pair.
Both systems were among those reviewed during the two-day meeting, which covered operational systems, development programmes and internal matters.
Roadmap on table
Members discussed scenarios for updating the roadmap for implementing the interoperability architecture in 2027–2028, taking account of consultations with the EES-ETIAS Advisory Group.
The Board then tasked eu-LISA with detailing the necessary preconditions ahead of its next meeting. No date for that meeting was given.

State of play across portfolio
The Board reviewed the state of play of the Agency’s operational systems and development programmes. The list covered Eurodac and DubliNet, the EES, and the European Travel Information and Authorisation System (ETIAS).
It also included ECRIS-TCN and ECRIS-RI, the Schengen Information System (SIS), the VIS, and the EU Visa Application Portal. The Prüm Router and the API-PNR Router completed the line-up.
Eurodac got its own slot. The first phase of the new Eurodac entered into operation in June, and the Board reviewed progress and related follow-up work.
On the EES and ETIAS, members discussed the latest developments, including implementation planning. They also looked at next steps towards upcoming milestones, which were not specified.
Members reviewed preparations related to ECRIS-TCN. They also covered developments concerning the SIS, the VIS, the EU Visa Application Portal, the Screening Regulations, the Prüm Router and the API-PNR Router.
Budgets, audits and desks
The Board reviewed implementation of the Agency’s 2026 budget. It also looked at the status of internal and external audit recommendations.
Members received an update on the European Court of Auditors’ audit of the 2025 financial year. The Board noted eu-LISA’s organisational structure, in place since 16 August 2026.
The Board also discussed progress on the Real Estate Capacity Programme. Discussion covered office space in Strasbourg and business continuity infrastructure.
Oversight, paperwork
Further discussions covered cooperation with other EU agencies and human resources matters. Members also considered implementing eu-LISA’s obligations under its establishing Regulation.
The Board went through the formal comments on the report by the European Data Protection Supervisor (EDPS) following its 2025 Eurodac inspection. It also covered the Awareness, Preparedness and Response Report and the results of the Working Group on Availability KPIs.
The European Commission updated the Board on legislative proposals affecting eu-LISA’s operations. Members noted the action plan following the Agency’s evaluation.
Homework before next meeting
The two sets of plans are complete, but the interoperability roadmap for 2027–2028 is still at the scenario and preconditions stage. eu-LISA now has to supply the details the Board asked for before members meet again.
Several other items remain open. The EES and ETIAS are heading towards unnamed milestones, and follow-up work on the first phase of the new Eurodac continues.
The outcome of the European Court of Auditors’ audit of the 2025 financial year is still to come. The Board is also evaluating the action plan following the Agency’s evaluation.