CDI NET logo

Service. SOC & CSIRT technical consultancy

Incident response under NIS2: build it, join it or buy it. Then get it authorized.

OUG 155/2024 gives essential and important entities three ways to cover incident response, and puts all three under DNSC authorization, the entity's own team included. Here is the path, and where we do the work with you.

Three routes, one authorization

Art. 30 of the ordinance leaves the choice to management: an own CSIRT, a sectorial CSIRT, or services bought from a provider of CSIRT-specific services authorized by DNSC. Whichever route you take, the team that serves you must hold a DNSC authorization, valid for three years. Running CSIRT activities without one is a contravention. That applies to an internal team as much as to a vendor.

The route decides the budget line, the paperwork and how much of the operational burden stays in-house. We drew the path below from the published texts, checked on 30.09.2026, and marked what is still waiting for DNSC's implementing orders.

The seven steps

Each step names the document the law expects, the clock or condition attached to it, and the part we take.

01.

Management decision, with a dedicated annual budget

Decision on the coverage model

OUG art. 30 (1) · art. 31 (1) g)

The document: the management decision, own CSIRT, sectorial CSIRT or authorized provider, with the annual budget that keeps the capability alive.

With us: we compare the three routes against your sector, size and incident history, and put numbers on each so the decision holds up in front of the board and the authority.

02.

Before the authorization request

Building the baseline capability

OUG art. 30 (3)

The document: the capability file for authorization: adequate, secure and resilient communication and information infrastructure, plus enough resources for the team's tasks.

With us: we design the team, the tooling and the communication channels, and assemble the capability file.

03.

3-year validity · mandatory for an internal CSIRT too

DNSC authorization

OUG art. 30 (2), art. 34 · sanction: art. 60 (1) aa)

The document: the authorization decision. CSIRT-specific activities without it are a contravention. The authorization regulation and its norms were still drafts on 30.09.2026.

With us: we prepare the dossier against the published requirements and track the regulation, so you file as soon as it is possible to file.

04.

Standing obligations of the team

Operational compliance

OUG art. 31 (1) a) to g)

The document: the procedures and the proof of interconnection: interoperability with the national CSIRT, the minimum service package, enough qualified staff, interconnection to DNSC's alert service, permanent availability.

With us: we write the procedures, size the staffing model and prepare the interconnection.

05.

Verifiable at control

Functioning requirements

OUG art. 32 (1) a) to h)

The document: the operational policies and the continuity plan: high-availability channels, secured premises, request handling, confidentiality, redundancy and a backup workspace, protection of beneficiaries' data.

With us: we write the policies and test the continuity plan before anyone else does.

06.

Minimum package to be detailed by DNSC order

Services delivered to beneficiaries

OUG art. 33 · art. 32 (5)

The document: the service catalogue and the reports to beneficiaries: monitoring and analysis, early warning and alerts, incident response and assistance, dynamic risk analysis, non-intrusive security scans on request.

With us: service catalogue, reporting templates, detection and response playbooks.

07.

Deadlines set by binding dispositions

DNSC supervision

OUG art. 53 · sanction: art. 60 (1) gg)

The document: compliance with DNSC's dispositions on art. 31 to 33, within the deadlines they set.

With us: control readiness: the evidence pack, a mock interview and a response calendar.

Download the one-page diagram (PDF) →

All ten obligations with legal bases, in Romanian. Version 2026.09. Free to share unchanged.

Three duties that run in parallel

These start with the team and never pause, whichever route you chose.

08.

Incident reporting

24 h · 72 h · final report

OUG art. 15, art. 16

The CSIRT operationalizes the reporting of beneficiaries' significant incidents and the voluntary reports. We write the response plan and rehearse it against the clock. Our SURU platform supports the detection and the reporting timeline.

09.

Cooperation and communities

Permanent · on the national CSIRT's request

OUG art. 30 (4), (6) · art. 32 (3), (4)

Cooperation with the national CSIRT and between teams, sectorial communities, common taxonomies and practices. We set up the channels and the sharing rules.

10.

Vulnerability management

Voluntary reports in 48 h · CVD through DNSC

OUG art. 36 (1), (7)

Vulnerability management processes at every entity, coordinated disclosure through DNSC. We build the process and the disclosure handling.

Where SURU fits in

A CSIRT is people, procedures and technology. SURU is our technology for the third part: a platform built for the activities art. 33 lists, sized so a small team can run it. It equips an own CSIRT, gives a sectorial CSIRT a sensor at each member, and is the tool a provider can run for you.

MONITORING AND ANALYSIS

art. 33 · art. 32 (5)

A hardened sensor at the edge of the network keeps connection records and blocks known attack traffic on the spot. Non-intrusive by design, so it doubles as the scan on request the law describes.

EARLY WARNING AND ALERTS

art. 33 · art. 31 (1) e)

Threat intelligence feeds and automatic notifications turn raw events into alerts, each one explained in plain language: what happened, why it matters, what to do now.

RESPONSE AND ASSISTANCE

art. 33

Every alert arrives as a brief with the steps to take and whom to call. SURU Lite adds agentic AI that executes containment measures and hands the team a case, not a log.

REPORTING AND DATA PROTECTION

art. 15 · art. 32 (1) h)

Incident reporting aligned to the NIS2 and CSIRT requirements set by DNSC, on the 24 h / 72 h clock. Beneficiaries' data stays on their own equipment, and every channel between components is encrypted.

SURU FOSS is open source and can be deployed and inspected by anyone; SURU Lite and SURU AI Plus add the built-in AI and the cloud integrations. Whichever edition, the team that operates it, and its authorization, stay with the entity or with the provider it chooses. Read more about the platform.

Still waiting for DNSC's orders

The ordinance delegates the practical rules to DNSC orders and decisions. On 30.09.2026 these were still drafts:

  • the authorization and verification regulation for CSIRTs, with the validity conditions (art. 34);
  • the minimum package of CSIRT services (art. 31, art. 32);
  • the compatibility and interoperability norms with the national CSIRT (art. 31);
  • the criteria for the number of qualified staff and the specialisation topics (art. 31);
  • the authorization regulation for CSIRT training providers (art. 54).

Until they are published, nobody can tell you the fee, the procedure or the exact content of the package. We track the drafts and we do not put a guess in your file.

Expertise, consultancy and technology

Consultancy

Route decision, CSIRT design and maturity, incident response plan and playbooks, tabletop exercises, the capability file for authorization, control readiness. Steps 01 to 07 and the three parallel duties.

Technology

SURU as the platform behind monitoring, alerting, response and reporting, installed and tuned by us on your equipment or your provider's. The team that runs it, and the authorization that team holds, stay where the law puts them: with the entity or the provider it chooses.

One more rule the law sets: security or CSIRT services to an entity exclude us from auditing that entity for twelve months. So we take one role per client, and we say which one before we start.

What we do not promise

  • The authorization. DNSC grants it. We prepare the file and the capability behind it.
  • An "authorized CSIRT service". Nobody can hold one before DNSC publishes the regulation. Until then we bring expertise, consultancy and technology, and we say so in every offer.
  • A headcount. The staffing criteria are not published. We size the team on your services and your hours of coverage, and we revise when the criteria arrive.

New to NIS2? Start with the compliance path, step by step.

Deciding between building, joining and buying? Send us your sector and size. We answer with the route and its first document.

Get in touch

References checked against the published texts on 30.09.2026. OUG 155/2024, approved with amendments by Law 124/2025 and completed by Law 123/2026. The authorization regulation, the minimum service package, the interoperability norms and the staffing criteria are approved by DNSC order and were still drafts at that date.