Three routes, one authorization
Art. 30 of the ordinance leaves the choice to management: an own CSIRT, a sectorial CSIRT, or services bought from a provider of CSIRT-specific services authorized by DNSC. Whichever route you take, the team that serves you must hold a DNSC authorization, valid for three years. Running CSIRT activities without one is a contravention. That applies to an internal team as much as to a vendor.
The route decides the budget line, the paperwork and how much of the operational burden stays in-house. We drew the path below from the published texts, checked on 30.09.2026, and marked what is still waiting for DNSC's implementing orders.
The seven steps
Each step names the document the law expects, the clock or condition attached to it, and the part we take.
01.
Management decision, with a dedicated annual budget
Decision on the coverage model
OUG art. 30 (1) · art. 31 (1) g)
The document: the management decision, own CSIRT, sectorial CSIRT or authorized provider, with the annual budget that keeps the capability alive.
With us: we compare the three routes against your sector, size and incident history, and put numbers on each so the decision holds up in front of the board and the authority.
02.
Before the authorization request
Building the baseline capability
OUG art. 30 (3)
The document: the capability file for authorization: adequate, secure and resilient communication and information infrastructure, plus enough resources for the team's tasks.
With us: we design the team, the tooling and the communication channels, and assemble the capability file.
03.
3-year validity · mandatory for an internal CSIRT too
DNSC authorization
OUG art. 30 (2), art. 34 · sanction: art. 60 (1) aa)
The document: the authorization decision. CSIRT-specific activities without it are a contravention. The authorization regulation and its norms were still drafts on 30.09.2026.
With us: we prepare the dossier against the published requirements and track the regulation, so you file as soon as it is possible to file.
04.
Standing obligations of the team
Operational compliance
OUG art. 31 (1) a) to g)
The document: the procedures and the proof of interconnection: interoperability with the national CSIRT, the minimum service package, enough qualified staff, interconnection to DNSC's alert service, permanent availability.
With us: we write the procedures, size the staffing model and prepare the interconnection.
05.
Verifiable at control
Functioning requirements
OUG art. 32 (1) a) to h)
The document: the operational policies and the continuity plan: high-availability channels, secured premises, request handling, confidentiality, redundancy and a backup workspace, protection of beneficiaries' data.
With us: we write the policies and test the continuity plan before anyone else does.
06.
Minimum package to be detailed by DNSC order
Services delivered to beneficiaries
OUG art. 33 · art. 32 (5)
The document: the service catalogue and the reports to beneficiaries: monitoring and analysis, early warning and alerts, incident response and assistance, dynamic risk analysis, non-intrusive security scans on request.
With us: service catalogue, reporting templates, detection and response playbooks.
07.
Deadlines set by binding dispositions
DNSC supervision
OUG art. 53 · sanction: art. 60 (1) gg)
The document: compliance with DNSC's dispositions on art. 31 to 33, within the deadlines they set.
With us: control readiness: the evidence pack, a mock interview and a response calendar.
All ten obligations with legal bases, in Romanian. Version 2026.09. Free to share unchanged.
Three duties that run in parallel
These start with the team and never pause, whichever route you chose.
08.
Incident reporting
24 h · 72 h · final report
OUG art. 15, art. 16
The CSIRT operationalizes the reporting of beneficiaries' significant incidents and the voluntary reports. We write the response plan and rehearse it against the clock. Our SURU platform supports the detection and the reporting timeline.
09.
Cooperation and communities
Permanent · on the national CSIRT's request
OUG art. 30 (4), (6) · art. 32 (3), (4)
Cooperation with the national CSIRT and between teams, sectorial communities, common taxonomies and practices. We set up the channels and the sharing rules.
10.
Vulnerability management
Voluntary reports in 48 h · CVD through DNSC
OUG art. 36 (1), (7)
Vulnerability management processes at every entity, coordinated disclosure through DNSC. We build the process and the disclosure handling.
Where SURU fits in
A CSIRT is people, procedures and technology. SURU is our technology for the third part: a platform built for the activities art. 33 lists, sized so a small team can run it. It equips an own CSIRT, gives a sectorial CSIRT a sensor at each member, and is the tool a provider can run for you.
MONITORING AND ANALYSIS
art. 33 · art. 32 (5)
A hardened sensor at the edge of the network keeps connection records and blocks known attack traffic on the spot. Non-intrusive by design, so it doubles as the scan on request the law describes.
EARLY WARNING AND ALERTS
art. 33 · art. 31 (1) e)
Threat intelligence feeds and automatic notifications turn raw events into alerts, each one explained in plain language: what happened, why it matters, what to do now.
RESPONSE AND ASSISTANCE
art. 33
Every alert arrives as a brief with the steps to take and whom to call. SURU Lite adds agentic AI that executes containment measures and hands the team a case, not a log.
REPORTING AND DATA PROTECTION
art. 15 · art. 32 (1) h)
Incident reporting aligned to the NIS2 and CSIRT requirements set by DNSC, on the 24 h / 72 h clock. Beneficiaries' data stays on their own equipment, and every channel between components is encrypted.
SURU FOSS is open source and can be deployed and inspected by anyone; SURU Lite and SURU AI Plus add the built-in AI and the cloud integrations. Whichever edition, the team that operates it, and its authorization, stay with the entity or with the provider it chooses. Read more about the platform.
Still waiting for DNSC's orders
The ordinance delegates the practical rules to DNSC orders and decisions. On 30.09.2026 these were still drafts:
- the authorization and verification regulation for CSIRTs, with the validity conditions (art. 34);
- the minimum package of CSIRT services (art. 31, art. 32);
- the compatibility and interoperability norms with the national CSIRT (art. 31);
- the criteria for the number of qualified staff and the specialisation topics (art. 31);
- the authorization regulation for CSIRT training providers (art. 54).
Until they are published, nobody can tell you the fee, the procedure or the exact content of the package. We track the drafts and we do not put a guess in your file.
Expertise, consultancy and technology
Consultancy
Route decision, CSIRT design and maturity, incident response plan and playbooks, tabletop exercises, the capability file for authorization, control readiness. Steps 01 to 07 and the three parallel duties.
Technology
SURU as the platform behind monitoring, alerting, response and reporting, installed and tuned by us on your equipment or your provider's. The team that runs it, and the authorization that team holds, stay where the law puts them: with the entity or the provider it chooses.
One more rule the law sets: security or CSIRT services to an entity exclude us from auditing that entity for twelve months. So we take one role per client, and we say which one before we start.
What we do not promise
- The authorization. DNSC grants it. We prepare the file and the capability behind it.
- An "authorized CSIRT service". Nobody can hold one before DNSC publishes the regulation. Until then we bring expertise, consultancy and technology, and we say so in every offer.
- A headcount. The staffing criteria are not published. We size the team on your services and your hours of coverage, and we revise when the criteria arrive.
New to NIS2? Start with the compliance path, step by step.
Deciding between building, joining and buying? Send us your sector and size. We answer with the route and its first document.
Get in touchReferences checked against the published texts on 30.09.2026. OUG 155/2024, approved with amendments by Law 124/2025 and completed by Law 123/2026. The authorization regulation, the minimum service package, the interoperability norms and the staffing criteria are approved by DNSC order and were still drafts at that date.