CDI NET logo

Service. NIS2 risk assessment & implementation

NIS2 compliance in Romania, mapped step by step.

Since OUG 155/2024, essential and important entities owe DNSC a fixed sequence of documents, each with its own deadline. Here is the path, and where we do the work with you.

A path, not a checklist

NIS2 in Romania is not one form. The ordinance sets a chain of seven obligations, each with a deadline and a document the entity owes DNSC. Three more duties run in parallel and never pause. Miss a step and the next one slips with it: the risk evaluation fixes the assurance level, the assurance level decides which controls apply, and the controls decide what the self-assessment and the audit will measure.

We drew this path from the published texts, checked against Monitorul Oficial. This page shows what has to happen and when. The method, the templates and the sizing of each step are what we bring to an engagement.

The seven steps

Each step names the document DNSC expects, the clock that runs on it, and the part we take.

01.

30 days from entering the scope

Notification and registration

OUG art. 18 (2), (3) · DNSC Order 1/2025

You owe DNSC: the notification form, generated through Platforma NIS2@RO.

With us: we check the sector and size criteria and assemble the data the form asks for, before you submit.

02.

60 days from the registration decision · recalculated every 3 years

Entity risk-level evaluation

OUG art. 10 (2), art. 18 (6) · DNSC Order 2/2025, Annex 2

You owe DNSC: the ENIRE@RO score with its written justification. The result sets the assurance level: Basic, Important or Essential.

With us: we run the scoring workshop with your team and write the justification behind every value. This is the risk assessment.

03.

60 days from the risk evaluation · then annually

Maturity self-assessment

OUG art. 12 (4), art. 18 (7) · DNSC Order 1/2026, Annex 2

You owe DNSC: the self-assessment, two scores per control justified in writing, and the statement of applicability.

With us: we gather the evidence, score each control against the five maturity stages and draft the written justifications.

04.

30 days for essential entities

Measures plan after the self-assessment

OUG art. 12 (5) · Methodology, art. 3

You owe DNSC: a measures plan assumed by management, for every control below the target of your assurance level.

With us: we rank the gaps by distance to target and draft the plan management signs.

05.

Continuous obligation

Implementing the controls

OUG art. 11, art. 13 · DNSC Order 1/2026, Annex 1

You owe DNSC: evidence for every control that applies to your assurance level. The set grows with the level.

With us: we implement the measures on your infrastructure, with your team, and the evidence register grows as we go. This is the implementation.

06.

Periodicity not yet set by order · ad hoc at DNSC's request

Cyber security audit

OUG art. 11 (5), (6), art. 57, art. 58

You owe DNSC: the audit report of a DNSC-attested auditor. The entity chooses the auditor. The auditor must be independent.

With us: CDI NET is attested by DNSC as a cyber security auditor, company and personnel. We audit against the controls of your level and write recommendations your plan can use as they are.

07.

15 working days from receiving the report

Measures plan after the audit

OUG art. 57 (8)

You owe DNSC: the measures plan, built on the auditor's recommendations and sent to DNSC.

With us: every finding in our report is written so it can enter the plan without rework, and we present it to management and to the technical team.

Download the one-page diagram (PDF) →

All ten obligations with deadlines and legal bases, in Romanian. Version 2026.09. Free to share unchanged.

Three duties that never pause

These run alongside the path from day one, whatever step you are on.

08.

Incident reporting

24 h · 72 h · final report

OUG art. 15

Notifying significant incidents and informing the recipients of your services. We write the response plan and rehearse it against the clock. Our SURU platform adds the insight: it watches the network, explains each alert and reports incidents in line with DNSC requirements.

09.

Security governance

Officer named in 30 days · accredited course in 12 months

OUG art. 14

Management approves the measures and appoints the network and systems security officer. We prepare the approval pack and the role.

10.

DNSC control

Point of view in 3 days · plan in 15 working days

OUG art. 46, art. 50 · DNSC Order 3/2025

The point of view, the measures plan and the evidence requested after the findings note. We get the documents ready before the notice arrives.

Two roles, one per client

Audit

As a DNSC-attested auditor we perform the cyber security audit at step 06 and write recommendations your 15-day plan can use. The report records findings; it does not certify anything.

Consultancy

Risk evaluation, assisted self-assessment, implementation of the controls, incident-response and control readiness: steps 01 to 05 and the three parallel duties.

The law keeps the two apart. An auditor may not have provided security services to the same entity in the previous twelve months. So we take one role per client, audit or consultancy, and we say which one before we start.

What we do not promise

  • A "NIS2 certificate". None exists in the law. The audit report records findings and recommendations; it does not certify conformity and it does not replace the authority's decisions.
  • A fixed audit interval. The ordinance delegates the periodicity to a DNSC order that has not been published. Anyone quoting one is guessing.
  • A shortcut through a diagnostic tool. The legal channel for the self-assessment is Platforma NIS2@RO or the DNSC assessment tools, on the legal scale of 1 to 5.

Covering incident response next? Read the CSIRT path: build, join or buy. Running a small office instead? Start with why small offices are targets.

Not sure which step you are on? Send us your sector and size. We answer with your next deadline.

Get in touch

References checked against the texts published in Monitorul Oficial on 29.09.2026. OUG 155/2024, approved with amendments by Law 124/2025 and completed by Law 123/2026.