A path, not a checklist
NIS2 in Romania is not one form. The ordinance sets a chain of seven obligations, each with a deadline and a document the entity owes DNSC. Three more duties run in parallel and never pause. Miss a step and the next one slips with it: the risk evaluation fixes the assurance level, the assurance level decides which controls apply, and the controls decide what the self-assessment and the audit will measure.
We drew this path from the published texts, checked against Monitorul Oficial. This page shows what has to happen and when. The method, the templates and the sizing of each step are what we bring to an engagement.
The seven steps
Each step names the document DNSC expects, the clock that runs on it, and the part we take.
01.
30 days from entering the scope
Notification and registration
OUG art. 18 (2), (3) · DNSC Order 1/2025
You owe DNSC: the notification form, generated through Platforma NIS2@RO.
With us: we check the sector and size criteria and assemble the data the form asks for, before you submit.
02.
60 days from the registration decision · recalculated every 3 years
Entity risk-level evaluation
OUG art. 10 (2), art. 18 (6) · DNSC Order 2/2025, Annex 2
You owe DNSC: the ENIRE@RO score with its written justification. The result sets the assurance level: Basic, Important or Essential.
With us: we run the scoring workshop with your team and write the justification behind every value. This is the risk assessment.
03.
60 days from the risk evaluation · then annually
Maturity self-assessment
OUG art. 12 (4), art. 18 (7) · DNSC Order 1/2026, Annex 2
You owe DNSC: the self-assessment, two scores per control justified in writing, and the statement of applicability.
With us: we gather the evidence, score each control against the five maturity stages and draft the written justifications.
04.
30 days for essential entities
Measures plan after the self-assessment
OUG art. 12 (5) · Methodology, art. 3
You owe DNSC: a measures plan assumed by management, for every control below the target of your assurance level.
With us: we rank the gaps by distance to target and draft the plan management signs.
05.
Continuous obligation
Implementing the controls
OUG art. 11, art. 13 · DNSC Order 1/2026, Annex 1
You owe DNSC: evidence for every control that applies to your assurance level. The set grows with the level.
With us: we implement the measures on your infrastructure, with your team, and the evidence register grows as we go. This is the implementation.
06.
Periodicity not yet set by order · ad hoc at DNSC's request
Cyber security audit
OUG art. 11 (5), (6), art. 57, art. 58
You owe DNSC: the audit report of a DNSC-attested auditor. The entity chooses the auditor. The auditor must be independent.
With us: CDI NET is attested by DNSC as a cyber security auditor, company and personnel. We audit against the controls of your level and write recommendations your plan can use as they are.
07.
15 working days from receiving the report
Measures plan after the audit
OUG art. 57 (8)
You owe DNSC: the measures plan, built on the auditor's recommendations and sent to DNSC.
With us: every finding in our report is written so it can enter the plan without rework, and we present it to management and to the technical team.
All ten obligations with deadlines and legal bases, in Romanian. Version 2026.09. Free to share unchanged.
Three duties that never pause
These run alongside the path from day one, whatever step you are on.
08.
Incident reporting
24 h · 72 h · final report
OUG art. 15
Notifying significant incidents and informing the recipients of your services. We write the response plan and rehearse it against the clock. Our SURU platform adds the insight: it watches the network, explains each alert and reports incidents in line with DNSC requirements.
09.
Security governance
Officer named in 30 days · accredited course in 12 months
OUG art. 14
Management approves the measures and appoints the network and systems security officer. We prepare the approval pack and the role.
10.
DNSC control
Point of view in 3 days · plan in 15 working days
OUG art. 46, art. 50 · DNSC Order 3/2025
The point of view, the measures plan and the evidence requested after the findings note. We get the documents ready before the notice arrives.
Two roles, one per client
Audit
As a DNSC-attested auditor we perform the cyber security audit at step 06 and write recommendations your 15-day plan can use. The report records findings; it does not certify anything.
Consultancy
Risk evaluation, assisted self-assessment, implementation of the controls, incident-response and control readiness: steps 01 to 05 and the three parallel duties.
The law keeps the two apart. An auditor may not have provided security services to the same entity in the previous twelve months. So we take one role per client, audit or consultancy, and we say which one before we start.
What we do not promise
- A "NIS2 certificate". None exists in the law. The audit report records findings and recommendations; it does not certify conformity and it does not replace the authority's decisions.
- A fixed audit interval. The ordinance delegates the periodicity to a DNSC order that has not been published. Anyone quoting one is guessing.
- A shortcut through a diagnostic tool. The legal channel for the self-assessment is Platforma NIS2@RO or the DNSC assessment tools, on the legal scale of 1 to 5.
Covering incident response next? Read the CSIRT path: build, join or buy. Running a small office instead? Start with why small offices are targets.
Not sure which step you are on? Send us your sector and size. We answer with your next deadline.
Get in touchReferences checked against the texts published in Monitorul Oficial on 29.09.2026. OUG 155/2024, approved with amendments by Law 124/2025 and completed by Law 123/2026.