NIS2 in Romania

DNSC Order No. 1/2026 establishes security measures and maturity assessment

NIS2 in Romania

NIS2 compliance in Romania is entering a more concrete stage. DNSC Order No. 1/2026, published in Official Gazette No. 712 of 27 August 2026, establishes the cybersecurity risk-management measures and the methodology for assessing their maturity.

The new order complements the framework established by Government Emergency Ordinance (GEO) No. 155/2024, which transposed the NIS2 Directive into national law, as well as the subsequent secondary legislation. For the organizations concerned, compliance is therefore moving from determining the level of risk towards the concrete assessment of security measures, the identification of gaps, and demonstrating that these measures work in practice.

What is DNSC Order No. 1/2026?

The Order approves two important components: cybersecurity risk-management measures for the network and information systems used by essential and important entities, and the methodology for assessing the maturity of these measures.

It should be considered together with DNSC Order No. 2/2025, which regulates the assessment of the risk level.

In practice, the process now follows a clearer sequence: the organization assesses its risk, determines the appropriate assurance level, identifies the applicable measures and controls, and evaluates the maturity of their implementation.

Who does it apply to?

The requirements apply to essential and important entities falling within the scope of GEO No. 155/2024.

NIS2 covers organizations across a wide range of sectors, including energy, transport, healthcare, digital infrastructure, public administration, ICT services, water, as well as certain manufacturing activities and other sectors considered essential or important.

However, whether an organization falls within the scope depends on the criteria established by the legislation. Therefore, the obligations do not automatically apply to all companies in Romania.

Is there a deadline for compliance?

Is there a deadline for compliance?

There is no single deadline for NIS2 compliance. The obligations are implemented in stages, and some deadlines are calculated from the date on which DNSC communicates its decision regarding the identification and registration of the entity.

One of the key stages is the risk level assessment (ENIRE), which must be submitted within 60 days of the communication of the DNSC decision.

This is followed by the self-assessment of the maturity of security measures, carried out in accordance with the methodology approved by DNSC. For essential entities, within 30 days of completing the self-assessment, a remediation plan addressing the identified deficiencies must be prepared and submitted.

Compliance should therefore be viewed as a multi-stage process rather than as an obligation that can be completed by a single deadline.

What do the new requirements mean for organizations?

Risk assessment should not be reduced to completing and submitting a form. An organization needs to understand what it is protecting, which threats it is exposed to, which assets and services are critical, and what impact their compromise or unavailability could have.

The next step is to assess the organization's actual protection capabilities. The maturity methodology uses the CyberFundamentals Framework (CyFun) and enables a structured analysis of the measures that have been implemented.

This is also where gap analysis becomes relevant: which controls are already in place, what is missing, where deficiencies exist, what needs to be prioritized, and what evidence can demonstrate that the measures are operating effectively.

The process does not concern IT or cybersecurity teams alone. Management, compliance, legal, procurement, and supplier management teams may all have direct roles in risk management and the implementation of the requirements. At management level, there must also be a clear understanding of the services and assets that need to remain operational in the event of an incident.

What do the new requirements mean for organizations?

From compliance to cyber resilience

The regulation establishes a minimum level of security, but cyber threats evolve faster than legislation. For this reason, an organization that formally meets the requirements is not automatically resilient.

The difference becomes apparent when the measures are put to the test. Policies, procedures, and technical solutions should be complemented by periodic testing and cyber incident simulations to verify how the organization responds, recovers affected systems, and maintains its operations.

The question is not only whether a business continuity plan or an incident response procedure exists, but whether the organization can actually put that plan into practice when an incident affects critical systems and services.

Ultimately, cyber resilience means more than protecting IT infrastructure: it means the ability of the business to continue operating and delivering essential services during and after an incident.

Compliance must be demonstrable 

With DNSC Order No. 1/2026, the question for organizations concerned is no longer simply “Does NIS2 apply to us?”, but also “Do we understand the risks we are exposed to, do we have the necessary measures in place, and can we demonstrate that they work?”

The objective is not simply to tick compliance boxes or prepare documentation for an audit. Risk assessment, maturity assessment, remediation, implementation, and testing of security measures must form a continuous process through which compliance effectively contributes to strengthening the organization's resilience.

Assess your organization’s NIS2 readiness
Assess your organization’s NIS2 readiness

For organizations looking to assess their current level of preparedness, Expertware provides a NIS2 assessment questionnaire developed in accordance with the CyberFundamentals Framework (CyFun). The assessment can be completed independently through a dedicated account, where results and assessment history are kept private, allowing organizations to track their progress over time. The NIS2 assessment questionnaire can be completed here.

For organizations that require an assessment tailored to their specific context or support throughout the compliance process, a meeting with an Expertware NIS2 compliance expert can be scheduled here: https://expertware.net/Contact.

Cloud image

30 Days of Enterprise-Grade Cyber Defense

Step into the future of cybersecurity with full access to a unified, intelligent platform — free for 30 days. Empower your security team with:

  • Advanced SIEM for real-time visibility, smart alerting, and deep forensics across cloud, on-prem, and hybrid environments

  • Continuous Vulnerability Management to identify, prioritize, and remediate risk across all assets

  • Live Cyber Threat Intelligence integrated directly into your workflows, with global insights and attacker profiling

  • AI-Powered Threat Detection that learns from your environment, explains alerts in plain language, and suggests next steps

  • Built-in Compliance Readiness for NIS2, GDPR, ISO 27001, and more, with automated reporting and audit tools

Whether you're managing a lean SOC or a full-scale enterprise security team, this platform gives you the tools to detect faster, respond smarter, and stay ahead of evolving threats — all without the complexity.

Experience enterprise-grade protection, streamlined workflows, and total control.

Your 30-day head start begins now.

Unlock Your 30 Days Free Trial