The NIS2 Directive makes cybersecurity a management responsibility and requires risk-management measures and incident reporting from the entities within scope. Applicability and specific obligations are determined by the organisation’s activity and the national framework in force.

The European Commission’s overview explains the scope of the directive, risk management and the responsibility of management.

DNSC Order No. 1/2026: the measures and the self-assessment methodology

The DNSC Director’s Order No. 1 of 6 August 2026, published in Romania’s Official Gazette No. 712 of 27 August 2026, approves two working instruments for essential and important entities: the cybersecurity risk-management measures for network and information systems and the methodology for self-assessing the maturity of those measures. The order also amends the risk-level assessment methodology approved by DNSC Order No. 2/2025.

The measures are organised by function — Govern, Identify, Protect, Detect, Respond and Recover — and by assurance level: basic, important and essential. Entities implement the controls of the assurance level that corresponds to their risk level, determined under the methodology approved by DNSC Order No. 2/2025: an overall score between 0 and 99 means the basic level, between 100 and 199 the important level, and 200 or above the essential level. Requirements from special or sector-specific regulations are recorded in a statement of applicability.

Self-assessment: documentation and implementation

For each applicable measure, the methodology requires two separate ratings: how well the measure is documented, through policies, procedures and responsibilities, and how well it works in practice. Each score is justified by evidence.

Emergency Ordinance No. 155/2024 (OUG 155/2024) requires the self-assessment to be carried out and submitted annually to DNSC and, where applicable, to the sector’s competent authority, endorsed by the entity’s management. The first self-assessment is due within 60 days of submitting the risk-level assessment. The steps, scores and thresholds are explained in the step-by-step NIS2 self-assessment guide (in Romanian). How the risk level is calculated is covered in our guide to the NIS2 risk level, and who can perform the audit in our guide to the NIS2 audit.

In practice, implementation evidence takes the most time. A PenTest report shows which vulnerabilities exist and, after retesting, whether remediation worked. SOC monitoring shows which events are collected, analysed and escalated, and who responds.

The remediation plan

Where the target level is not reached, gaps are addressed through a plan of measures: what is missing, which actions follow, who is responsible, what resources are needed, the deadline and how the result is verified. For essential entities, OUG 155/2024 requires the plan, endorsed by the entity’s management, to be drawn up and submitted within 30 days of completing the self-assessment.

A credible plan starts from risk priorities, not from a list of products. CIO-as-a-Service can coordinate priorities, budget and responsibilities, while PenTest retesting confirms that technical findings have been closed.

The first DNSC fine: 29 September 2026

On 29 September 2026, DNSC issued its first fine under OUG 155/2024: RON 50,000 to a specialised body of the central public administration for failing to meet the notification deadline (the administrative offence under Art. 60(1)(o)). The sanction did not stem from a cyber incident but from an administrative obligation that was not met on time. See the AGERPRES news report (in Romanian).

For companies, the message is that procedural deadlines matter as much as technical measures. It is worth checking the basic steps first.

What to check now

  1. Classification and notification. Whether the organisation is an essential or important entity, and whether it has notified DNSC for registration.
  2. The risk-level assessment. Completed and submitted within the required deadline.
  3. The self-assessment. Following the methodology in DNSC Order No. 1/2026, with scores and evidence for documentation and for implementation.
  4. The remediation plan. With owners, resources and deadlines; for essential entities, submitted within 30 days.
  5. Technical evidence. PenTest reports and retest results, SOC reports, configurations and documented procedures.

For the maturity calculator, audits by DNSC-certified auditors who are TRU partners, and TRU support, see NIS2 audit and compliance.

From obligations to organised measures

A security programme includes people, processes and technology. Risk assessment, responsibilities, business continuity and incident management must be aligned with the real infrastructure. Buying a product, on its own, does not demonstrate the organisation’s compliance.

Encryption is assessed in the context of use

Proton Workspace natively covers the NIS2 encryption requirements: data encrypted in transit and at rest with zero-access encryption, traffic encrypted through a VPN, encryption keys under your control, sign-in with a physical security key and Proton Pass for passwords. No premium licences and no separate configuration. At Proton, zero-access encryption is standard for all data, unlike the big-tech suites. At Microsoft 365 and Google Workspace, data is encrypted, but the provider holds the keys. Your own keys require the top-tier plans. The details are in our guide to the encryption NIS2 requires.

For email, what matters is the sender, the recipient and the method used. Messages between Proton accounts benefit from end-to-end encryption. Ordinary sending to other providers is not end-to-end by default; dedicated options are available, such as password-protected messages or PGP. See Proton’s explanation of encryption.

Protecting accounts and devices, access control and recovery measures remain relevant in any configuration. We choose solutions according to the organisation’s risks and workflows.

A starting point for your company

We can start with your existing infrastructure, the main risks and your team’s responsibilities. We establish what needs to be assessed, monitored or configured and who carries out each activity. Contact TRU to discuss the technical and management components of the project.

From requirements to activities and evidence

We use the right services to build the technical and management components of the security programme. We establish what each project covers and what remains the organisation’s responsibility.

ComponentTRU service contributionWhat we document
Vulnerability assessmentInternal and external PenTest, with recommendations and retesting.The authorised scope, findings, priorities and retest results.
Incident managementSOC 24/7/365, with analysis and escalation.Covered assets, contacts, investigated events and authorised actions.
Information protectionProton Workspace, with data encrypted in transit and at rest, with zero-access encryption.Configuration, access and the encryption methods applicable to communications.
IT programme organisationCIO-as-a-Service, for priorities and coordination.The agreed action plan, budgets and responsibilities.

What we establish before a proposal

The company’s activity and applicable framework, the systems its operations depend on, existing assessments, suppliers and responsible people. We then choose a concrete testing or monitoring scope and an implementation plan. A PenTest report and a SOC subscription are components of the programme; they do not constitute a general NIS2 compliance certificate.

Reference framework

Directive (EU) 2022/2555 (NIS2), the national framework established by OUG 155/2024, approved with amendments by Law No. 124/2025, and DNSC Order No. 1/2026 must be analysed together with the acts and instructions applicable to the organisation. European Commission · OUG 155/2024 · Law No. 124/2025 · DNSC Order No. 1/2026 · First DNSC fine (AGERPRES, Romanian) · DNSC.