Banking and financial market infrastructure are the only Annex 1 sectors to which OUG 155/2024 applies only in part. Art. 2(3) states that entities subject to the DORA Regulation are covered only by arts. 5–10 and art. 18, meaning classification and registration. The DNSC methodology also exempts them from the risk-level assessment.

Who is in the NIS2 annex from the financial area

Annex 1 to OUG 155/2024 takes over the list in the NIS2 Directive. From the financial area, only three types of entity are covered, in two sectors:

Insurers, investment firms, payment institutions and e-money institutions do not appear in the NIS2 annexes. DORA applies to them directly, from 17 January 2025, supervised by the National Bank of Romania or the Financial Supervisory Authority (ASF), as applicable.

What applies from each act

For banks, trading venues and central counterparties, obligations are split between OUG 155/2024 and DORA. The DNSC methodology, as amended by Order No. 1/2026, states that banking and financial market infrastructure entities subject to DORA do not carry out the risk-level assessment and apply the DORA measures.

ObligationWhere it comes from
Classification as an essential or important entityOUG 155/2024, arts. 5–10
Notification and registration with DNSCOUG 155/2024, art. 18
Risk-level assessmentnot carried out: the DNSC methodology refers to DORA
Risk-management measuresDORA: the ICT risk-management framework
Incident reportingDORA: major ICT-related incidents, to the financial supervisor
TestingDORA: the digital operational resilience testing programme and, for designated entities, threat-led penetration testing at least every 3 years
ICT suppliersDORA: the register of information on contracts and the mandatory contractual clauses

DORA requires a testing programme. TRU PenTest tests the external and internal network every month, with CREST-accredited reports within 48 hours of the scan being completed.

See PenTest

What the ICT risk-management framework covers

DORA covers all ICT systems that support the business. In practice, the assessment starts from critical or important functions and works down to:

Are you an ICT supplier to a bank?

DORA reaches suppliers too. Financial entities keep a register of information on their contracts with ICT service providers and include mandatory clauses in those contracts: where data is processed, service levels, incident support, audit rights and exit conditions.

For an IT company, this means questionnaires, audits and tests requested by the client. And if the company is medium-sized or large and provides managed services, it is itself covered by NIS2, in the ICT service management sector.

The DNSC methodology exempts digital infrastructure and ICT service management providers from the risk-level assessment only if they are designated as critical ICT third-party service providers under DORA. All others carry out the assessment, like any entity in their sector.

What you need to do

How TRU helps

For banks and their suppliers, we help mainly with testing and monitoring:

Through CIO-as-a-Service we help you keep the ICT supplier register and the remediation plan up to date.

Frequently asked questions

Does a bank carry out the risk-level assessment with DNSC?

No. The DNSC methodology excludes banking and financial market infrastructure entities subject to DORA from the assessment; they apply the DORA measures. Notification for registration with DNSC remains mandatory.

Is an insurance company covered by NIS2?

No, insurers are not in the NIS2 annexes. DORA applies to them, under ASF supervision.

Does our cloud provider have to comply with DORA?

Indirectly, through the contract: the bank imposes the DORA clauses. Directly, only if it is designated a critical ICT third-party service provider at European level. Separately, a medium-sized or large cloud provider is covered by NIS2, under digital infrastructure.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Regulation (EU) 2022/2554 (DORA) · DNSC Order No. 1/2026 (in Romanian).