Banking and financial market infrastructure are the only Annex 1 sectors to which OUG 155/2024 applies only in part. Art. 2(3) states that entities subject to the DORA Regulation are covered only by arts. 5–10 and art. 18, meaning classification and registration. The DNSC methodology also exempts them from the risk-level assessment.
Who is in the NIS2 annex from the financial area
Annex 1 to OUG 155/2024 takes over the list in the NIS2 Directive. From the financial area, only three types of entity are covered, in two sectors:
- banking: credit institutions;
- financial market infrastructure: operators of trading venues, such as stock exchanges and multilateral trading facilities;
- financial market infrastructure: central counterparties.
Insurers, investment firms, payment institutions and e-money institutions do not appear in the NIS2 annexes. DORA applies to them directly, from 17 January 2025, supervised by the National Bank of Romania or the Financial Supervisory Authority (ASF), as applicable.
What applies from each act
For banks, trading venues and central counterparties, obligations are split between OUG 155/2024 and DORA. The DNSC methodology, as amended by Order No. 1/2026, states that banking and financial market infrastructure entities subject to DORA do not carry out the risk-level assessment and apply the DORA measures.
| Obligation | Where it comes from |
|---|---|
| Classification as an essential or important entity | OUG 155/2024, arts. 5–10 |
| Notification and registration with DNSC | OUG 155/2024, art. 18 |
| Risk-level assessment | not carried out: the DNSC methodology refers to DORA |
| Risk-management measures | DORA: the ICT risk-management framework |
| Incident reporting | DORA: major ICT-related incidents, to the financial supervisor |
| Testing | DORA: the digital operational resilience testing programme and, for designated entities, threat-led penetration testing at least every 3 years |
| ICT suppliers | DORA: the register of information on contracts and the mandatory contractual clauses |
DORA requires a testing programme. TRU PenTest tests the external and internal network every month, with CREST-accredited reports within 48 hours of the scan being completed.
See PenTestWhat the ICT risk-management framework covers
DORA covers all ICT systems that support the business. In practice, the assessment starts from critical or important functions and works down to:
- core banking, payments and connections to settlement systems;
- internet and mobile banking, with customer authentication;
- trading and clearing platforms;
- cloud services and ICT suppliers supporting critical or important functions;
- workstations, email and employees’ remote access;
- backups and continuity plans.
Are you an ICT supplier to a bank?
DORA reaches suppliers too. Financial entities keep a register of information on their contracts with ICT service providers and include mandatory clauses in those contracts: where data is processed, service levels, incident support, audit rights and exit conditions.
For an IT company, this means questionnaires, audits and tests requested by the client. And if the company is medium-sized or large and provides managed services, it is itself covered by NIS2, in the ICT service management sector.
The DNSC methodology exempts digital infrastructure and ICT service management providers from the risk-level assessment only if they are designated as critical ICT third-party service providers under DORA. All others carry out the assessment, like any entity in their sector.
What you need to do
- notification to DNSC, for entry in the register of essential and important entities, under art. 18 of OUG 155/2024; the first DNSC fine, of RON 50,000, sanctioned exactly a missing notification;
- the ICT risk-management framework, reporting of major incidents and the testing programme, under DORA;
- the register of information on ICT contracts, kept up to date and made available to the supervisor on request;
- the DORA clauses in new contracts and in contracts being renewed.
How TRU helps
For banks and their suppliers, we help mainly with testing and monitoring:
- PenTest, external and internal, with monthly testing and CREST-accredited reports within 48 hours of the scan being completed;
- SOC 24/7/365, for incident detection and for the data you need when reporting to the supervisor;
- Proton Workspace, for internal communication and communication with partners, encrypted in transit and at rest, with the encryption keys under your control.
Through CIO-as-a-Service we help you keep the ICT supplier register and the remediation plan up to date.
Frequently asked questions
Does a bank carry out the risk-level assessment with DNSC?
No. The DNSC methodology excludes banking and financial market infrastructure entities subject to DORA from the assessment; they apply the DORA measures. Notification for registration with DNSC remains mandatory.
Is an insurance company covered by NIS2?
No, insurers are not in the NIS2 annexes. DORA applies to them, under ASF supervision.
Does our cloud provider have to comply with DORA?
Indirectly, through the contract: the bank imposes the DORA clauses. Directly, only if it is designated a critical ICT third-party service provider at European level. Separately, a medium-sized or large cloud provider is covered by NIS2, under digital infrastructure.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Regulation (EU) 2022/2554 (DORA) · DNSC Order No. 1/2026 (in Romanian).