Solutions /AUDIT AND COMPLIANCE · NIS2

NIS2 in Romania.
From self‑assessment and audit to compliance.

Estimate your maturity level for free, complete the audit with a DNSC-certified auditor partnered with TRU, and implement the measures with TRU solutions.

Discuss NIS2 compliance Calculate your maturity score

Updated

HOW IT WORKS

Five steps,
each with its deadline.

The obligations come from Emergency Ordinance 155/2024 and DNSC Order No. 1/2026 and apply to essential and important entities in Romania. Deadlines matter: the first DNSC fine, RON 50,000 on 29 September 2026, penalised a failure to meet the notification deadline. More about the fine

  1. 01

    Notification to DNSC

    Within 30 days of the date the ordinance becomes applicable to the entity.

  2. 02

    Risk level

    The risk-level assessment produces a score that sets the assurance level: basic, important or essential. How it is calculated

  3. 03

    Self-assessment

    Annual and endorsed by management; the first one within 60 days of submitting the risk-level assessment.

  4. 04

    Audit

    Performed by a DNSC-certified auditor, at the frequency DNSC sets according to the risk level.

  5. 05

    Remediation plan

    Actions and deadlines for the gaps found in the self-assessment or the audit.

WHAT WE OFFER

Every role
in its place.

An independent auditor performs the audit. TRU provides management support and the technology for the measures.

01

Maturity calculator

Free, on this page. Find your assurance level and, in a few minutes, see how ready you are before the official self-assessment.

Calculate your score
02

NIS2 audit through partners

Audits are performed by DNSC-certified auditors partnered with TRU, under a direct contract with the auditor. The partner auditor also supports you in dealing with DNSC on the audit.

Request an audit
03

CIO-as-a-Service for NIS2

Support for the self-assessment, the remediation plan and high-level technical challenges: priorities, budgets, responsibilities and suppliers.

About CIO-as-a-Service
04

Solutions for the measures

PenTest for vulnerability assessment, 24/7/365 SOC for detection and response, Proton Workspace for the encryption NIS2 requires: data encrypted in transit and at rest, with zero-access encryption and the keys under your control.

DNSC ORDER NO. 1/2026

Where each service contributes.

The order groups the controls into six functions. TRU services contribute to the measures; compliance remains the entity’s responsibility.

FunctionTRU contribution
GovernCIO-as-a-Service: strategy, policies, roles and supplier relationships.
IdentifyPenTest for vulnerability assessment; CIO-as-a-Service for asset inventory and risk assessment.
ProtectProton Workspace for encrypting data in transit and at rest, with zero-access encryption; CIO-as-a-Service for access policies.
Detect24/7/365 SOC: continuous monitoring and event analysis.
RespondSOC: incident analysis and escalation, within the agreed scope.
RecoverCIO-as-a-Service for continuity and recovery plans.
FREE CALCULATOR

How ready are you
for NIS2?

Three steps, in a few minutes: find your assurance level from your sector and organisation size (DNSC Order No. 2/2025), answer 12 simple questions, then see your estimated score on the DNSC scale, from 1 to 5, against the target for your level.

The result is indicative: the quick check is written by TRU and does not reproduce the requirements of the official self-assessment. Your answers stay in your browser; they reach us only if you send them to us through the form. The official self-assessment is completed in the NIS2@RO platform or, if it is unavailable, with the DNSC EVAL_MMS tools.

WHY THROUGH PARTNERS

The auditor stays independent.

Cybersecurity audits may only be performed by auditors holding a valid DNSC certificate. The law does not allow an audit by anyone currently providing security services to the entity or who had a contract for the audited system in the last year.

That is why TRU does not audit: it provides the technology and support for the measures, while the audit is performed by a DNSC-certified auditor partnered with TRU, under a direct contract with you.

After the audit, the entity submits the results to DNSC within 5 days and the remediation plan within 15 working days of receiving the report.

FREQUENTLY ASKED QUESTIONS

The details
that matter.

How do I find out my assurance level?

Through the risk-level assessment, done in the NIS2@RO platform or with the DNSC ENIRE@RO tool. The overall score sets the level: 0–99 basic, 100–199 important, 200–1,500 essential. The score starts from the standard values of your sector, multiplied according to your organisation’s size, and the calculator on this page works it out from these two criteria in its first step. The details are in our guide to the NIS2 risk level.

Who can perform the NIS2 audit?

Only cybersecurity auditors holding a valid DNSC certificate. TRU works with DNSC-certified auditors partnered with TRU, and the audit contract is signed directly with the auditor.

Can my SOC or PenTest provider perform the audit?

No. The law does not allow an audit by an auditor currently providing security services to the entity or who had a contract for the audited system in the last year.

Does the calculator replace the official self-assessment?

No. It is a quick, indicative check with 12 questions written by TRU. The assurance level is calculated with the DNSC rule, and the score is shown on the same 1–5 scale and compared with the same target. The official score may differ, because it is calculated for each requirement. The official self-assessment is completed in NIS2@RO or with the DNSC EVAL_MMS tools and is endorsed by the entity’s management.

What if I do not reach the target scores?

You prepare a remediation plan with actions and deadlines. Essential entities submit it to DNSC within 30 days of the self-assessment. CIO-as-a-Service can help you build and track it.

How does TRU help after the audit?

Through CIO-as-a-Service for prioritising and coordinating the remediation plan, and through the solutions for the measures: PenTest, 24/7/365 SOC and Proton Workspace.

What does Proton Workspace cover of the NIS2 requirements?

Proton Workspace natively covers the NIS2 encryption requirements: data encrypted in transit and at rest with zero-access encryption, traffic encrypted through a VPN, encryption keys under your control, sign-in with a physical security key and Proton Pass for passwords. No premium licences and no separate configuration. At Microsoft 365 and Google Workspace, data is encrypted, but the provider holds the keys. Your own keys require the top-tier plans. The details are in our guide to the encryption NIS2 requires.

Does TRU certify NIS2 compliance?

No. TRU provides management support and the technology for the measures. A DNSC-certified auditor performs the audit, and compliance remains the entity’s responsibility.

NEXT STEP

Let’s discuss your company’s needs.

Tell us your assurance level and where you are with the self-assessment. We will agree the right starting point.

Discuss NIS2 compliance