Digital infrastructure and business-to-business ICT service management are in Annex 1 to OUG 155/2024 and share with energy the highest standard score among private-sector sectors: 95 points for a small organisation. It is also the sector with the most exceptions to the size rule: DNS service providers, TLD name registries and qualified trust service providers are essential entities even when they are small.
Who is covered by NIS2 in digital infrastructure and ICT services
Annex 1 to OUG 155/2024 takes over the list in the NIS2 Directive, in two sectors with the same standard score:
- digital infrastructure: internet exchange point providers; DNS service providers, excluding operators of root name servers; TLD name registries; cloud computing service providers; data centre service providers; content delivery network providers; trust service providers; providers of public electronic communications networks and of publicly available electronic communications services;
- ICT service management (business-to-business): managed service providers and managed security service providers.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | only the providers in the table below | 95 | basic | 34 controls, threshold 2.5 |
| Medium | important; essential for public electronic communications | 190 | important | 133 controls, threshold 3 |
| Large | essential | 285 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
The DNSC methodology exempts providers in these two sectors from the risk-level assessment only if they are designated as critical ICT third-party service providers under DORA. All others carry out the assessment, with a standard score of 95.
Find your level and maturity score in a few minutes. The calculator opens with the “Digital infrastructure and ICT service management (B2B)” sector already selected; you choose the size and answer 12 questions.
Calculate the level for digital servicesWhat is assessed at a digital service provider
For an infrastructure or managed service provider, the assessment covers the platform you offer clients and the tools you use to run it:
- the infrastructure management platform: hypervisors, orchestration and cloud consoles;
- the remote management and monitoring tools used at clients;
- engineers’ privileged accounts and their authentication;
- the data centre: physical access, power, cooling and building management systems;
- DNS servers, signing and certificate management systems;
- the client portal, billing and the ticketing system.
Who is covered regardless of size
In this sector, the size rule has the most exceptions. The entity type depends on the service provided:
| Provider type | Entity type |
|---|---|
| DNS service provider | essential, regardless of size |
| Top-level domain (TLD) name registry | essential, regardless of size |
| Qualified trust service provider | essential, regardless of size |
| Other trust service provider | at least important, regardless of size |
| Provider of public electronic communications networks or publicly available services | at least important, regardless of size; essential from medium size |
| Cloud, data centres, content delivery networks, internet exchange points, managed services | the usual rule: important if medium-sized, essential if large |
For cloud, data centres, DNS, TLD, content delivery networks, trust services and managed services, the European Commission set out the technical requirements in Implementing Regulation (EU) 2024/2690, which applies directly. It is worth reading alongside the DNSC controls, because it goes into detail on testing, vulnerability handling and the criteria for significant incidents.
For managed service providers there is also an old lesson: in July 2021, attackers compromised Kaseya VSA, remote management software used by such providers, and through it encrypted the systems of up to 1,500 client companies. The access you have to clients is a risk for them, and clients that are NIS2 entities will assess it.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
We work as a managed security service provider ourselves, so we know what clients ask of their suppliers. We usually start with:
- PenTest, external and internal, on the management platform and client access, with CREST-accredited reports within 48 hours of the scan being completed;
- SOC 24/7/365, monitoring privileged accounts and remote management tools;
- Proton Workspace, for communication with clients and technical documentation, encrypted in transit and at rest, with the encryption keys under your control.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a small IT integrator covered by NIS2?
As a rule, no: managed service providers are covered if they are medium-sized or large companies. Your clients that are NIS2 entities will still require security measures through the contract, because supply-chain security is a mandatory measure for them.
Is a web hosting company covered?
It depends on what it offers. Virtual servers and on-demand storage are usually cloud computing services, and colocation in its own data centre is a data centre service. Both are covered if the company is medium-sized or large.
Do domain name registrars have obligations?
The NIS2 Directive requires TLD registries and entities providing domain name registration services to keep an accurate and complete database of registration data, regardless of size.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Implementing Regulation (EU) 2024/2690 · RCP Magazine, the attack on Kaseya VSA, July 2021.