Digital infrastructure and business-to-business ICT service management are in Annex 1 to OUG 155/2024 and share with energy the highest standard score among private-sector sectors: 95 points for a small organisation. It is also the sector with the most exceptions to the size rule: DNS service providers, TLD name registries and qualified trust service providers are essential entities even when they are small.

Who is covered by NIS2 in digital infrastructure and ICT services

Annex 1 to OUG 155/2024 takes over the list in the NIS2 Directive, in two sectors with the same standard score:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microonly the providers in the table below95basic34 controls, threshold 2.5
Mediumimportant; essential for public electronic communications190important133 controls, threshold 3
Largeessential285essential218 controls, threshold 3.5 and at least 3 in every category

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

The DNSC methodology exempts providers in these two sectors from the risk-level assessment only if they are designated as critical ICT third-party service providers under DORA. All others carry out the assessment, with a standard score of 95.

Find your level and maturity score in a few minutes. The calculator opens with the “Digital infrastructure and ICT service management (B2B)” sector already selected; you choose the size and answer 12 questions.

Calculate the level for digital services

What is assessed at a digital service provider

For an infrastructure or managed service provider, the assessment covers the platform you offer clients and the tools you use to run it:

Who is covered regardless of size

In this sector, the size rule has the most exceptions. The entity type depends on the service provided:

Provider typeEntity type
DNS service provideressential, regardless of size
Top-level domain (TLD) name registryessential, regardless of size
Qualified trust service provideressential, regardless of size
Other trust service providerat least important, regardless of size
Provider of public electronic communications networks or publicly available servicesat least important, regardless of size; essential from medium size
Cloud, data centres, content delivery networks, internet exchange points, managed servicesthe usual rule: important if medium-sized, essential if large

For cloud, data centres, DNS, TLD, content delivery networks, trust services and managed services, the European Commission set out the technical requirements in Implementing Regulation (EU) 2024/2690, which applies directly. It is worth reading alongside the DNSC controls, because it goes into detail on testing, vulnerability handling and the criteria for significant incidents.

For managed service providers there is also an old lesson: in July 2021, attackers compromised Kaseya VSA, remote management software used by such providers, and through it encrypted the systems of up to 1,500 client companies. The access you have to clients is a risk for them, and clients that are NIS2 entities will assess it.

What comes next

How TRU helps

We work as a managed security service provider ourselves, so we know what clients ask of their suppliers. We usually start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a small IT integrator covered by NIS2?

As a rule, no: managed service providers are covered if they are medium-sized or large companies. Your clients that are NIS2 entities will still require security measures through the contract, because supply-chain security is a mandatory measure for them.

Is a web hosting company covered?

It depends on what it offers. Virtual servers and on-demand storage are usually cloud computing services, and colocation in its own data centre is a data centre service. Both are covered if the company is medium-sized or large.

Do domain name registrars have obligations?

The NIS2 Directive requires TLD registries and entities providing domain name registration services to keep an accurate and complete database of registration data, regardless of size.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Implementing Regulation (EU) 2024/2690 · RCP Magazine, the attack on Kaseya VSA, July 2021.