Drinking water is in Annex 1 to OUG 155/2024, among the sectors of high criticality. The standard score is 67.5 for a small organisation, 135 for a medium-sized one and 202.5 for a large one. The gap between the last two matters: the medium-sized operator applies 133 controls, the large one 218.
Who is covered by NIS2 in drinking water
Annex 1 to OUG 155/2024 takes over the wording of the NIS2 Directive. The drinking water sector covers:
- suppliers and distributors of water intended for human consumption, meaning the operators of the water supply service: regional operators, municipal companies and private companies operating the service under a concession;
- operators that produce drinking water and deliver it to other operators;
- not covered: distributors for which distributing water for human consumption is a non-essential part of their general activity of distributing other goods.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 67.5 | basic | 34 controls, threshold 2.5 |
| Medium | important | 135 | important | 133 controls, threshold 3 |
| Large | essential | 202.5 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Drinking water” sector already selected; you choose the size and answer 12 questions.
Calculate the level for drinking waterWhich systems are assessed at a water operator
At a water operator, operational systems are spread over tens or hundreds of kilometres. They usually include:
- the central dispatch and the SCADA system monitoring intakes, treatment plants and reservoirs;
- pumping stations and field controllers, connected over mobile or radio networks;
- chemical dosing and water quality analysers;
- metering, remote reading and billing;
- customer relations: the online portal, payments and the call centre;
- remote access by integrators and automation suppliers.
What the attack on Romanian Waters shows
On 20 December 2025, the National Administration Romanian Waters (Apele Române) was hit by a ransomware attack. DNSC reported around 1,000 compromised systems, including in 10 of the 11 river basin administrations: GIS application and database servers, email, web and DNS servers, and Windows servers and workstations. The attackers used BitLocker, the encryption feature built into Windows, to encrypt the files.
Romanian Waters is not a drinking water operator; it manages water resources and hydraulic structures. The lesson applies directly, though: the hydraulic structures kept working normally, operated locally by staff, and the institution’s network was not covered by the national system protecting critical infrastructure.
For a water operator, this means three things: manual operating procedures must be rehearsed, not just written; administrator accounts must be limited, so that an attacker cannot launch encryption on every server; and backups must be kept separate from the Windows domain.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
Water operators usually have small IT teams and old operational systems. We start with:
- PenTest, external, showing whether dispatch, controllers or remote access are visible from the internet, with reports within 48 hours of the scan being completed;
- SOC 24/7/365, which supports the in-house IT team at night and at weekends;
- Proton Workspace, for email and operational documents, encrypted in transit and at rest, with zero access.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
The regional operator runs both water and sewerage. What score applies?
You assess each sector separately. Drinking water and waste water have the same standard score, 67.5 for a small organisation. The highest score applies, so the result does not change, but the inventory must cover both activities.
Do field pumping stations go into the inventory?
Yes. Every connected controller, every modem and every remote access account belongs in the asset inventory required by art. 13(f) of OUG 155/2024. Without an inventory, you cannot show at the audit that you control them.
Who carries out the NIS2 audit of a water operator?
A cybersecurity auditor certified by DNSC. We work with DNSC-certified auditors who are TRU partners; you sign the audit contract directly with the auditor.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · The Register, the attack on Romanian Waters, 22 December 2025.