Drinking water is in Annex 1 to OUG 155/2024, among the sectors of high criticality. The standard score is 67.5 for a small organisation, 135 for a medium-sized one and 202.5 for a large one. The gap between the last two matters: the medium-sized operator applies 133 controls, the large one 218.

Who is covered by NIS2 in drinking water

Annex 1 to OUG 155/2024 takes over the wording of the NIS2 Directive. The drinking water sector covers:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law67.5basic34 controls, threshold 2.5
Mediumimportant135important133 controls, threshold 3
Largeessential202.5essential218 controls, threshold 3.5 and at least 3 in every category

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Find your level and maturity score in a few minutes. The calculator opens with the “Drinking water” sector already selected; you choose the size and answer 12 questions.

Calculate the level for drinking water

Which systems are assessed at a water operator

At a water operator, operational systems are spread over tens or hundreds of kilometres. They usually include:

What the attack on Romanian Waters shows

On 20 December 2025, the National Administration Romanian Waters (Apele Române) was hit by a ransomware attack. DNSC reported around 1,000 compromised systems, including in 10 of the 11 river basin administrations: GIS application and database servers, email, web and DNS servers, and Windows servers and workstations. The attackers used BitLocker, the encryption feature built into Windows, to encrypt the files.

Romanian Waters is not a drinking water operator; it manages water resources and hydraulic structures. The lesson applies directly, though: the hydraulic structures kept working normally, operated locally by staff, and the institution’s network was not covered by the national system protecting critical infrastructure.

For a water operator, this means three things: manual operating procedures must be rehearsed, not just written; administrator accounts must be limited, so that an attacker cannot launch encryption on every server; and backups must be kept separate from the Windows domain.

What comes next

How TRU helps

Water operators usually have small IT teams and old operational systems. We start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

The regional operator runs both water and sewerage. What score applies?

You assess each sector separately. Drinking water and waste water have the same standard score, 67.5 for a small organisation. The highest score applies, so the result does not change, but the inventory must cover both activities.

Do field pumping stations go into the inventory?

Yes. Every connected controller, every modem and every remote access account belongs in the asset inventory required by art. 13(f) of OUG 155/2024. Without an inventory, you cannot show at the audit that you control them.

Who carries out the NIS2 audit of a water operator?

A cybersecurity auditor certified by DNSC. We work with DNSC-certified auditors who are TRU partners; you sign the audit contract directly with the auditor.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · The Register, the attack on Romanian Waters, 22 December 2025.