Energy is the first sector in Annex 1 to OUG 155/2024 and shares with digital infrastructure the highest standard score among private-sector sectors: 95 points for a small organisation. A medium-sized company reaches 190, the important level, and a large one 285, the essential level, with 218 controls at self-assessment.

Who is covered by NIS2 in energy

Energy has five subsectors in Annex 1, taken over from the NIS2 Directive:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law95basic34 controls, threshold 2.5
Mediumimportant190important133 controls, threshold 3
Largeessential285essential218 controls, threshold 3.5 and at least 3 in every category

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Find your level and maturity score in a few minutes. The calculator opens with the “Energy” sector already selected; you choose the size and answer 12 questions.

Calculate the level for energy

Which systems are assessed, from the office to the substation

In an energy company, the assessment covers both the office network and the systems that run generation and the grid. It usually includes:

The attack on Electrica, December 2024

On 9 December 2024, the Electrica group announced a cyberattack, which DNSC attributed to the Lynx Ransomware group. According to the Ministry of Energy, the ransomware hit the IT systems of Distribuție Energie Electrică România, while the SCADA system stayed isolated and functional. DNSC confirmed that the systems critical for the power supply were not affected.

Separation made the difference. When the operational network is isolated from the office network, ransomware in IT means delayed invoices and a busy call centre, not customers without power.

DNSC then advised companies to scan their infrastructure for the malicious file, isolate affected systems, keep the ransom note and the logs, and restore from backups only after full clean-up. These are the measures NIS2 expects to be prepared in advance: an incident response plan, retained logs and tested backups.

What comes next

How TRU helps

In energy, the priority is that an IT incident stays in IT. We usually start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a solar farm covered by NIS2?

Yes, if the company operating it is medium-sized or large: electricity producers are in Annex 1. Size is set under Law No. 346/2004, which also takes partner and linked enterprises into account. A small project company within a large group should therefore be analysed carefully, not excluded by default.

Is an EV charging network covered?

Operators of recharging points providing recharging services to end users are in Annex 1, under electricity. What counts is the company responsible for managing and operating the charging points, and the size rule applies in the same way.

Is an energy supplier without its own grid covered?

Yes. Electricity and natural gas supply is in the annex even if the company owns no infrastructure. The assessment then focuses on billing, trading platforms and customer data.

Is the city’s district heating operator covered?

Yes, district heating operators are a subsector of energy. They are classified by the size of the company, whether it is private or owned by the local authority.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Agerpres, the attack on Electrica, 11 December 2024 (in Romanian).