Energy is the first sector in Annex 1 to OUG 155/2024 and shares with digital infrastructure the highest standard score among private-sector sectors: 95 points for a small organisation. A medium-sized company reaches 190, the important level, and a large one 285, the essential level, with 218 controls at self-assessment.
Who is covered by NIS2 in energy
Energy has five subsectors in Annex 1, taken over from the NIS2 Directive:
- electricity: producers, transmission and distribution system operators, suppliers, nominated electricity market operators, market participants providing aggregation, demand response or energy storage services, and operators of recharging points that provide recharging services to end users;
- district heating and cooling: operators of district heating or district cooling;
- oil: operators of oil transmission pipelines, operators of oil production, refining, treatment, storage and transmission facilities, and central stockholding entities;
- natural gas: supply undertakings, distribution, transmission, storage and LNG system operators, natural gas undertakings and operators of refining and treatment facilities;
- hydrogen: operators of hydrogen production, storage and transmission.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 95 | basic | 34 controls, threshold 2.5 |
| Medium | important | 190 | important | 133 controls, threshold 3 |
| Large | essential | 285 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Energy” sector already selected; you choose the size and answer 12 questions.
Calculate the level for energyWhich systems are assessed, from the office to the substation
In an energy company, the assessment covers both the office network and the systems that run generation and the grid. It usually includes:
- SCADA and dispatch systems, substations and field automation;
- smart metering and remote reading systems;
- billing, the customer portal and the call centre;
- trading and generation and demand forecasting platforms;
- inverters and remote monitoring of solar and wind farms;
- equipment suppliers’ maintenance connections.
The attack on Electrica, December 2024
On 9 December 2024, the Electrica group announced a cyberattack, which DNSC attributed to the Lynx Ransomware group. According to the Ministry of Energy, the ransomware hit the IT systems of Distribuție Energie Electrică România, while the SCADA system stayed isolated and functional. DNSC confirmed that the systems critical for the power supply were not affected.
Separation made the difference. When the operational network is isolated from the office network, ransomware in IT means delayed invoices and a busy call centre, not customers without power.
DNSC then advised companies to scan their infrastructure for the malicious file, isolate affected systems, keep the ransom note and the logs, and restore from backups only after full clean-up. These are the measures NIS2 expects to be prepared in advance: an incident response plan, retained logs and tested backups.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
In energy, the priority is that an IT incident stays in IT. We usually start with:
- PenTest, external and internal, checking whether the office network can reach operational systems and what is exposed to the internet, with reports within 48 hours of the scan being completed; OT testing is planned separately, with the operator;
- SOC 24/7/365, which also watches the connections between IT and OT, including supplier access;
- Proton Workspace, for email and technical documentation, encrypted in transit and at rest, with zero access.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a solar farm covered by NIS2?
Yes, if the company operating it is medium-sized or large: electricity producers are in Annex 1. Size is set under Law No. 346/2004, which also takes partner and linked enterprises into account. A small project company within a large group should therefore be analysed carefully, not excluded by default.
Is an EV charging network covered?
Operators of recharging points providing recharging services to end users are in Annex 1, under electricity. What counts is the company responsible for managing and operating the charging points, and the size rule applies in the same way.
Is an energy supplier without its own grid covered?
Yes. Electricity and natural gas supply is in the annex even if the company owns no infrastructure. The assessment then focuses on billing, trading platforms and customer data.
Is the city’s district heating operator covered?
Yes, district heating operators are a subsector of energy. They are classified by the size of the company, whether it is private or owned by the local authority.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Agerpres, the attack on Electrica, 11 December 2024 (in Romanian).