Public administration is in Annex 1 to OUG 155/2024 and has the highest standard score of all sectors: 125 points. Unlike companies, an institution’s size is set by its average number of employees. And the first fine DNSC imposed, on 29 September 2026, targeted an institution in this very sector.
Which institutions are covered by NIS2
OUG 155/2024 defines a public administration entity as an authority or institution of public administration, an administrative-territorial unit, a body governed by public law or an association of these. From this broad category, the following are covered:
- automatically: central public administration entities, meaning ministries, agencies, authorities and other specialised bodies, which are essential entities regardless of size, under art. 5(1)(a);
- after identification: other public entities, if DNSC identifies them on the basis of the criteria in art. 9, for example if they are the sole provider of an essential service or if a disruption would have a significant impact on public safety.
City halls and county councils are not covered automatically. They can be covered through identification by DNSC or through the services they operate, each in its own sector: water supply, sewerage, district heating or waste management. Any entity can also register with DNSC voluntarily, regardless of size.
The NIS2 Directive excludes entities working in national security, public security, defence or law enforcement, as well as the judiciary, parliaments and central banks.
Which assurance level applies
| Average number of employees | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Up to 49 employees | essential | 125 | important | 133 controls, threshold 3 |
| 50–249 employees | essential | 250 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
| 250 employees or more | essential | 375 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
For public administration, the DNSC methodology sets the size factor by average number of employees: 1 up to 49 employees, 2 from 50 to 249 and 3 from 250 upwards. The average is calculated under Law No. 346/2004. The score can differ only if DNSC validates other impact and probability values for you.
Public administration has no basic level: even a small institution applies 133 controls, and from 50 employees, 218.
Find your level and maturity score in a few minutes. The calculator opens with the “Public administration” sector already selected; for size, choose by number of employees: small up to 49, medium from 50 to 249, large from 250.
Calculate the institution’s levelWhich systems are assessed in an institution
A central institution manages data on citizens and companies and services people use every day. The assessment usually covers:
- the national registers and databases the institution manages;
- portals for citizens and companies, online forms and payments;
- interconnections with other institutions, through web services and dedicated networks;
- the registry office and the document management system;
- institutional email and workstations, the usual target of phishing;
- applications built or maintained by external suppliers under public procurement contracts.
The first DNSC fine: what it sanctioned
On 29 September 2026, DNSC imposed the first fine under OUG 155/2024: RON 50,000, on a legal entity that is a specialised body of the central public administration, classified in the public administration sector. The institution’s name was not published.
The fine was not for an incident but because the institution did not meet the obligation to notify DNSC within the legal deadline. It is the simplest obligation in the OUG and the one that opens all the other steps: the DNSC decision, the risk-level assessment, the self-assessment and the audit.
For institutions, deadlines overlap with the budget cycle and public procurement. A pentest, a SOC service or an audit requires a procurement procedure, so they are worth planning from the start of the budget year.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
Institutions usually have few IT specialists and many legacy systems. We start with:
- PenTest, external, on the portals and services exposed to the public, with reports within 48 hours of the scan being completed;
- SOC 24/7/365, contracted as a service, without hiring an in-house monitoring team;
- Proton Workspace, for working documents and internal correspondence, encrypted in transit and at rest, with zero access.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a city hall covered by NIS2?
Not automatically. The annex targets central public administration. A city hall can be covered if DNSC identifies it on the basis of the criteria in the law, or through the services it operates directly, for example water supply. It can also register voluntarily.
The institution has fewer than 50 employees. What level does it have?
The important level: the standard score is 125, above the 100 threshold. You apply 133 controls, with a threshold of 3 at self-assessment.
How are an institution’s employees counted?
As the average number of persons employed, calculated under Law No. 346/2004. The thresholds are 50 and 250 employees.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Economica.net, the first DNSC fine, 30 September 2026 (in Romanian).