Public administration is in Annex 1 to OUG 155/2024 and has the highest standard score of all sectors: 125 points. Unlike companies, an institution’s size is set by its average number of employees. And the first fine DNSC imposed, on 29 September 2026, targeted an institution in this very sector.

Which institutions are covered by NIS2

OUG 155/2024 defines a public administration entity as an authority or institution of public administration, an administrative-territorial unit, a body governed by public law or an association of these. From this broad category, the following are covered:

City halls and county councils are not covered automatically. They can be covered through identification by DNSC or through the services they operate, each in its own sector: water supply, sewerage, district heating or waste management. Any entity can also register with DNSC voluntarily, regardless of size.

The NIS2 Directive excludes entities working in national security, public security, defence or law enforcement, as well as the judiciary, parliaments and central banks.

Which assurance level applies

Average number of employeesEntity typeStandard risk scoreAssurance levelAt self-assessment
Up to 49 employeesessential125important133 controls, threshold 3
50–249 employeesessential250essential218 controls, threshold 3.5 and at least 3 in every category
250 employees or moreessential375essential218 controls, threshold 3.5 and at least 3 in every category

For public administration, the DNSC methodology sets the size factor by average number of employees: 1 up to 49 employees, 2 from 50 to 249 and 3 from 250 upwards. The average is calculated under Law No. 346/2004. The score can differ only if DNSC validates other impact and probability values for you.

Public administration has no basic level: even a small institution applies 133 controls, and from 50 employees, 218.

Find your level and maturity score in a few minutes. The calculator opens with the “Public administration” sector already selected; for size, choose by number of employees: small up to 49, medium from 50 to 249, large from 250.

Calculate the institution’s level

Which systems are assessed in an institution

A central institution manages data on citizens and companies and services people use every day. The assessment usually covers:

The first DNSC fine: what it sanctioned

On 29 September 2026, DNSC imposed the first fine under OUG 155/2024: RON 50,000, on a legal entity that is a specialised body of the central public administration, classified in the public administration sector. The institution’s name was not published.

The fine was not for an incident but because the institution did not meet the obligation to notify DNSC within the legal deadline. It is the simplest obligation in the OUG and the one that opens all the other steps: the DNSC decision, the risk-level assessment, the self-assessment and the audit.

For institutions, deadlines overlap with the budget cycle and public procurement. A pentest, a SOC service or an audit requires a procurement procedure, so they are worth planning from the start of the budget year.

What comes next

How TRU helps

Institutions usually have few IT specialists and many legacy systems. We start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a city hall covered by NIS2?

Not automatically. The annex targets central public administration. A city hall can be covered if DNSC identifies it on the basis of the criteria in the law, or through the services it operates directly, for example water supply. It can also register voluntarily.

The institution has fewer than 50 employees. What level does it have?

The important level: the standard score is 125, above the 100 threshold. You apply 133 controls, with a threshold of 3 at self-assessment.

How are an institution’s employees counted?

As the average number of persons employed, calculated under Law No. 346/2004. The thresholds are 50 and 250 employees.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Economica.net, the first DNSC fine, 30 September 2026 (in Romanian).