Before the self-assessment, every essential or important entity must know its risk level. It decides the assurance level: 34 controls at the basic level, 133 at the important level and 218 at the essential level. The calculation rule is in the methodology approved by DNSC Order No. 2/2025.

Timeline

Deadlines matter. The first DNSC fine, RON 50,000 on 29 September 2026, penalised a failure to meet the notification deadline. The details are in our guide to NIS2 in Romania in 2026.

Where the assessment is done

The methodology provides two mechanisms: the NIS2@RO platform and the ENIRE@RO tool. The entity uses only one of them.

ENIRE@RO is downloaded from the DNSC websites and used locally. You use it when the NIS2@RO platform is unavailable or when you want a pre-assessment.

If you completed the assessment outside the platform because it was unavailable, you upload the report and supporting documents within 20 days of the platform becoming available. DNSC validates and confirms within 15 days of the upload.

How the score is calculated

The methodology looks at risk from the perspective of five types of attacker, in two groups:

For each type of attacker, five categories of attack are considered: sabotage or disruption of the service, information theft and espionage, cybercrime attacks, hacktivism and cyber vandalism, and attacks that target or affect the entity’s image.

For each combination, the risk value is obtained by multiplying four parameters:

Entity size
1 for small and micro enterprises, 2 for medium-sized ones, 3 for large ones. In public administration, the average number of employees counts: up to 49, from 50 to 249, at least 250.
Nature of the attack
1 for global, indiscriminate attacks and 2 for targeted attacks. DNSC sets the value for each sector and it cannot be changed.
Impact
10 for high impact, 5 for medium and 0 for low, according to the service disruption criteria and thresholds in Annex 1 to the order.
Probability
1 for high, 0.5 for medium and 0 for low.

Impact and probability values are predefined for each sector. The overall score is the sum of all risk values, for all types of attacker and all categories of attack.

Which level you get

Article IV of DNSC Order No. 1/2026 requires entities to implement the controls of the assurance level that matches their risk level.

Standard scores by sector

With the standard sector values, the score depends only on the size of the organisation: for a medium-sized enterprise it is double the score of a small one, and for a large one, triple. The table shows the standard score and the resulting level.

The scores are those in the annex to the methodology. Your score can differ only if DNSC validates other impact and probability values for you.

You can work out your level for one or more sectors with the TRU NIS2 maturity calculator.

Special cases

The risk level is not the entity type

The entity type, essential or important, follows from OUG 155/2024, based on sector and size. The assurance level follows from the risk score. The two do not necessarily match:

What comes after the assessment

Within 60 days of sending the risk-level assessment, you carry out the first maturity self-assessment against the controls of your level. We explain the steps in our guide to the NIS2 self-assessment (in Romanian).

The risk level also matters for the audit: OUG 155/2024 provides that the frequency of the cybersecurity audit is set according to the risk level. The details are in our guide to the NIS2 audit.

How TRU helps

Through CIO-as-a-Service we help you check your classification, prepare the analysis for non-standard values where needed and organise the self-assessment. Audits are performed by DNSC-certified auditors who are TRU partners. The details are on the NIS2 audit and compliance page.

For the encryption NIS2 requires, Proton Workspace natively protects data in transit and at rest, with zero-access encryption. The details are in our guide to NIS2 encryption with Proton Workspace.

Sources

DNSC Order No. 2/2025 · Methodology for assessing the risk level of entities · DNSC Order No. 1/2026 · OUG 155/2024, consolidated version (all in Romanian).