Before the self-assessment, every essential or important entity must know its risk level. It decides the assurance level: 34 controls at the basic level, 133 at the important level and 218 at the essential level. The calculation rule is in the methodology approved by DNSC Order No. 2/2025.
Timeline
| Step | Deadline | Legal basis |
|---|---|---|
| Notification to DNSC | 30 days from the date OUG 155/2024 becomes applicable to the entity | OUG, art. 18(2) |
| DNSC decision on identification and entry in the register | 60 days for essential entities and 150 days for important ones, from notification | OUG, art. 18(4)–(5) |
| Risk-level assessment | 60 days from the decision being communicated | OUG, art. 18(6) |
| First maturity self-assessment | 60 days from sending the risk-level assessment | OUG, art. 18(7) |
| Recalculating the score | every 3 years and whenever the impact exceeds the sector’s high threshold | DNSC Order No. 2/2025, art. 5(5) |
Deadlines matter. The first DNSC fine, RON 50,000 on 29 September 2026, penalised a failure to meet the notification deadline. The details are in our guide to NIS2 in Romania in 2026.
Where the assessment is done
The methodology provides two mechanisms: the NIS2@RO platform and the ENIRE@RO tool. The entity uses only one of them.
ENIRE@RO is downloaded from the DNSC websites and used locally. You use it when the NIS2@RO platform is unavailable or when you want a pre-assessment.
If you completed the assessment outside the platform because it was unavailable, you upload the report and supporting documents within 20 days of the platform becoming available. DNSC validates and confirms within 15 days of the upload.
How the score is calculated
The methodology looks at risk from the perspective of five types of attacker, in two groups:
- common-level capabilities: terrorists, ideologically motivated activists and hostile competitors;
- extended capabilities: cybercriminals and state actors.
For each type of attacker, five categories of attack are considered: sabotage or disruption of the service, information theft and espionage, cybercrime attacks, hacktivism and cyber vandalism, and attacks that target or affect the entity’s image.
For each combination, the risk value is obtained by multiplying four parameters:
- Entity size
- 1 for small and micro enterprises, 2 for medium-sized ones, 3 for large ones. In public administration, the average number of employees counts: up to 49, from 50 to 249, at least 250.
- Nature of the attack
- 1 for global, indiscriminate attacks and 2 for targeted attacks. DNSC sets the value for each sector and it cannot be changed.
- Impact
- 10 for high impact, 5 for medium and 0 for low, according to the service disruption criteria and thresholds in Annex 1 to the order.
- Probability
- 1 for high, 0.5 for medium and 0 for low.
Impact and probability values are predefined for each sector. The overall score is the sum of all risk values, for all types of attacker and all categories of attack.
Which level you get
| Overall score | Assurance level | At the self-assessment |
|---|---|---|
| 0–99 | Basic | 34 controls, maturity target 2.5 |
| 100–199 | Important | 133 controls, maturity target 3 |
| 200–1,500 | Essential | 218 controls, maturity target 3.5 and at least 3 in every category |
Article IV of DNSC Order No. 1/2026 requires entities to implement the controls of the assurance level that matches their risk level.
Standard scores by sector
With the standard sector values, the score depends only on the size of the organisation: for a medium-sized enterprise it is double the score of a small one, and for a large one, triple. The table shows the standard score and the resulting level.
| Sector | Small or micro | Medium | Large |
|---|---|---|---|
| Energy | 95 · basic | 190 · important | 285 · essential |
| Transport | 85 · basic | 170 · important | 255 · essential |
| Banking and financial market infrastructure | 85 · basic | 170 · important | 255 · essential |
| Health | 72.5 · basic | 145 · important | 217.5 · essential |
| Drinking water | 67.5 · basic | 135 · important | 202.5 · essential |
| Waste water | 67.5 · basic | 135 · important | 202.5 · essential |
| Digital infrastructure and ICT service management (B2B) | 95 · basic | 190 · important | 285 · essential |
| Public administration | 125 · important | 250 · essential | 375 · essential |
| Space | 87.5 · basic | 175 · important | 262.5 · essential |
| Postal and courier services | 50 · basic | 100 · important | 150 · important |
| Waste management | 15 · basic | 30 · basic | 45 · basic |
| Manufacture, production and distribution of chemicals | 60 · basic | 120 · important | 180 · important |
| Production, processing and distribution of food | 42.5 · basic | 85 · basic | 127.5 · important |
| Manufacturing | 57.5 · basic | 115 · important | 172.5 · important |
| Digital providers | 55 · basic | 110 · important | 165 · important |
| Research | 62.5 · basic | 125 · important | 187.5 · important |
The scores are those in the annex to the methodology. Your score can differ only if DNSC validates other impact and probability values for you.
You can work out your level for one or more sectors with the TRU NIS2 maturity calculator.
Special cases
- Several sectors: you assess the risk level separately for each sector and implement the level of measures matching the highest score.
- Values other than the standard ones: if impact or probability in your organisation differ from the sector values, you send DNSC an analysis with a sound justification for each value. If DNSC validates it, the score is calculated with the updated values.
- Recalculation: every 3 years and whenever the impact of a service disruption exceeds the sector’s high threshold. It is not needed if you already apply the highest level of measures. You may also recalculate when the impact falls below the threshold.
- DORA: banking and financial market infrastructure entities subject to Regulation (EU) 2022/2554 do not perform this assessment and apply the DORA requirements. The same applies to digital infrastructure and ICT service management entities designated as critical ICT third-party service providers under DORA.
The risk level is not the entity type
The entity type, essential or important, follows from OUG 155/2024, based on sector and size. The assurance level follows from the risk score. The two do not necessarily match:
- a large waste management company is an important entity, but its standard score is 45, so it has the basic level;
- a medium-sized provider of public electronic communications is an essential entity, but with the digital infrastructure standard score of 190 it has the important level;
- a public institution with 50–249 employees has a standard score of 250, so it has the essential level.
What comes after the assessment
Within 60 days of sending the risk-level assessment, you carry out the first maturity self-assessment against the controls of your level. We explain the steps in our guide to the NIS2 self-assessment (in Romanian).
The risk level also matters for the audit: OUG 155/2024 provides that the frequency of the cybersecurity audit is set according to the risk level. The details are in our guide to the NIS2 audit.
How TRU helps
Through CIO-as-a-Service we help you check your classification, prepare the analysis for non-standard values where needed and organise the self-assessment. Audits are performed by DNSC-certified auditors who are TRU partners. The details are on the NIS2 audit and compliance page.
For the encryption NIS2 requires, Proton Workspace natively protects data in transit and at rest, with zero-access encryption. The details are in our guide to NIS2 encryption with Proton Workspace.
Sources
DNSC Order No. 2/2025 · Methodology for assessing the risk level of entities · DNSC Order No. 1/2026 · OUG 155/2024, consolidated version (all in Romanian).