Waste management is in Annex 2 to OUG 155/2024. Its standard score is the lowest of all sectors: 15 points for a small organisation, 30 for a medium-sized one and 45 for a large one. All of them stay below 100, so you apply the basic level: 34 controls and a threshold of 2.5 at self-assessment.
Who is covered by NIS2 in waste management
Annex 2 to OUG 155/2024 takes over the list in the NIS2 Directive, which refers to the definition in the Waste Framework Directive. It covers:
- companies collecting and transporting waste, including municipal sanitation operators;
- companies recovering waste, including sorting and recycling;
- operators of landfills and of treatment and disposal facilities;
- waste dealers and brokers;
- not covered: undertakings for which waste management is not the principal economic activity, for example a factory handing its waste to an authorised operator.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 15 | basic | 34 controls, threshold 2.5 |
| Medium | important | 30 | basic | 34 controls, threshold 2.5 |
| Large | important | 45 | basic | 34 controls, threshold 2.5 |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Waste management” sector already selected; you choose the size and answer 12 questions.
Calculate the level for waste managementWhich systems are assessed at a waste company
The business depends on traceability and on the documents accompanying each transport. The assessment usually covers:
- weighbridges and the weighing system at the entrance to the landfill or sorting plant;
- GPS fleet tracking and collection route planning;
- waste records and reporting to environmental authorities;
- invoicing clients and the relationship with city halls, through delegation contracts;
- automation of sorting lines and treatment facilities;
- office email and workstations.
Basic level does not mean no obligations
The low score reflects the DNSC assessment: a disruption in waste management has, on average, less impact than one in energy or health. But the legal obligations stay the same for any important entity: notification, the risk-level assessment, the self-assessment, reporting of significant incidents and the audit.
The difference is in volume. The basic level has 34 controls, against 218 at the essential level, and a threshold of 2.5 at self-assessment. In practice, a waste company starts with what exposes it most often: weak passwords and accounts without multi-factor authentication, unpatched systems and untested backups.
The score can rise. If you also operate in another sector, for example producing energy from waste or treating waste water for others, the highest score applies. A large company that also produces energy reaches 285, the essential level.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
For a waste company, the basic level allows a simple start. We start with:
- PenTest, external, showing what is exposed to the internet, with reports within 48 hours of the scan being completed;
- Proton Workspace, with physical security key authentication and Proton Pass for passwords, to sort out accounts and passwords in one place;
- SOC 24/7/365, when you want permanent detection and response without an in-house team.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a city hall’s sanitation company covered?
Yes, if it is medium-sized or large: waste collection is waste management, whoever owns the company.
I have the basic level. Do I still need an audit?
Yes. Essential and important entities go through a cybersecurity audit carried out by a DNSC-certified auditor, at intervals set according to the risk level.
The calculator shows the basic level even though we are a large company. Is that right?
Yes. The standard score of a large company in this sector is 45, below the 100 threshold. It changes only if you also operate in another sector or if DNSC validates other impact and probability values for you.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian).