Chemical sector: 4.40 out of 5 on web and e-mail filtering. What comes next under NIS2

Cyber maturity score 4.40 out of 5 for the chemical sector, CyFun control PR.PS-05.1

Romania’s National Cyber Security Directorate (DNSC) has published the cyber maturity score of the Romanian chemical sector for CyFun® control PR.PS-05.1: 4.40 out of 5. It is one of the strongest sector results in the series of measurements carried out under the PNRR 184 project, and the control assessed is about as concrete as they come: web and e-mail filters must be installed and used.

The figure deserves careful reading, in both directions. It confirms that the chemical industry has invested in the layer of defence that stops the most common attack vectors. It says very little about the distance still to cover towards compliance with GEO no. 155/2024, and that difference costs money when an inspection arrives.

What DNSC actually measured

Under the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, 1,599 beneficiaries from the public and private sectors assessed their own cyber maturity on the SecureRO platform, using the CyberFundamentals (CyFun®) framework developed by the Centre for Cybersecurity Belgium.

Two qualifications change how the result should be read. First, this is a self-assessment, not an audit. No evidence was requested for the answers given, and field experience consistently shows that declared scores are more generous than what can be verified. Second, CyFun® is not Romania’s compliance framework. It is a useful working instrument, conceptually aligned with NIS2, but the legal obligation is measured against GEO no. 155/2024, approved with amendments by Law no. 124/2025, and against the orders issued by DNSC under it.

A 4.40 out of 5 on a single technical control is a good signal. It is not a statement of compliance.

What control PR.PS-05.1 requires

The control text is short: “Web and e-mail filters must be installed and used.” Its stated objective is to reduce the risk of malware infection, phishing attacks and data breaches through the implementation and maintenance of effective web and e-mail filtering solutions.

The word that separates a score of 3 from a score of 5 is “maintenance”. An e-mail gateway bought in 2021 and left on its default configuration ticks the box for having a solution, not for its effectiveness. Real maturity looks different:

  • filtering applied to every flow, including shared mailboxes, office@ addresses and accounts used by applications;
  • sender authentication fully configured: SPF, DKIM and DMARC in reject mode, not merely monitoring;
  • attachments and links inspected at the time of access, not only at delivery;
  • web filtering that also covers endpoints outside the corporate network;
  • rules reviewed periodically, with logs retained and actually examined, not merely generated;
  • exceptions documented, each with an expiry date and an owner, rather than accumulated on request.

In a chemical company, filtering carries an additional stake. E-mail is how orders, safety data sheets, customs documents and correspondence with suppliers of regulated substances arrive. A forged message that changes a bank account, or an altered safety data sheet, produces more than a financial loss, it produces process risk.

Where a good technical score stops

The chemical sector appears in the annexes of GEO no. 155/2024, and entities above the qualifying thresholds fall into the essential or important category. The obligations that follow are not covered by e-mail filters.

In practice, an entity in the sector has an administrative path with its own steps and deadlines:

  • self-assessment of disruptive effect, governed by art. 9 of GEO no. 155/2024, for which DNSC has published a dedicated guide;
  • notification for registration, generated with the NIS2@RO tool, signed by the legal representative and sent to [email protected] or filed at DNSC headquarters;
  • risk level assessment using the ENIRE@RO tool, whose score, once validated by DNSC, sets the applicable level: Basic, Important or Essential;
  • self-assessment of the maturity of risk management measures, required by art. 18 para. (7), using the instrument matching the resulting level;
  • the substantive measures: governance, risk analysis, incident handling, business continuity, supply chain security, access control, cryptography, management training.

That last point is what catches out companies with solid technical infrastructure. The filters work, but the approved policy, the responsibility matrix, the incident register, the tested response plan and the evidence that the management body was trained are all missing. At an inspection, the documents are what is asked for.

Three checks that reveal the real score

First: send a test message with a harmless attachment carrying a double extension to a shared company address, not to the CTO’s mailbox. If it arrives, filtering covers only the main flow.

Second: check the domain’s DMARC record. If the policy is “none”, anyone can send messages in the company’s name without them being rejected. It is the cheapest control on the list and the one most often left half-finished.

Third: ask for the list of active exceptions in the filtering solution. If nobody can produce it the same day, the control is not being maintained, whatever the self-assessment says.

Supervision is no longer hypothetical

Through Order no. 3 of 27 November 2025, the DNSC director approved the rules for supervising, verifying and enforcing compliance with GEO no. 155/2024, together with the risk-based methodology for prioritising those activities. The supervisory framework exists, is public and operates on risk criteria, which means entities with a high risk level and thin documentation reach the authority’s attention first.

Where to start

The first useful step is not buying a solution, but establishing scope precisely. The CysNis platform walks through the qualifying criteria step by step and separates legal obligations from technical recommendations.

To measure the distance between the current state and the legal requirements, the next step is a NIS2 compliance analysis with a remediation plan. ProDefence is a NIS auditor accredited by DNSC, and the assessment is built on evidence rather than declarations. Organisations without an internal owner for the process can cover the role through an outsourced NIS2 officer, accountable for deadlines, documentation and the relationship with the authority. The rest of the work is listed in the cybersecurity services register.

A 4.40 out of 5 on filtering is a good starting point. The rest still has to be demonstrated.

Data source: DNSC, “Cyber maturity score for Romania’s chemical sector, CyFun® control PR.PS-05.1”, 11 September 2026.

Skip to content