Financial market infrastructure: 4.83 out of 5 on backups. The best DNSC score and what still needs proving
Romania’s financial market infrastructure scored 4.83 out of 5 on CyFun® control PR.DS-11.1, the strongest result in the entire DNSC series. The control requires business-critical data to be backed up and stored on a system separate from the one holding the original data, precisely so that it survives loss, system failure and ransomware.
The score is no surprise. This is the only sector in the series where separate backups were already a regulatory requirement rather than a good practice. The useful question is not how the sector reached 4.83, but what remains to be demonstrated beyond this control.
What was measured
The data comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, under which 1,599 public and private beneficiaries self-assessed on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium. DNSC’s conclusion: the high level indicates a good capacity to protect critical data through secure, separate backups, supporting operational resilience and rapid recovery.
The difference between holding copies and being able to return
Control PR.DS-11.1 verifies that copies exist and are separated. It does not verify restoration. That distinction decides, in real incidents, between an outage of hours and one of days. The questions a 4.83 leaves open:
- when the last full restoration was performed on a separate system, timed and recorded;
- how long the service itself takes to return, not how long files take to copy, including rebuilding dependencies and verifying data integrity;
- whether a copy exists that is unreachable from the network and immutable, surviving an attacker holding administrative rights;
- whether the encryption keys for the copies are held somewhere other than the protected system;
- whether the person able to run the restoration is available outside working hours, and whether the procedure works without them;
- whether suppliers hosting parts of the service keep verified copies of their own, with a contractual duty to prove it.
A documented restoration exercise, run at least annually, turns a declared score into evidence. Without it, the figure remains an intention.
Which legal regime actually applies
Here the financial sector has a particularity the others do not. The NIS2 Directive provides that where a sector-specific EU act imposes at least equivalent requirements, that act applies instead of the general regime. For financial entities, that act is Regulation (EU) 2022/2554 on digital operational resilience, applicable since January 2025, covering ICT risk management, incident reporting, resilience testing and oversight of critical third-party providers.
The practical consequence is that an entity in the financial market infrastructure should not assume automatically that the GEO no. 155/2024 regime applies to it in full, nor assume the opposite. The perimeter is established by entity type and by the activities carried out, and groups with mixed activities may sit under both regimes simultaneously for different components. Establishing the perimeter correctly is the first deliverable, not a formality.
Where the general regime does apply, the administrative obligations are the familiar ones: notification for registration within 30 days under art. 18 para. (2), risk level assessment using ENIRE@RO, the annual maturity self-assessment under art. 12 para. (4), and the incident reporting deadlines of art. 15 para. (7): 24 hours, 72 hours, one month.
Where the advantage is lost
Organisations with high technical maturity rarely fail on the technical side. They fail on demonstration: the policy approved by the management body is missing or outdated, the responsibility matrix no longer matches the org chart, the incident register contains only the large events, and the evidence of accredited management training required by art. 14 para. (2) does not exist.
Through Order no. 3 of 27 November 2025, the DNSC director approved the rules on supervising, verifying and enforcing compliance with the ordinance, together with the risk-based prioritisation methodology. Verification starts from documents. An impeccable backup system, without the documentation describing it and the record of its tests, presents badly in exactly the place where it should be strongest.
The exercise that validates the score
A serious restoration test is not announced a month in advance and is not run on a conveniently chosen file. Pick a real service, assume the original system no longer exists, and time the whole path: identifying the correct copy, obtaining the keys, rebuilding the environment, verifying data integrity, restarting the service and confirming that the data is what was expected, not merely present.
The result is compared against the declared recovery time and maximum data loss objectives. The gap between the two is the only honest measure of resilience, and recording it, with date, participants, problems encountered and remediation actions, is precisely the evidence an inspection asks for.
A second, shorter exercise concerns third parties: ask a supplier hosting part of the service for evidence of its last restoration test. The answer, or the absence of one, says more about real resilience than any questionnaire completed at contract signature.
Next steps
The first step is delimitation: what applies to the entity and at what level. The CysNis platform walks through the qualifying criteria with references to the legal text.
For evidence-based verification of the measures and the documentation presented at an inspection, including restoration scenarios, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Entities that prefer not to load their internal team with compliance work can cover the role through an outsourced NIS2 officer. The full range of services is in the cybersecurity services register.
A 4.83 out of 5 is a real advantage. It turns into demonstrable compliance only when it comes with proof: recorded tests, approved policies, assigned roles and a clear delimitation of the applicable regime.
Data source: DNSC, “Cyber maturity score for Romania’s financial market infrastructure, CyFun® control PR.DS-11.1”, 24 August 2026.


