Public administration: 2.07 out of 5 on independent evaluations. DNSC’s blunt conclusion

Cyber maturity score 2.07 out of 5 for public administration, CyFun control ID.IM-03.7

Romania’s public administration scored 2.07 out of 5 on CyFun® control ID.IM-03.7, which requires independent teams to evaluate the organisation’s processes, best practices and technology solutions for protecting critical systems and assets. DNSC’s conclusion is unusually blunt: in general, public administration entities do not carry out independent evaluations of their own processes and IT infrastructure, exposing themselves unnecessarily to cyber risk.

The wording leaves no room for interpretation. This is not a level that could be improved; it is a type of verification that largely does not take place.

What was measured

The data comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”. A total of 1,599 beneficiaries from the public and private sectors assessed their own maturity on the SecureRO platform, using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium.

The methodological irony is worth noting: the lowest score on independent evaluation comes from a self-assessment. Organisations that are not checked from outside acknowledged, by themselves, that they are not checked from outside.

What “independent” means

The control’s objective is to strengthen protection of critical systems and assets through objective evaluation of the organisation’s processes, practices and technologies. DNSC adds a note for operational technology environments: independent evaluations help identify vulnerabilities, reduce bias and support continuous improvement of resilience and safety.

“Reducing bias” is the heart of the control. The team that designed a system cannot evaluate it objectively, however competent it may be, not out of bad faith, but because it tests exactly the assumptions it used when building it. Independence can be achieved three ways: an internal structure separate from the one operating the system, a team from another institution, or an external evaluator. In local administration, the first two are rarely realistic.

An independent evaluation is also not an automated vulnerability scan. That covers technology. The control asks for evaluation of processes and practices: how access rights are granted and revoked, how changes are managed, how suppliers are verified, how continuity plans are tested.

Why it matters more in the public sector

A public institution has several traits that magnify the effect of missing external verification. Systems are old and interconnected, because they were added in successive layers through projects with different funding. Knowledge of them often sits with a single person. The suppliers who built them retain remote access, sometimes under contracts signed years ago. And the data administered belongs to citizens, who have no alternative to the service.

In those conditions, the absence of objective evaluation means nobody has ever verified whether the things assumed to work actually do. Backup restoration, revocation of former employees’ access, isolation of the operational network, all remain assumptions until first tested.

What the law says

Public authorities and institutions fall within the scope of GEO no. 155/2024, approved with amendments by Law no. 124/2025, under the conditions the ordinance sets. The core obligations are the same: notification for registration within 30 days under art. 18 para. (2), risk level assessment using the ENIRE@RO tool, the maturity self-assessment submitted annually to DNSC under art. 12 para. (4), and reporting of significant incidents within the deadlines of art. 15 para. (7): 24 hours, 72 hours, one month.

Art. 14 is the most uncomfortable for institutional leadership: management bodies approve the risk management measures, oversee their implementation and are liable for breaches, without prejudice to the rules on the liability of public institutions and civil servants. Para. (2) requires members of management to complete accredited professional training.

Through Order no. 3 of 27 November 2025, the DNSC director approved the rules on supervising, verifying and enforcing compliance with the ordinance, together with the risk-based prioritisation methodology. Institutions with a high risk level and no documentation reach the authority’s attention first.

What can be done on an institutional budget

The first independent evaluation does not have to cover everything. Choose the public service with the greatest impact on citizens and evaluate the chain supporting it: systems, data, access, suppliers, procedures and the recovery plan. The result is a report with findings, priorities and estimates, a document that serves simultaneously as evidence for DNSC, as justification for budget and as input for future procurement specifications.

The second step, cheaper than it looks, is writing the right of independent evaluation into contracts with system suppliers. Without that clause, verification of the most exposed component depends on the goodwill of the party being evaluated.

A third step, equally inexpensive, is setting a fixed interval for repeating the evaluation. A check carried out once, under deadline pressure, produces a report that ages within months as new systems appear and suppliers change. A check repeated at a known interval becomes a process, and processes are what an inspection looks for, not isolated documents.

Next steps

Scope is established first, because it determines the level of obligations. The CysNis platform walks through the criteria step by step, with references to the legal text.

The independent evaluation itself means a NIS2 compliance analysis with a remediation plan, built on evidence by NIS auditors accredited by DNSC, exactly the type of verification control ID.IM-03.7 calls for. Institutions without an internal owner for the process can cover the role through an outsourced NIS2 officer, including annual deadlines and the relationship with the authority. The full range of services is in the cybersecurity services register.

A 2.07 out of 5 on independent evaluation describes a situation repaired by a single administrative decision, not by an investment. The first evaluation is also the one that shows what the rest will cost.

Data source: DNSC, “Cyber maturity score for Romania’s public administration, CyFun® control ID.IM-03.7”, 17 August 2026.

Skip to content