CysNIS platform ranked 9th in IT & Tech at INNOVENTURE 2025-2026
The CysNIS platform, built by ProDefence for coordinated NIS2 implementation, has been ranked 9th in the IT & Tech category at INNOVENTURE 2025-2026, Romania’s National Innovation Competition for SMEs, with a final score of 3.85.
The recognition matters to us for a specific reason: the category was contested by software companies with hundreds of employees, and the entry assessed is not a general-purpose suite but a tool built for a single problem, NIS2 compliance in Romania.
The official IT & Tech ranking
| Rank | Company | Project | Score |
|---|---|---|---|
| 1 | Egnosis SRL | Biobank.ro | 4.32 |
| 2 | Expertware S.R.L. | SIEMBIOT | 4.30 |
| 3 | Arhiv360 | Archive management system | 4.18 |
| 4 | Wolfpack Digital SRL | 3D2Cut | 4.15 |
| 5 | Planograma S.R.L. | Planograma | 4.10 |
| 6 | Linnify | AgentLens | 4.06 |
| 7 | Maya Intercons | COMPLEXIO | 4.00 |
| 8 | AMC Websoft SRL | CRM AMC | 3.91 |
| 9 | ProDefence | CysNIS platform | 3.85 |
| 10 | AROBS Transilvania Software | NC4F | 3.62 |
Assessment ran in two stages. In the first round, a team of 20 experts, five per industry, selected ten innovative companies in each sector. A committee of three leaders of Romanian innovation then decided the grand prizes across all industries. The competition is an initiative of Loop Operations, and the full ranking is published on the organiser’s site.
What CysNIS actually is
CysNIS is the platform an organisation uses to check, on an indicative basis, whether it falls under NIS2, to manage the implementation of its measures and to document compliance in one place, instead of a folder of files scattered across several departments.
It connects the elements that in practice sit apart: the scoping assessment, the maturity level, identified risks, security measures, implementation plans, owners, deadlines and the evidence supporting every measure claimed.
The problem is not reading the law. It is coordination.
Organisations falling under GEO no. 155/2024, approved with amendments by Law no. 124/2025, discover quickly that the legal text can be read in an afternoon. What consumes the months that follow is something else: who owns each measure, in what order they are implemented, what evidence supports each claim, and how to keep track of a programme spanning several departments and several suppliers.
The cost of poor coordination shows up at fixed moments written into the ordinance:
- the annual maturity self-assessment of risk management measures, which art. 12 para. (4) requires to be submitted to DNSC year after year, a deadline missed quietly, because nobody has it in a calendar;
- notification of a significant incident, with an early warning within 24 hours, notification within 72 hours and a final report within one month under art. 15 para. (7), deadlines that leave no time for hunting through documents;
- supervision by the authority, whose rules were approved by DNSC director’s Order no. 3 of 27 November 2025, together with the risk-based prioritisation methodology.
In all three, the question is the same: where is the evidence. An organisation that keeps its records inside a process answers in minutes. One that keeps them in e-mails and spreadsheets spends, at best, a day reconstructing them.
What the platform does not do
Worth saying plainly, because compliance attracts a lot of promises: CysNIS does not replace legal analysis, does not replace an audit and does not stand in for a specialist’s judgement. The scoping check it offers is indicative, and the platform does not substitute for DNSC’s own procedures or official channels.
What it provides is the operational frame: organising activities, letting teams work together, tracking deadlines and preparing evidence. The scoping decision, the evidence-based assessment and the documentation presented at an inspection remain human work, at ProDefence, the work of NIS auditors accredited by DNSC.
Why it matters for a small security firm
In a market where “compliance platform” has become a label attached to any checklist spreadsheet, an assessment by an independent jury, on innovation criteria, provides an outside reference point. It is not a product audit and it guarantees results for nobody. It is, however, confirmation that the direction, turning a legal text into a trackable operational programme, is considered useful by people outside the company.
For clients, the practical signal is different: the platform they rely on is not a project abandoned between two contracts, but a product under continuous development, with reputational stakes for whoever builds it.
What comes next
The INNOVENTURE 2026 gala is scheduled for 24 November 2026 at the Sheraton Bucharest Hotel, in the Platinum Ballroom, where the competition’s grand prizes will be announced.
Our thanks to the organisers and the jury. Development continues, with the emphasis on usefulness and traceability. The rest is marketing detail.
Where to start
If you do not yet know whether your organisation falls under NIS2, the first step is the indicative scoping check on CysNIS, by sector, service, size and the special criteria that may apply.
If scope is already clear and the hard part is next, the starting point is a NIS2 compliance analysis with a remediation plan, built on evidence. Organisations without an internal owner to carry the programme forward can cover the role through an outsourced NIS2 officer, including the annual deadlines and the relationship with the authority. The full range of services is in the cybersecurity services register.



