NIS2 implementation in Romania: in-house, with a consultant, or an outsourced NIS2 officer
NIS2 requirements in Romania can be implemented in three ways: in-house, with a consultant running the process, or through CISO as a Service, where an external specialist covers the NIS2 officer role. The obligations under GEO no. 155/2024, approved with amendments by Law no. 124/2025, are identical in all three. What differs is who does the work, how long it takes and how the cost is shaped: internal time, a one-off project, or a monthly retainer.
What follows compares the three routes on the same criteria, including the uncomfortable ones. None is inherently better. The choice depends on three things you already know: how many people you have, how quickly you need the result, and who carries the programme after implementation ends.
What has to be done, whichever route you take
Before choosing who does the work, it helps to fix the list of what the work is. It is the same for everyone:
- Scoping. Establishing whether the entity falls under the ordinance and in what capacity, essential or important, including the self-assessment of disruptive effect under art. 9.
- Notification for registration with DNSC, within 30 days of the moment the provisions become applicable, under art. 18 para. (2). Changes to registration data are reported within two weeks or three months, depending on the category.
- Risk level assessment using the ENIRE@RO tool, whose result, validated by DNSC, sets the applicable level: Basic, Important or Essential.
- Maturity self-assessment of risk management measures, within 60 days of submitting the risk assessment, and annually thereafter under art. 12 para. (4).
- The substantive measures in art. 11: governance, risk analysis, incident handling, business continuity, supply chain security, access control, cryptography, testing.
- Management training. Art. 14 para. (2) requires members of the management body to complete accredited professional training, and para. (1) makes them liable for breaches.
- Reporting significant incidents, with an early warning within 24 hours, notification within 72 hours and a final report within one month, under art. 15 para. (7).
- Readiness for inspection. The supervision, verification and control rules were approved by DNSC director’s Order no. 3 of 27 November 2025, together with the risk-based prioritisation methodology.
One thing does not change in any route: liability stays with the management body. Neither the consultant nor the outsourced officer takes it on. What is outsourced is the work and the expertise, not the legal responsibility.
Route 1. In-house implementation
The organisation runs the programme with its own resources: an IT or security team, an internally designated officer, and support from legal, procurement and HR.
When it works
It works where an information security management system already exists, whether certified to ISO/IEC 27001 or built internally, and where someone’s job description includes tracking legal requirements. It also works in organisations that went through GDPR with a serious process, because part of the inventories, registers and documentary discipline can be reused.
What it actually costs
There is no fee, but there is time, and time is the resource most often missing. For a medium-sized important entity, realistic effort runs to several hundred hours spread over six to twelve months, plus management time for approvals and training. That allocation shows up as other projects postponed.
Where it stalls
Stalls rarely happen on the technical side. They happen on documentation, on interpreting an ambiguous requirement, and at the first self-assessment, where the question is not what you implemented but what you can prove. The second classic obstacle is objectivity: the team that built the systems tests exactly the assumptions it used when building them, and self-assessment scores come out systematically more generous than what can be verified.
Route 2. Implementation with a consultant
An external consultant runs the project: scoping analysis, assessment of the current state against requirements, remediation plan, documentation and knowledge transfer to the internal team. The organisation still owns the programme, but does not start from zero and does not learn on its own.
When it works
This is the right route when the deadline is short, when the organisation has capable people without experience of this particular framework, or when a security function exists that needs method rather than execution. It also fits situations calling for an independent view, requested by shareholders, by a major client or by a sector authority.
What it costs
At ProDefence, consulting and implementation start from EUR 10,000 per project, and a compliance audit from EUR 5,000 per engagement. Price varies with the number of sites, infrastructure complexity, the presence of operational technology environments and the level produced by the risk assessment.
Where it stalls
The specific risk here is the project that finishes beautifully and stops there. The consultant leaves, the documentation stays, and at the first annual self-assessment nobody remembers where the evidence register was. A well-run consulting project includes knowledge transfer and a named internal owner, not only deliverables.
Route 3. CISO as a Service, acting as the outsourced NIS2 officer
An external specialist covers the cybersecurity officer role continuously, in the model known as CISO as a Service. It is not a project with a start and an end but a standing function on partial allocation: keeping the obligations calendar, updating documentation, preparing management meetings, handling the relationship with DNSC and coordinating incident response.
When it works
It suits organisations that fall under NIS2 without having the critical mass for a full-time post, which describes most important entities in Romania. An experienced specialist on permanent staff costs considerably more than a partially allocated role, and in many organisations the actual workload does not justify a full-time hire.
It also suits organisations that have finished implementation and discovered that the hard part is only starting: the obligation repeats annually, legislation changes, suppliers change, and incidents give no notice.
What it costs
At ProDefence, the outsourced NIS2 officer role starts from EUR 1,200 per month, on a 12-month contract with monthly invoicing. The fee depends on organisation size, the number of critical systems and suppliers, and the applicable assurance level.
Where it stalls
An external role works only if it has access and authority. If the outsourced officer learns about a new supplier after the contract is signed, or about an incident the next day, the role becomes decorative. The mandate, the access rights and the direct channel to management are settled at the start, not at the first incident.
Compared on the same criteria
| Criterion | In-house | With a consultant | Outsourced officer |
|---|---|---|---|
| Who runs the programme | The internal team | The consultant, with the team | The external specialist, as a standing role |
| Internal time required | High | Medium | Low |
| Speed to first evidence | Slow | Fast | Moderate but steady |
| Cost shape | Internal time, no fee | Project, paid once | Monthly retainer |
| Entry cost at ProDefence | Documentation package, EUR 1,500 or 2,000 | From EUR 10,000 per project | From EUR 1,200 per month |
| Legal liability | Management body | Management body | Management body |
| What happens after go-live | Stays with the team | Stays with the team, if handover happened | Continues without interruption |
| Objectivity of self-assessment | Weak point | Good | Good |
| Fits when | You have process and people | You have a deadline and people | You have the obligation but not the person |
How to choose without asking a vendor
Three questions separate the routes better than any sales deck.
Whose job description currently includes tracking legal security requirements? If the answer is a name, in-house is realistic. If the answer is a department rather than a person, the obligation will fall between chairs.
How long would it take to prove that a declared measure actually works? If the answer is hours, you have a process. If it is days of reconstruction, you need method, which means a consultant.
Who will do next year’s self-assessment? This question dispels illusions fastest. The obligation in art. 12 para. (4) repeats annually, and a closed project does not answer it.
What all three routes have in common
Whoever does the work, two things help in every scenario.
The CysNIS platform, for records and tracking
CysNIS connects in one place the elements that in practice sit apart: the scoping assessment, the maturity level, risks, measures, plans, owners, deadlines and evidence. In-house it replaces a tool you do not have. With a consultant it keeps the programme visible to management during the project. With an outsourced officer it is the shared space where they and your team work.
The first step in any route is the indicative scoping check, by sector, service, size and the special criteria that may apply.
The NIS2 documentation package, for the written part
Most of the compliance effort is not technical but documentary: policies, procedures, registers, plans, self-assessment forms and the evidence file presented at an inspection. The NIS2 documentation package covers exactly that, with 219 documents for important entities and 229 for essential ones, the difference being the modules for the Essential assurance level, for ICT and cloud environments and for OT, ICS and SCADA environments.
It fits all three routes, for different reasons. In-house it saves months of drafting from scratch. With a consultant it shortens the project, because the conversation starts from existing documents to be adapted rather than a blank page. With an outsourced officer it becomes the base they keep current.
Prices are EUR 1,500 for important entities and EUR 2,000 for essential entities, paid once, licensed for a single organisation. ProDefence S.R.L. is not registered for VAT, so the price shown is final. The package is sold only to organisations in scope of NIS2, for their own compliance programme.
Frequently asked questions
Can NIS2 be implemented without a consultant?
Yes. The ordinance does not require a consultant. It requires the outcome: measures proportionate to risk, documented, with evidence that can be presented at an inspection. An organisation with a mature security process and a designated internal officer can implement on its own.
Does an outsourced NIS2 officer take on the legal liability?
No. Under art. 14 of GEO no. 155/2024, management bodies approve the measures, oversee their implementation and are liable for breaches. Outsourcing covers execution and expertise, not liability.
How long does NIS2 implementation take?
It depends on the level produced by the risk assessment and on the starting point. For an important entity with existing security practices, a consultant-led programme reaches a first complete set of evidence in two to four months. In-house, the usual range is six to twelve months, because the work runs alongside day-to-day operations.
What does CISO as a Service mean?
It is the model where the information security officer role is covered by an external specialist on partial allocation and a long-term contract, instead of a full-time hire. In the NIS2 context, it covers the duties of the designated officer for the relationship with DNSC and for the compliance programme.
Does the documentation package replace consulting?
No. The documents cover the form, not the content specific to your organisation. Risk analysis, scoping decisions and adapting measures to the real infrastructure still have to be done, internally or with external support. The package removes the drafting work, not the analysis.
Can the route change along the way?
Yes, and the most frequent combination is a consultant-led implementation project followed by an outsourced role that keeps the programme running. The reverse, from outsourced role to in-house, works when the organisation hires a specialist in the meantime.
Where to start
The order that saves the most time is the same in all three routes: scoping first, then risk level, then the decision about who executes. Doing it the other way round, choosing a supplier before knowing the applicable level, produces quotes that cannot be compared.
For an assessment of the current state against the requirements, ProDefence offers a NIS2 compliance analysis with a remediation plan, built on evidence by NIS auditors accredited by DNSC. For the standing role, details are on the outsourced NIS2 officer page. The full list of services is in the cybersecurity services register.



