„NIS2 certification”: what really exists and what is sold under that label

NIS2 certification, what really exists and what is sold

„NIS2 certification” is one of the most searched phrases on this subject, and it deserves a short answer before any explanation: an organisation cannot be certified NIS2. No such certification exists, in EU law or in Romanian law.

What is sold under that label is a set of entirely different things, some perfectly legitimate, others with no legal effect. The distinction matters, because it determines what you can actually show a client, a partner or an inspector.

What the directive says

The only article about certification in Directive (EU) 2022/2555 is art. 24, „Use of European cybersecurity certification schemes”, and its object is explicit:

„In order to demonstrate compliance with particular requirements of Article 21, Member States may require essential and important entities to use particular ICT products, ICT services and ICT processes […] that are certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881.”

Products, services and processes. Not organisations. Recital (80) confirms the approach, referring to the promotion of relevant European and international standards „in the absence of appropriate European cybersecurity certification schemes”. Art. 25 adds that member states encourage the use of standards, without imposing any particular technology.

The first European scheme adopted in that framework is EUCC, established by Commission Implementing Regulation (EU) 2024/482. It too certifies ICT products, against Common Criteria, not organisations.

What Romanian law says

GEO no. 155/2024 provides for no certification of entities. The word „certification” appears only in connection with Regulation (EU) 2019/881 and with the procurement of ICT products and services. The mechanisms through which an entity demonstrates its state are different, and there are two of them:

  • the annual maturity self-assessment, art. 12 para. (4), endorsed by the entity’s management and submitted to DNSC, with the methodology set out in Order of the DNSC director no. 1/2026;
  • the cyber security audit, art. 11 para. (5) and art. 58, performed by an auditor holding a valid DNSC attestation.

Neither is called certification, and neither produces a NIS2 certificate of compliance.

What is actually sold under the „NIS2 certification” label

What it isWhat it certifiesWhat it is worth
Personal certifications such as NIS 2 Foundation or NIS 2 Lead Implementerthe competence of an individualreal, but personal; says nothing about the entity
NIS officer training coursesthe preparation of the appointed personuseful for art. 14 para. (4) letter e), not for entity compliance
Privately issued „NIS2 compliance attestations”the provider’s opinionstrictly contractual, no legal effect in Romanian law
ISO/IEC 27001the information security management systema real accredited certification, with a different object
EUCCICT productsa real European scheme, but not for organisations

All of them can be useful. None of them is a NIS2 certification.

The Belgian exception, and why it does not travel

The only model in the Union that comes close is the Belgian CyberFundamentals scheme, developed by the Centre for Cybersecurity Belgium. Even there the terminology is careful: verification for the Basic and Important levels, certification for the Essential level, issued by authorised conformity assessment bodies, with an optional CyFun label. The result is a presumption of conformity with the Belgian transposition law, not a European NIS2 certificate.

Romania has formally adopted the CyFun framework and sits in the scheme owner group alongside Belgium, Ireland, Malta and Cyprus. The structure of the control catalogue in Order no. 1/2026 shows that lineage clearly. But as at the date of this article, Romanian law contains no provision granting any certification a presumption of conformity with GEO no. 155/2024. The Belgian regime does not extend automatically.

ISO 27001 and NIS2

An ISO/IEC 27001 certificate covers a significant part of the technical and organisational requirements and makes the work much easier. What it does not cover, in Romania:

  • the registration notification to DNSC and its updates, art. 18;
  • the incident reporting deadlines, art. 15;
  • the annual maturity self-assessment submitted to the authority and the remediation plan, art. 12 para. (4) and (5);
  • the appointment of the responsible officer and the conditions in art. 14 para. (4);
  • accredited training for management bodies and their accountability, art. 14 para. (1) and (2).

There is also a practical point: the scores under Order no. 1/2026 are given per control, separately for documentation and for implementation, with written justification. No certificate, however good, produces those scores on its own.

What to show when a client asks for „your NIS2 certification”

The question usually has a legitimate intent: the partner wants assurance. The right answer is not „it does not exist”, but a set of documents that say more than a certificate would:

  1. evidence of the notification and, where issued, the DNSC decision on entry in the register of entities;
  2. confirmation of the risk level and of the applicable assurance level;
  3. the maturity self-assessment as submitted, with the total score and the key measure scores;
  4. the statement of applicability, with justified exclusions;
  5. the remediation plan, where thresholds are not met;
  6. the report of the most recent audit by a DNSC attested auditor;
  7. the appointment decision for the responsible officer and evidence of management training.

A supplier who can put those seven things on the table demonstrates more than one holding a purchased „compliance attestation”.

Four questions for any „NIS2 certification” offer

  • What does the document certify: a person, a product or the organisation?
  • Who issues it, and under which normative act?
  • What legal effect does it have in dealings with DNSC?
  • What happens to it if the entity does not meet the thresholds in Order no. 1/2026?

If the answer to the second question does not name an act published in the Official Gazette or in the Official Journal of the European Union, the document carries the weight of a commercial opinion.

Where we can help

We do not sell NIS2 certifications, because they do not exist. What can be done is verifiable: a NIS2 compliance analysis with a remediation plan, built on evidence, and the cyber security audit itself. ProDefence is a cyber security auditor accredited by DNSC. If you have nobody to appoint internally, the role can be covered through an outsourced NIS2 officer.

If the real question is whether you are in scope, the CysNis platform walks through the criteria step by step.

Sources

This material is informative and does not constitute legal advice. Quotations from the Romanian acts are working translations. The European certification framework evolves; check the acts in force at the time of your decision.

Frequently asked questions

Is there a NIS2 certification for companies?

No. Directive (EU) 2022/2555 establishes no certification scheme for organisations. Its only certification article, art. 24, concerns ICT products, services and processes. GEO no. 155/2024 likewise provides for no certification of entities.

What is sold under the name NIS2 certification then?

Personal certifications such as NIS 2 Foundation or Lead Implementer, NIS officer training courses, privately issued compliance attestations, ISO/IEC 27001 certification and, at product level, European schemes such as EUCC. All can be useful, none is a NIS2 certification of the organisation.

Does ISO 27001 mean NIS2 compliance?

No, although it helps considerably. ISO 27001 certifies the information security management system. It does not cover the procedural obligations in GEO no. 155/2024: registration with DNSC, incident reporting deadlines, the annual maturity self-assessment, the remediation plan, appointment of the responsible officer and management training. Romanian law grants ISO 27001 no presumption of conformity.

How does an entity demonstrate compliance then?

Through the annual maturity self-assessment under art. 12 para. (4), detailed in Order of the DNSC director no. 1/2026, and through the cyber security audit performed by a DNSC attested auditor under art. 11 para. (5) and art. 58.

What is the Belgian CyFun label?

It is the output of the Belgian CyberFundamentals scheme: verification for the Basic and Important levels, certification for the Essential level, issued by authorised bodies. It produces a presumption of conformity with the Belgian transposition law. Romania has formally adopted the CyFun framework but has not enacted an equivalent presumption.

What do I show a client who asks for our NIS2 certification?

Evidence of the notification and the registration decision, the risk and assurance levels, the maturity self-assessment as submitted, the statement of applicability, the remediation plan where applicable, the latest audit report from a DNSC attested auditor, and the appointment decision for the responsible officer. Together they say more than any certificate.

Skip to content