NIS2 compliance · Legal framework applicable in Romania

Cybersecurity obligations are not negotiable. How you meet them is.

We determine whether your organisation is an essential or important entity, which requirements apply to you in concrete terms, and in what order they must be addressed. We then stay with you through implementation, testing and preparation for supervision.

European frameworkDirective (EU) 2022/2555
National transpositionGEO 155/2024
ApprovalLaw 124/2025
Affiliations and partnerships
TÜV Austria RomaniaCYSCOERoHealthCSA Romania

Regulated sectors and applicable analyses

The annexes to GEO 155/2024 list the sectors of high criticality and the other critical sectors. For each of them we have published an analysis of the cybersecurity measures applicable to essential services.

Sector register · published analyses
No.Sector of activityClassification
01EnergyAnnex I
02HealthAnnex I
03TransportAnnex I
04Drinking waterAnnex I
05Banking sectorAnnex I
06Financial market infrastructureAnnex I
07Digital infrastructureAnnex I
08Public administrationAnnex I
09SpaceAnnex I
Your organisation is not listed in the annexes, but supplies a regulated entity? Verification procedure

How we work

Order matters: without a correct scoping assessment, the measures implemented risk being either insufficient against the legal obligations or disproportionately expensive.

STAGE 1

Scoping

Establishing whether you are an essential or important entity and which obligations apply.

STAGE 2

Gap analysis

Comparing the current situation against the legal requirements, on both the technical and the organisational side.

STAGE 3

Implementation

Documentation, technical measures, internal governance, supplier assessment, incident reporting procedure.

STAGE 4

Verification

Technical testing, preparation for audits and inspections, continuous monitoring of compliance.

Competence

Most compliance providers stop at documentation. For over 15 years we have published analyses of attacks, phishing campaigns and malware targeting organisations in Romania. That same experience underpins the measures we recommend.

Principal field
NIS2 and GEO 155/2024: scoping, implementation, audit, outsourced officer
Technical capability
Penetration testing, malware analysis, investigation of incidents and cybercrime
Research
An in-house department for research and innovation in cybersecurity
Membership
CYSCOE, CSA Romania, RoHealth; participation in national and international conferences
Teaching
Courses delivered in the private sector, in public institutions and in universities

In-house platforms

Platforms developed internally to support organisations in implementing the requirements and in prevention work.

CysNis

Compliance platform

Structuring the NIS2 obligations, tracking implementation progress and keeping documentation in a single place, in a form that can be presented during an inspection.

Visit cysnis.ro

CysEdu

Education platform

Cybersecurity courses structured by level, interactive guides, practical simulations and AI-assisted tools. Supports the obligation to train staff and management.

Visit cysedu.eu

What organisations ask us most often

Short answers to the questions that come up in almost every first conversation.

01How do I know whether my organisation falls under NIS2?

Three criteria decide it in most cases: whether you operate in one of the sectors listed in the annexes to GEO 155/2024, whether you have at least 50 employees or an annual turnover above EUR 10 million, and whether you supply services to an essential or important entity as part of its supply chain. The business activity code alone is not sufficient to establish classification.

02What is the difference between an essential and an important entity?

Both carry cybersecurity obligations. The main difference is the supervisory regime: essential entities are subject to proactive supervision, whereas important entities are checked mainly following an incident or a complaint.

03Where does NIS2 implementation start?

With the scoping analysis, not with buying technical solutions. First establish which obligations actually apply to you, then compare the current situation against those requirements, and only then decide on measures. In the reverse order you risk either insufficient measures or disproportionate spending.

04Who is accountable within the organisation for NIS2 compliance?

Management. Legal responsibility rests with the management bodies and cannot be transferred in full to an external provider or to the IT department. An outsourced officer coordinates the work and prepares the documentation, but accountability remains with management.

05What does an outsourced NIS2 officer do?

It is a recurring service through which we coordinate cybersecurity activities, monitor progress against the legal requirements, keep documentation up to date and support incident reporting, without the organisation having to hire a dedicated person internally.

Contact

Tell us your sector of activity. We will tell you which obligations apply.

The preliminary scoping conversation is free of charge. If your organisation does not fall under NIS2, we will say so directly.

Response time
One working day at most
Request form
Full name
Data processing consent
Privacy policy: prodefence.ro/en/privacy-policy/