Energy: 2.15 out of 5 on the critical supplier register. Supply chain risk under NIS2

Cyber maturity score 2.15 out of 5 for the energy sector, CyFun control GV.SC-07.2

Romanian energy sector entities scored 2.15 out of 5 on CyFun® control GV.SC-07.2, which requires a documented list of all critical suppliers, vendors and partners who could be involved in a major incident, established, kept up to date and available both online and offline. DNSC rated the result as low.

Two words in the control text explain both the low score and why it matters: “updated” and “offline”. The first is missed for lack of process. The second is missed because nobody pictures the day the systems do not come back up.

The figure in context

The measurement comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, in which 1,599 public and private beneficiaries assessed their own maturity on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium. DNSC’s conclusion for energy: records and updates concerning critical suppliers and partners need strengthening, to support a rapid and coordinated response to major incidents.

The list is not a supplier table

Every energy company has a supplier list, in its procurement system. The control asks for something else: a record of those third parties whose unavailability or compromise would affect the service, with the information needed to reach them and work with them mid-incident. The difference shows up in the columns:

  • what service or equipment they supply and what stops without it;
  • the technical contact, not the commercial one, with a direct number and a named backup;
  • actual availability hours and the contractual response time;
  • the type of access they hold in your infrastructure, remote, permanent, through a dedicated account or a shared one;
  • their own notification obligations in case of an incident on their side, and the deadline for informing you;
  • the alternative, if one exists, and the time needed to switch to it.

In an energy company, the list must also cover industrial control system integrators, equipment manufacturers with remote maintenance, communications providers carrying telemetry and the data centre operators hosting supporting systems. These are, as a rule, the ones missing from existing records.

Why “offline” is not a formality

The scenario in which the list is most needed is exactly the scenario in which it cannot be reached: the network has been isolated as a precaution, the directory service is compromised, e-mail is down, work phones are locked because authentication runs through the affected system. A record living only on the intranet or in a cloud service tied to company accounts becomes unusable in precisely the hour it mattered.

The offline version means a printed copy or separate media, kept in known locations, under confidentiality controls, the list contains information that, in the wrong hands, describes the organisation’s weak points exactly. The control says explicitly that the record is kept “with due regard to confidentiality and security”.

What the law requires beyond the control

Art. 11 para. (1) of GEO no. 155/2024, approved by Law no. 124/2025, requires essential and important entities to take proportionate and appropriate measures to identify, assess and manage risks affecting the networks and information systems they use, and to reduce the effects of incidents on the recipients of their services and on other services. That final phrase covers propagation through the supply chain directly.

In energy, this effect has a dimension other sectors lack: interdependence. An incident at a supplier shared by several operators does not produce nine separate problems but one, simultaneous, with immediate public pressure. The ordinance’s preamble cites exactly such a case from another sector, the first quarter of 2024, when 26 hospitals were affected through the same managed service provider.

To this are added the reporting deadlines of art. 15 para. (7): early warning within 24 hours, incident notification within 72 hours, final report within one month. When the cause sits with a third party, the first hours go into finding out whose and what, or they do not, if the record exists.

A simple test

Pick a critical supplier and ask, without warning, for three pieces of information: the name of the technical contact, the contractual response time and the type of access they hold in your infrastructure. If the answer takes more than an hour and involves opening the procurement system, control GV.SC-07.2 is not met, however good the self-assessment looks.

Second test: ask who maintains the list and when it was last reviewed. A record without a designated owner and a review interval is a document, not a control.

Next steps

The volume of measures depends on the risk level produced by the ENIRE@RO assessment and validated by DNSC. Before anything else, scope is established: the CysNis platform walks through the criteria with references to the legal text.

For the critical supplier record, the contractual security clauses and the documentation required at an inspection, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Operators without a dedicated internal role can cover it through an outsourced NIS2 officer, including the annual self-assessment required by art. 12 para. (4). The full range of services is in the cybersecurity services register.

There is one more effect operators underestimate: the critical supplier list is also a negotiating instrument. Once you know exactly what stops without each third party and how quickly, the conversation about security clauses, notification deadlines and audit rights is held with arguments rather than boilerplate. Suppliers who refuse those clauses identify themselves, and that, in itself, is risk information.

Data source: DNSC, “Cyber maturity score for Romania’s energy sector, CyFun® control GV.SC-07.2”, 25 August 2026.

Skip to content