Postal and courier: 2.00 out of 5, the weakest DNSC score. A sector that does not track its own obligations
Romania’s postal and courier sector scored 2.00 out of 5 on CyFun® control GV.OC-03.2, the weakest result in the entire DNSC series. The control requires legal, regulatory and contractual obligations relating to information security to be managed continuously, so that they remain accurate, up to date and effectively applied.
Put more directly: the control measures whether the organisation knows what the law requires of it and keeps pace with changes. A 2.00 out of 5 on that question, in a sector under new regulation, describes the problem precisely.
What was measured
The data comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, in which 1,599 public and private beneficiaries self-assessed on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium. DNSC’s conclusion for the postal sector points to the need to strengthen processes for monitoring and continuously updating legal and regulatory requirements.
How many obligations a postal operator actually carries
On the cybersecurity side alone, the applicable framework has changed four times in two years:
- GEO no. 155/2024, published on 30 December 2024, replacing the regime of Law no. 362/2018;
- Law no. 124/2025, of 7 July 2025, approving the ordinance with amendments and additions;
- DNSC director’s Order no. 1/2025, on the requirements of the registration notification process;
- Order no. 2/2025, with the criteria and thresholds for determining the degree of service disruption and the methodology for assessing entity risk level;
- Order no. 3 of 27 November 2025, with the supervision, verification and control rules and the risk-based prioritisation methodology.
Added to these are the instruments DNSC publishes and updates, NIS2@RO for notification, ENIRE@RO for risk level assessment, the maturity self-assessment tools for the three levels, each with its own version number. Anyone not tracking the authority’s pages systematically is working with outdated forms.
What is lost when nobody tracks
The consequences are not theoretical. Art. 18 para. (2) requires notification to DNSC for registration within 30 days of the moment the provisions become applicable to the entity. Para. (8) of the same article requires changes to registration data to be communicated within two weeks for some categories and three months for others. A change of registered office or contact person, left unreported, is a breach in itself.
Art. 12 para. (4) adds an obligation that repeats year after year: essential and important entities carry out and submit to DNSC an annual self-assessment of the maturity of their risk management measures. It is the kind of deadline that is missed quietly, because nobody has it in a calendar.
The contractual side of the control matters just as much. A courier operator has contracts with e-commerce platforms, last-mile subcontractors and parcel tracking providers. The security clauses in those contracts age: they remain written against the old regime, contain no notification obligations matching current deadlines and grant no right of verification.
The sector with the greatest public exposure
Postal and courier services have a particular feature: their names are used intensively in fraud campaigns even when their own systems have not been touched. Messages about held parcels or unpaid delivery fees circulate constantly, and recipients attribute them to the operator. The obligation to inform service recipients about significant threats does not disappear because the attack occurred outside the operator’s own infrastructure.
The obligations register therefore has to include the communication side too: who decides, within what time, through which channels and with what message. Improvisation here is visible to the public.
The three deadlines most often missed
First: the 30 days for registration notification, counted from the moment the provisions become applicable, including when they become applicable following growth in turnover or headcount.
Second: the two weeks for reporting changes to core registration data. A change of contact person is an HR operation for the organisation and a legal obligation towards DNSC, and the two do not talk to each other unless someone connects them.
Third: the annual maturity self-assessment. Being annual, it occurs to nobody at the right moment. In an obligations register with deadlines and an owner, it does.
What a working process looks like
An obligations register, kept as a living document, covers most of this control. Each row holds the legal act or contract, the applicable article, the obligation in the organisation’s own words, the deadline, the internal owner and the evidence that demonstrates fulfilment. The register is reviewed at fixed intervals and after every legislative change, and the outcome of each review reaches the management meeting.
Such a register needs no expensive tooling. It needs a designated owner with allocated time and a duty to monitor the sources, which, in practice, is exactly the missing part. Penalties under the ordinance reach EUR 7,000,000 or 1.4% of net turnover for important entities and EUR 10,000,000 or 2% for essential ones, whichever is higher.
Where to start
The first check is scope and level. The CysNis platform walks through the criteria step by step and separates legal obligations from technical recommendations.
To build the obligations register, the deadline calendar and the documentation presented at an inspection, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Where nobody’s job description includes tracking legislation, the practical answer is an outsourced NIS2 officer who keeps the calendar and the relationship with the authority. The remaining services are in the cybersecurity services register.
A 2.00 out of 5 on knowing your own obligations is not a technical problem. It is a problem of assigned responsibility: as long as tracking the legal framework appears in nobody’s job description, it belongs to everyone, which means to no one. The first thing that changes is not a system but a line in a job description.
Data source: DNSC, “Cyber maturity score for Romania’s postal and courier sector, CyFun® control GV.OC-03.2”, 26 August 2026.


