Transport: 2.68 out of 5 on data identification. The inventory that blocks NIS2 compliance

Cyber maturity score 2.68 out of 5 for the transport sector, CyFun control ID.AM-07.1

Romania’s transport sector scored 2.68 out of 5 on CyFun® control ID.AM-07.1, worded as plainly as possible: “The data the organisation stores and uses must be identified.” DNSC rated the result as low and concluded that identification and record-keeping of data need strengthening.

It is the least spectacular control in the whole series and, at the same time, the one that blocks everything else. Without knowing what data you hold and where it sits, there is no risk analysis, no classification, no continuity plan and no accurate incident notification.

Where the figure comes from

The measurement is part of the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”. In total, 1,599 beneficiaries from the public and private sectors assessed their own maturity on the SecureRO platform, using the CyberFundamentals (CyFun®) framework defined by the Centre for Cybersecurity Belgium.

The control’s objective, as DNSC states it, is for all data stored and used by the organisation to be clearly identified, which supports its proper management and protection and alignment with organisational and regulatory requirements.

What “identifying data” means in a transport company

A transport operator holds data in far more places than the systems inventory suggests. Categories most often missing:

  • location and telemetry data from on-board units, stored with the fleet monitoring provider rather than with the operator;
  • tachograph records and driver data, with their own statutory retention regime;
  • transport documents, consignment notes and customs declarations, often living in mailboxes rather than systems;
  • passenger data in reservation and ticketing systems, including records held by intermediaries;
  • operational control parameters, signalling, dispatch, terminal automation, moving between the operational and office networks;
  • video archives from depots, terminals and vehicles;
  • backups hosted with third parties, whose contents nobody can describe precisely.

An inventory that does not reach these places is not an inventory. It is a list of servers.

The link to the legal obligation

Art. 11 para. (1) of GEO no. 155/2024 requires essential and important entities to take proportionate and appropriate measures to identify, assess and manage the risks affecting the networks and information systems they use. “Identify” comes first in the text for a reason: the remaining obligations are built on top of it.

An incomplete inventory produces consequences at three distinct moments:

  • at the risk level assessment, carried out with the ENIRE@RO tool provided by DNSC: the answers about systems and data determine the resulting level, Basic, Important or Essential, and therefore the volume of mandatory measures;
  • at the annual maturity self-assessment required by art. 12 para. (4) and submitted to DNSC: you cannot assess the protection of data you have not listed;
  • at incident notification, within the 24- and 72-hour deadlines of art. 15 para. (7): the question “which data was affected” is answered in hours only if the inventory existed beforehand.

Transport has an extra difficulty

In transport, the boundary between office systems and operational ones is porous. A dispatch terminal, a depot workstation or a terminal management system belongs technically to the operational technology world, yet is administered with IT accounts and IT tooling. Inventories drawn up separately, by different teams, leave between them precisely the zone through which incidents propagate.

The second difficulty is suppliers. A large share of an operator’s operational data is hosted by third parties: fleet monitoring platforms, reservation systems, freight forwarding services. The data remains the operator’s responsibility even when the infrastructure does not belong to it. A serious inventory includes the column “where it physically resides” and the column “who has access”.

An inventory that holds up

The exercise is faster than it looks if done in the right order: start from the services the organisation provides, not from the list of applications. For each service, identify the data without which the service stops, then where it sits, who administers it, how long it must be kept, and what happens if it becomes unavailable or public. The result feeds directly into the risk analysis and the continuity plan, without being rewritten.

A good inventory updates itself through process: every new service, every new supplier and every new integration passes through a step that refreshes the record. Otherwise the document is accurate exactly once, on the day it was signed.

The question asked at an inspection

Through Order no. 3 of 27 November 2025, the DNSC director approved the rules on supervising, verifying and enforcing compliance with GEO no. 155/2024, together with the risk-based prioritisation methodology for those activities. The supervisory framework is in force and works on risk criteria.

In a check, the first question is not which security products you bought, but which systems and which data you hold. An operator answering with an up-to-date document that also covers supplier-hosted systems demonstrates a working process. An operator who starts asking colleagues on the spot demonstrates the opposite, and the rest of the conversation proceeds accordingly.

There is one more practical reason to do the inventory first: it lowers the cost of every step that follows. A risk analysis run over a complete record finishes in days rather than months, and the security clauses in supplier contracts can be written concretely, against identified data, instead of in general terms that oblige nobody to anything.

Where to start

Scope comes before inventory, because it determines the level of effort. The CysNis platform walks through the criteria step by step, with references to the legal text.

To build the record itself and the documentation an inspection asks for, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Operators without the internal resource to carry the process forward can cover the role through an outsourced NIS2 officer. The full list of services is in the cybersecurity services register.

Data source: DNSC, “Cyber maturity score for Romania’s transport sector, CyFun® control ID.AM-07.1”, 28 August 2026.

Skip to content