Practical guide 2026

NIS2 Implementation in Romania: the complete 2026 guide

NIS2 implementation is the process by which an organisation meets the cybersecurity requirements of OUG 155/2024 — the 17 pillars of technical and organisational measures from Art. 21, DNSC registration, incident reporting in 6h/24h/72h and audit documentation preparation. This guide covers all stages, typical duration, indicative costs and mandatory documents.

Updated: April 2026 · Applicable to essential and important entities in the 18 regulated sectors

In brief

What NIS2 implementation means

NIS2 implementation represents the transformation of the organisation to fully comply with the cybersecurity requirements of EU Directive 2022/2555, transposed in Romania through OUG 155/2024. It is not a formal checkbox exercise, but a structured program of technical and organisational measures that reduce incident risk and ensure resilience of critical services.

Implementation covers four parallel axes: (1) governance — the management body formally assumes responsibility for cybersecurity; (2) technical — concrete measures in IT infrastructure (segmentation, MFA, cryptography, monitoring, EDR); (3) operational — incident response procedures, BCM, change management, supply chain; (4) compliance — documentation, DNSC registration, incident reporting, periodic audit.

Unlike NIS1 (Directive 2016/1148), NIS2 significantly extends scope (from 7 to 18 sectors), introduces a three-tier reporting regime (6h early notification / 24h incident notification / 72h detailed notification / 1 month final report), directly holds the management body accountable and imposes considerably larger sanctions.

Who is required to implement NIS2

The obligation applies to essential entities and important entities in the 18 sectors regulated by Annexes I and II of OUG 155/2024.

The 18 regulated sectors

Annex I — sectors of critical importance (essential entities): energy (electricity, gas, oil, hydrogen, district heating/cooling), transport (air, rail, water, road), banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, B2B ICT service management, public administration, space.

Annex II — additional critical sectors (important entities): postal and courier services, waste management, manufacturing/production/distribution of chemicals, food (production, processing, distribution), manufacturing (medical devices, electronics, machinery, vehicles), digital providers, research.

Size thresholds

CategoryEmployeesTurnoverBalance sheet
Essential (Annex I, large)≥250>50M EUR>43M EUR
Important (medium)50-24910-50M EUR10-43M EUR
Below threshold<50<10M EUR<10M EUR

Important exceptions: regardless of size, entities fulfilling unique critical roles are required — national infrastructure operators (energy, communications), essential service providers without alternatives, public authorities. For exact classification, see the classification tool.

The 17 Art. 21 OUG 155/2024 pillars

Article 21 lists the mandatory technical, operational and organisational measures. NIS2 implementation in practice means implementing the 13 explicitly listed pillars (letters a-k) plus 4 complementary domains derived from the CyFun® 2025 framework of the Centre for Cybersecurity Belgium, recognised by DNSC as a best practices reference.

a) Risk policiesPolicies on risk analysis and information system security.
b) IncidentsIncident management, reporting and investigation procedures.
c) BCMBusiness continuity: backup, recovery, crisis management.
d) SCRMSupply chain security and direct supplier security.
e) Acquisition, development, maintenanceSystem lifecycle security and vulnerability management.
f) EffectivenessPolicies and procedures for evaluating measure effectiveness.
g) Cyber hygieneBasic practices and training for all staff.
h) CryptographyPolicies and procedures on cryptography use.
i1) HRHuman resource security (checks, contract termination).
i2) AccessAccess control and privilege policies.
i3) AssetsAsset inventory and management.
j) MFAMulti-factor authentication and secure communications solutions.
k) VulnerabilitiesVulnerability identification, evaluation and remediation.
+ Governance (GV.OC)Governance framework and executive accountability (Art. 20).
+ Monitoring (DE.CM)Continuous detection, SIEM, security alerts.
+ Logging (PR.PS)Centralised logging, retention, log integrity.
+ Recovery (RC.RP)Disaster recovery plans and DR testing.

The 4 implementation stages

Stage 1 — Gap Analysis (2-4 weeks)

Initial assessment of cyber maturity against the 17 pillar requirements. Identifies technical, procedural and documentary gaps. Typical deliverable: gap report with score per domain (1-5), risk prioritisation, budget estimate. Without Gap Analysis, the risk is implementing controls you don't need or missing critical requirements.

Stage 2 — Planning (1-2 weeks)

Risk treatment plan, implementation calendar, budget and resource allocation, role definition (CISO, process owners, incident response team). Formal approval by the management body — explicitly required by Art. 20 NIS2.

Stage 3 — Implementation (2-12 months)

Parallel implementation across four axes: documentation (policies, procedures, registers), technical (MFA, EDR, SIEM, segmentation, encrypted backup), operational (training, incident simulations, SCRM contracts with suppliers), compliance (DNSC registration, incident reporting flow configuration).

Stage 4 — Audit and maintenance (annual cycle)

Internal and/or external compliance audit. Preparation for possible DNSC inspection. After certification, annual review cycle: risk re-assessment, policy updates, DR re-testing, continuous training, annual reporting to leadership.

Typical duration by size

Organisation profileInitial maturityEstimated duration
Micro-enterprise required as critical supplierLow3-6 months
Small organisation (50-100 employees)Medium (have basic security measures implemented but no formalised policies)4-8 months
Medium organisation (100-249 employees)Medium6-12 months
Large organisation (250+ employees)Medium-high9-18 months
Organisation with critical OT/SCADA systemsVariable12-24 months

Estimates assume allocated resources: at least one dedicated internal lead (CISO or equivalent), approved budget and access to specialised consulting for technical areas (cryptography, SCRM, OT).

Indicative costs

Total NIS2 implementation cost typically consists of five categories:

Prodefence — NIS2 implementation partner

Prodefence SRL is the company behind the CysNis platform and provides direct consulting and support services for NIS2 implementation in Romanian organisations. We combine team expertise (individually certified auditors, security engineers, GRC, ISO 27001 Lead Auditor) with a proprietary platform that significantly accelerates documentation and tracking stages.

How Prodefence engages in implementation

Engagement models

Prodefence does not substitute the management body and does not assume the legal responsibility of the obligated entity — our role is technical and methodological partner, significantly reducing time, non-compliance risk and the internal effort required for implementation.

Mandatory NIS2 documentation (~25 documents)

The NIS2 audit verifies the existence and effective application of documentation. Here is the minimum set required to demonstrate compliance:

CategoryDocuments
GovernanceGeneral information security policy; Security committee establishment decision; CISO/DPO roles and responsibilities
RiskRisk analysis methodology; Risk register; Risk treatment plan; Annual risk report
IncidentsIncident management policy; IR procedure (6h/24h/72h); Incident register; Crisis communication plan
BCM/DRBCM policy; Business continuity plan (BCP); Disaster recovery plan (DRP); DR test report
Access and HRAccess control policy; MFA policy; Onboarding/offboarding procedure; Confidentiality agreement
TechnicalCryptography policy; Backup procedure; Patch management policy; Logging policy
SCRMSCRM policy; Critical supplier register; Standard NIS2 contractual clauses
AuditInternal audit plan; Audit report; Corrective action plan

Common NIS2 implementation mistakes

How the CysNis platform helps

CysNis is the NIS2 compliance platform developed for the Romanian market by Prodefence SRL. It covers the entire implementation cycle:

Start NIS2 implementation today

Free account, no card required. Immediate access to automatic classification, internal evaluation and action plan.

Create free account View consulting service

Frequently asked questions about NIS2 implementation

What does NIS2 implementation mean?
NIS2 implementation is the process by which an organisation in one of the 18 regulated sectors meets the cybersecurity requirements of OUG 155/2024. Includes DNSC registration, implementing the 17 Art. 21 pillars, reporting incidents in 6h/24h/72h and demonstrating compliance through documentation and audit.
How long does NIS2 implementation take?
For a small organisation (50-100 employees) with average maturity, 3-6 months. For medium organisations (250 employees), 6-12 months. For large or with critical OT/SCADA systems, 12-24 months. Estimates include Gap Analysis, planning, measure implementation and audit preparation.
Where do I start NIS2 implementation?
Step zero is verifying classification — whether your organisation falls under NIS2 and as which category. Then: (1) get formal mandate from the management body; (2) perform Gap Analysis; (3) plan risk treatment; (4) implement priority measures; (5) register with DNSC within the legal deadline (60 or 150 days). Verify classification at /incadrare.
What is DNSC and what role does it play in NIS2 implementation?
DNSC (National Cyber Security Directorate) is the competent authority in Romania for NIS2. Its roles: registration of obligated entities, receiving incident notifications, compliance supervision through inspections, applying sanctions. DNSC operates the ENIRE@RO platform for incident reporting and issues practical implementation guidelines.
What is the DNSC registration deadline?
60 days for essential entities and 150 days for important entities, calculated from the date the obligation becomes applicable (size changes, entry into a regulated sector). For entities obligated at the date OUG 155/2024 entered into force, the deadline runs from December 2024.
Do I need to implement all of ISO 27001 for NIS2?
No. ISO 27001 covers most NIS2 requirements but is not mandatory. NIS2 requires implementing the 17 Art. 21 pillars — can be achieved through any recognised framework: CyFun® 2025 (recommended by DNSC), ISO 27001, NIST CSF, or a combination. ISO 27001 additionally offers the international certification advantage, useful in B2B relationships.
What do I report to DNSC in 6h/24h/72h?
6h: early notification — signal that a significant incident has occurred, without complete technical details. 24h: incident notification — preliminary description, estimated impact, affected sector. 72h: detailed notification — technical analysis, indicators of compromise (IoC), measures taken. 1 month: final report with root causes and corrective actions.
How is Gap Analysis done for NIS2?
Gap Analysis evaluates current compliance level against the 17 requirements. Typical methodology: structured questionnaire on each pillar (5-15 questions), 1-5 scoring (non-existent → optimised), evidence identification, gap prioritisation by risk and effort. The CysNis platform includes an initial internal evaluation module that generates a PDF report in 30-60 minutes.
Who signs the approval of NIS2 policies?
Per Art. 20, the management body (board of directors, sole administrator, general director) must formally approve the security policy and assume responsibility for compliance. Management body members also have minimal cyber training obligation. NIS2 sanctions include the possibility of temporary management personnel suspension.
Can I fully outsource NIS2 implementation?
Outsourcing some components is common (consulting, SIEM as a service, audit), but legal responsibility remains entirely with the obligated organisation. There must be an internal lead (CISO or equivalent), clear SCRM contracts must be signed with suppliers and minimum internal understanding and control capability must be maintained. DNSC does not accept "I didn't know, it was at the supplier" as a defence.
What happens if I don't implement NIS2 on time?
Multiple risks: fines up to 10 million EUR or 2% of global turnover (whichever is higher), temporary suspension of regulated activities, ban for management personnel, reputational damage, increased exposure to security incidents with direct costs. DNSC can perform inspections at any time after the registration deadline.
How do I demonstrate NIS2 compliance at audit?
Through three types of evidence: (1) documentary — updated and approved policies, procedures, registers; (2) technical — system configurations, logs, screenshots, security tool reports; (3) operational — meeting minutes, training reports, documented IR/DR simulations, supplier evaluations. The auditor verifies not only existence, but effective application of policies.

Glossary

NIS2
Directive (EU) 2022/2555 on the security of network and information systems, transposed in Romania through OUG 155/2024.
DNSC
National Cyber Security Directorate — competent authority for NIS2 in Romania.
OUG 155/2024
Romanian Government Emergency Ordinance transposing NIS2 (December 2024).
Art. 21
The OUG 155/2024 article listing mandatory technical and organisational measures.
Art. 20
The article on management body responsibility for cybersecurity.
Essential entity
Organisation in Annex I sectors with >250 employees or >50M EUR turnover.
Important entity
Medium organisation in Annex I and II sectors exceeding NIS2 thresholds but not classified as essential.
CyFun® 2025
Best practices framework from the Centre for Cybersecurity Belgium, recognised as a NIS2 implementation reference.
ENIRE@RO
DNSC platform for security incident reporting.
SCRM
Supply Chain Risk Management.
BCM/DR
Business Continuity Management / Disaster Recovery.
SIEM
Security Information and Event Management — centralised security event monitoring and correlation system.