In brief
- Who it applies to: essential and important entities in 18 sectors, >50 employees or >10M EUR turnover.
- Legal framework: OUG 155/2024 (transposition of EU Directive 2022/2555), competent authority DNSC.
- Registration deadline: 60 days (essential) / 150 days (important) from the date of becoming applicable.
- Sanctions: up to 10 million EUR or 2% of global turnover.
What NIS2 implementation means
NIS2 implementation represents the transformation of the organisation to fully comply with the cybersecurity requirements of EU Directive 2022/2555, transposed in Romania through OUG 155/2024. It is not a formal checkbox exercise, but a structured program of technical and organisational measures that reduce incident risk and ensure resilience of critical services.
Implementation covers four parallel axes: (1) governance — the management body formally assumes responsibility for cybersecurity; (2) technical — concrete measures in IT infrastructure (segmentation, MFA, cryptography, monitoring, EDR); (3) operational — incident response procedures, BCM, change management, supply chain; (4) compliance — documentation, DNSC registration, incident reporting, periodic audit.
Unlike NIS1 (Directive 2016/1148), NIS2 significantly extends scope (from 7 to 18 sectors), introduces a three-tier reporting regime (6h early notification / 24h incident notification / 72h detailed notification / 1 month final report), directly holds the management body accountable and imposes considerably larger sanctions.
Who is required to implement NIS2
The obligation applies to essential entities and important entities in the 18 sectors regulated by Annexes I and II of OUG 155/2024.
The 18 regulated sectors
Annex I — sectors of critical importance (essential entities): energy (electricity, gas, oil, hydrogen, district heating/cooling), transport (air, rail, water, road), banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, B2B ICT service management, public administration, space.
Annex II — additional critical sectors (important entities): postal and courier services, waste management, manufacturing/production/distribution of chemicals, food (production, processing, distribution), manufacturing (medical devices, electronics, machinery, vehicles), digital providers, research.
Size thresholds
| Category | Employees | Turnover | Balance sheet |
|---|---|---|---|
| Essential (Annex I, large) | ≥250 | >50M EUR | >43M EUR |
| Important (medium) | 50-249 | 10-50M EUR | 10-43M EUR |
| Below threshold | <50 | <10M EUR | <10M EUR |
Important exceptions: regardless of size, entities fulfilling unique critical roles are required — national infrastructure operators (energy, communications), essential service providers without alternatives, public authorities. For exact classification, see the classification tool.
The 17 Art. 21 OUG 155/2024 pillars
Article 21 lists the mandatory technical, operational and organisational measures. NIS2 implementation in practice means implementing the 13 explicitly listed pillars (letters a-k) plus 4 complementary domains derived from the CyFun® 2025 framework of the Centre for Cybersecurity Belgium, recognised by DNSC as a best practices reference.
The 4 implementation stages
Stage 1 — Gap Analysis (2-4 weeks)
Initial assessment of cyber maturity against the 17 pillar requirements. Identifies technical, procedural and documentary gaps. Typical deliverable: gap report with score per domain (1-5), risk prioritisation, budget estimate. Without Gap Analysis, the risk is implementing controls you don't need or missing critical requirements.
Stage 2 — Planning (1-2 weeks)
Risk treatment plan, implementation calendar, budget and resource allocation, role definition (CISO, process owners, incident response team). Formal approval by the management body — explicitly required by Art. 20 NIS2.
Stage 3 — Implementation (2-12 months)
Parallel implementation across four axes: documentation (policies, procedures, registers), technical (MFA, EDR, SIEM, segmentation, encrypted backup), operational (training, incident simulations, SCRM contracts with suppliers), compliance (DNSC registration, incident reporting flow configuration).
Stage 4 — Audit and maintenance (annual cycle)
Internal and/or external compliance audit. Preparation for possible DNSC inspection. After certification, annual review cycle: risk re-assessment, policy updates, DR re-testing, continuous training, annual reporting to leadership.
Typical duration by size
| Organisation profile | Initial maturity | Estimated duration |
|---|---|---|
| Micro-enterprise required as critical supplier | Low | 3-6 months |
| Small organisation (50-100 employees) | Medium (have basic security measures implemented but no formalised policies) | 4-8 months |
| Medium organisation (100-249 employees) | Medium | 6-12 months |
| Large organisation (250+ employees) | Medium-high | 9-18 months |
| Organisation with critical OT/SCADA systems | Variable | 12-24 months |
Estimates assume allocated resources: at least one dedicated internal lead (CISO or equivalent), approved budget and access to specialised consulting for technical areas (cryptography, SCRM, OT).
Indicative costs
Total NIS2 implementation cost typically consists of five categories:
- Consulting and project management (15-25% of budget) — Gap Analysis, plan, implementation support, audit preparation.
- Security software (30-40%) — SIEM, EDR/XDR, MFA, backup solutions, DLP systems, vulnerability scanner.
- Hardware and infrastructure (10-20%) — network segmentation, redundancy, off-site backup systems.
- Audit and certification (5-10%) — internal and/or external compliance audit, possibly complementary ISO 27001 certifications.
- Training and internal development (10-15%) — general training (cyber hygiene) and specialised (CISO, IR, dev sec).
Prodefence — NIS2 implementation partner
Prodefence SRL is the company behind the CysNis platform and provides direct consulting and support services for NIS2 implementation in Romanian organisations. We combine team expertise (individually certified auditors, security engineers, GRC, ISO 27001 Lead Auditor) with a proprietary platform that significantly accelerates documentation and tracking stages.
How Prodefence engages in implementation
- Initial diagnostic and classification — we confirm whether the organisation is subject to NIS2, in which sector and as which category (essential/important), including for structures with multiple activities or company groups.
- Gap Analysis and treatment plan — formal evaluation across the 17 Art. 21 requirements, report with maturity score and prioritised action plan based on risk, effort and DNSC deadlines.
- Documentation support — adapting policies, procedures and registers to the real organisational context, starting from the platform's base of over 100 validated templates.
- Technical implementation support — architecture recommendations, assistance configuring controls (MFA, logging, backup, segmentation, SCRM) and integration with existing internal flows.
- Audit preparation and DNSC registration — evidence verification, audit simulation, support filling in registration forms and incident notifications via ENIRE@RO.
- Continuous support — platform subscription for compliance tracking, legislative updates and AI assistance based on Google Gemini Enterprise (without training on client data).
Engagement models
- Self-service via platform — free account with access to classification, initial internal evaluation and basic templates; suitable for organisations with internal security teams.
- Targeted support — consulting sessions on specific components (policies, SCRM, IR, BCM/DR), billed hourly or as packages.
- Assisted implementation — complete end-to-end project coordinated by Prodefence, with mixed client + consultant team, clear deliverables and contractually agreed schedule.
- Post-implementation retainer — compliance maintenance, leadership reporting, support for incidents and DNSC inspections.
Prodefence does not substitute the management body and does not assume the legal responsibility of the obligated entity — our role is technical and methodological partner, significantly reducing time, non-compliance risk and the internal effort required for implementation.
Mandatory NIS2 documentation (~25 documents)
The NIS2 audit verifies the existence and effective application of documentation. Here is the minimum set required to demonstrate compliance:
| Category | Documents |
|---|---|
| Governance | General information security policy; Security committee establishment decision; CISO/DPO roles and responsibilities |
| Risk | Risk analysis methodology; Risk register; Risk treatment plan; Annual risk report |
| Incidents | Incident management policy; IR procedure (6h/24h/72h); Incident register; Crisis communication plan |
| BCM/DR | BCM policy; Business continuity plan (BCP); Disaster recovery plan (DRP); DR test report |
| Access and HR | Access control policy; MFA policy; Onboarding/offboarding procedure; Confidentiality agreement |
| Technical | Cryptography policy; Backup procedure; Patch management policy; Logging policy |
| SCRM | SCRM policy; Critical supplier register; Standard NIS2 contractual clauses |
| Audit | Internal audit plan; Audit report; Corrective action plan |
Common NIS2 implementation mistakes
- Treating NIS2 as an IT project, not a business one. NIS2 requires assumption at the management body level (Art. 20). Without executive mandate, the project stalls.
- Buying tools without policies. A SIEM without alert triage procedures or an EDR without a response process does not produce compliance.
- Ignoring the supply chain (SCRM). Many critical suppliers lack security clauses in contracts. NIS2 requires formal supplier evaluation and specific contractual clauses.
- Lack of periodic testing. DR, BCM and IR plans not practically proven through simulations are not accepted at audit.
- Underestimating incident reporting. The 6h early notification deadline is very short — without pre-approved procedures and 24/7 escalation flow, the organisation will miss the deadline.
- Generic "copy-paste" documentation. Auditors and DNSC verify effective application, not just document existence. Policies must be adapted to the real context.
How the CysNis platform helps
CysNis is the NIS2 compliance platform developed for the Romanian market by Prodefence SRL. It covers the entire implementation cycle:
- Automatic classification — checks whether your organisation falls under NIS2, in which sector and as which category (essential/important).
- Initial internal evaluation (Gap Analysis) — structured questionnaire across the 17 domains, generates PDF report with maturity score.
- Personalised implementation plan — based on Gap Analysis, generates action plan with deadlines and responsibilities.
- Template library — over 100 pre-filled NIS2 documents (policies, procedures, registers), exportable DOCX/XLSX.
- Compliance tracking — monitors progress on each requirement and synchronises with the CyFun® 2025 framework.
- Risk register — 5x5 matrix per NIS2 methodology, exportable in standard formats.
- AI assistant for technical questions — based on Google Gemini Enterprise, without training on your data.
- DNSC notification form — generator for incident reporting in the format required by ENIRE@RO.
Start NIS2 implementation today
Free account, no card required. Immediate access to automatic classification, internal evaluation and action plan.
Create free account View consulting serviceFrequently asked questions about NIS2 implementation
What does NIS2 implementation mean?
How long does NIS2 implementation take?
Where do I start NIS2 implementation?
What is DNSC and what role does it play in NIS2 implementation?
What is the DNSC registration deadline?
Do I need to implement all of ISO 27001 for NIS2?
What do I report to DNSC in 6h/24h/72h?
How is Gap Analysis done for NIS2?
Who signs the approval of NIS2 policies?
Can I fully outsource NIS2 implementation?
What happens if I don't implement NIS2 on time?
How do I demonstrate NIS2 compliance at audit?
Glossary
- NIS2
- Directive (EU) 2022/2555 on the security of network and information systems, transposed in Romania through OUG 155/2024.
- DNSC
- National Cyber Security Directorate — competent authority for NIS2 in Romania.
- OUG 155/2024
- Romanian Government Emergency Ordinance transposing NIS2 (December 2024).
- Art. 21
- The OUG 155/2024 article listing mandatory technical and organisational measures.
- Art. 20
- The article on management body responsibility for cybersecurity.
- Essential entity
- Organisation in Annex I sectors with >250 employees or >50M EUR turnover.
- Important entity
- Medium organisation in Annex I and II sectors exceeding NIS2 thresholds but not classified as essential.
- CyFun® 2025
- Best practices framework from the Centre for Cybersecurity Belgium, recognised as a NIS2 implementation reference.
- ENIRE@RO
- DNSC platform for security incident reporting.
- SCRM
- Supply Chain Risk Management.
- BCM/DR
- Business Continuity Management / Disaster Recovery.
- SIEM
- Security Information and Event Management — centralised security event monitoring and correlation system.
