„What, concretely, do we need to do for NIS2?” is the most common question we get from small firms. The answer isn't a library of procedures — it's 10 minimum measures, set out in Romania's OUG 155/2024 (which transposes Article 21 of the NIS2 Directive) and enacted through Law 124/2025.
One important detail that's often missed: the law requires these measures to be „proportionate” to the size, exposure and risk of the firm. A 20-person company doesn't do what a bank does. Here are the 10 measures, grouped practically.
The foundation — governance and people
The first group is about knowing who is responsible and keeping people prepared. It covers: (1) a risk analysis and a written security policy; (2) basic cyber hygiene and staff training — 30 minutes once a year makes a real difference; (3) human-resources security, access control and asset management, i.e. who can access what and which devices the firm owns.
Everyday defence
The second group is the day-to-day technical protection: (4) two-factor authentication (MFA) and secured communications — the one measure that, on its own, stops most account attacks; (5) encryption where appropriate, from laptop disks to sensitive data; (6) security in acquiring and maintaining systems, including applying updates on time.
When something goes wrong
The third group prepares the firm for an incident: (7) incident handling — how you detect, treat and report it. For entities under NIS2, reporting to DNSC through the PNRISC platform has strict deadlines: early warning within 24 hours, notification within 72 hours, and a final report within 30 days. (8) business continuity: backup, disaster-recovery plan and crisis management — remembering that an untested backup is not a backup.
Ties to the outside
The last group looks beyond the company walls: (9) supply-chain security — your IT and cloud vendors become part of your risk; (10) regularly assessing whether the measures actually work in practice.
What to do next
The good news: you most likely already have 4–5 of these measures, even if you never called them that. The rest are built one per month, within a single quarter. Beyond compliance, these same 10 measures are the baseline hygiene that large customers increasingly ask for in security questionnaires before signing a contract.
Frequently asked questions
How many of the 10 measures do we need if we're a small firm?
All 10 apply, but „proportionately” to the firm's size and risk. For 10–50 employees, that means simple versions written on a few pages — not corporate procedures. What matters is that each measure exists and has an owner.
Which measure should we start with?
With a written security policy and two-factor authentication (MFA) on email and on anything holding customer data. They are the cheapest and stop the most attacks. The rest follows naturally, one measure a month.
How large are the fines for not complying with NIS2?
For essential entities, up to 10 million euro or 2% of annual turnover; for important entities, up to 7 million euro or 1.4%. But for a small firm, the real risk is more often an avoidable incident than the fine.
Sources
This article was generated with AI assistance.