NIS2 compliance, without the headache

The NIS2 Directive — transposed in Romania through GEO 155/2024 and Law 124/2025 — requires essential and important entities to implement strict cybersecurity measures, report incidents and appoint a NIS officer. We cover the entire journey: from scoping assessment to an outsourced NIS officer.

NIS2 self-assessment tool Request an assisted assessment
NIS2 services

Everything you need for compliance

One partner for audit, implementation and ongoing operations — overseen by certified specialists.

Scoping & registration

We establish whether you are an essential or important entity, based on sector and size, and assist with the DNSC registration. The initial assessment is free.

Cybersecurity audit

Gap analysis against NIS2 requirements: policies, technical measures, supply chain, continuity. You get a clear report with priorities and estimated costs.

Measure implementation

We implement the risk management measures: technical controls, procedures, backup and disaster recovery, cyber hygiene, encryption and secure IT procurement.

Outsourced NIS officer

The legally required role — managerial authority, independence from operational IT and specialised certification — provided by our specialists, on a monthly subscription.

PNRISC incident reporting

Procedures and assistance for the legal deadlines: 24h warning, 72h notification, final report in 30 days. Incident response together with your team.

Management & staff training

NIS2 requires the direct involvement of management. We run training sessions for leadership and awareness programmes for employees.

Who falls under NIS2

Sectors covered by the law

NIS2 covers far more companies than the old NIS law. If you operate in one of the sectors below and have over 50 employees or over €10 million turnover, you are very likely in scope — and in some cases even below these thresholds.

  • Energy, transport, banking, financial market infrastructure, healthcare, drinking and waste water;
  • Digital infrastructure, managed ICT service providers, public administration, space;
  • Postal and courier services, waste management, chemicals, food, critical manufacturing (medical devices, electronics, machinery, vehicles), digital providers, research;
  • Plus suppliers in the supply chain of the entities above — even if not directly in scope.
Check for free if you are in scope

Scoping assessment

Questionnaire + analysis: sector, size, supply chain role. Answer within 48h.

Audit & gap analysis

We measure the distance between your current state and NIS2 requirements, with a prioritised report.

Plan and implementation

We implement the technical and organisational measures, with an agreed budget and timeline.

Ongoing operations

Outsourced NIS officer, monitoring, incident reporting and periodic audits.

Why it matters now

The fines and management liability are real

Fines up to €10 million

Essential entities risk penalties up to €10 million or 2% of worldwide turnover; important entities, up to €7 million or 1.4%.

Management liability

Leadership approves and oversees the security measures and can be held directly liable for non-compliance — it is no longer "just an IT problem".

Short reporting deadlines

24 hours for the early warning, 72 for the initial notification. Without procedures prepared in advance, the deadlines are nearly impossible to meet.

NIS2 FAQ

Frequently asked questions about NIS2

What is the NIS2 Directive and how does it apply in Romania?

NIS2 (EU Directive 2022/2555) is the European cybersecurity framework for essential and important entities. Romania transposed it through GEO 155/2024, approved with amendments by Law 124/2025. The competent authority is the National Cyber Security Directorate (DNSC).

Does my company fall under NIS2?

It depends on your sector, your size (typically over 50 employees or over €10 million turnover) and your role in the supply chain of other covered entities. Some entities are covered regardless of size. Request our free scoping assessment and find out within 48 hours.

What is the NIS officer and why outsource the role?

It is the person appointed by management for network and information system security: managerial-level authority, independent from the day-to-day IT department, holding a specialised certification. For most companies, outsourcing the role is faster and more efficient than recruiting — you get certified expertise immediately, on subscription.

What incident reporting deadlines does NIS2 impose?

Early warning within 24 hours of detecting a significant incident, initial notification within 72 hours, intermediate reports on request and a final report within 30 days — all via the PNRISC platform to DNSC. Affected users must be notified as well.

What fines do non-compliant companies risk?

Up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important ones — whichever is higher. On top of that, management carries personal liability for governance obligations.

How long does it take to become compliant?

It depends on your starting point. After the audit, most companies need 3–9 months for full implementation. That is why we recommend starting with the scoping assessment and the audit as early as possible — pressure from the authority and from supply chain partners keeps growing.

Find out within 48 hours whether your company falls under NIS2

The scoping assessment is free and without obligation. If you are in scope, you also receive an estimate of the compliance effort.

Request the free assessment