NIS 2 Compliance

NIS 2 is already in force. We take you to compliance, step by step.

The NIS 2 Directive requires essential and important entities to register with their national authority, implement cybersecurity measures and report incidents against fixed deadlines. In Romania it applies through GEO 155/2024, with the National Cyber Security Directorate as competent authority. We turn the legal text into a plan with owners, priorities and deadlines — and see it through with your team.

Directive (EU) 2022/2555 · Romania: GEO 155/2024 · authority: DNSC

No strings attached Reply within 15 minutes NDA on request

€10m
maximum fine for essential entities — or 2% of global annual turnover, whichever is higher
€7m
maximum for important entities — or 1.4% of global annual turnover
18 sectors
from energy, health and transport to manufacturing, food and digital services
The board
approves the measures, must undergo training and is personally accountable for non-compliance

Quick check

Are you in scope for NIS 2?

Three questions, thirty seconds. Tap every statement that is true for your company.

This result is indicative and does not constitute legal advice. The official classification is made by the entity itself, on its own responsibility, through the national authority's platform.

Classification is not paperwork. It changes everything that follows.

The difference between "essential" and "important" changes the fine ceiling, the supervisory regime and the consequences for the board. Getting it wrong costs in both directions: penalties for obligations you missed, or money spent on measures you never needed.

Essential entities

Fine
up to €10m or 2% of global turnover
Supervision
proactive, including planned inspections
Management
may be temporarily suspended from duties

Important entities

Fine
up to €7m or 1.4% of global turnover
Supervision
ex-post — on complaint, incident or evidence of non-compliance
Management
accountable for approving and overseeing the measures

Scope

Eighteen sectors, two size thresholds

Scope is decided by two criteria applied together: sector of activity and company size. Sectors of high criticality produce essential entities at large companies; the same sectors at medium companies, plus the other critical sectors, produce important entities.

Sectors of high criticality

Large companies — from 250 employees or above €50 million turnover — plus entities individually designated by the authority, regardless of size.

Energy Transport Banking Financial market infrastructures Health Drinking water Waste water Digital infrastructure Managed ICT services Public administration Space

Other critical sectors

Medium companies — from 50 employees or above €10 million turnover. This is where most companies caught out by NIS 2 sit: firms that never thought of themselves as critical infrastructure.

Postal and courier services Waste management Chemicals Food Manufacturing (incl. medical devices, electronics, automotive) Digital providers Research

Size thresholds are not absolute: sole providers at national level, providers a critical service depends on and public administration are in scope regardless of headcount.


Your obligations

What the law asks, in the order it reaches you

This is not a list of good practice but a set of obligations with deadlines. Two of them start a clock you cannot stop: registration and incident reporting.

30 days

Register with the authority

Enrol the entity on the national platform, with contact details and sector of activity.

Stage 2

Risk assessment

Assess security risks and self-assess your maturity level against the official methodology.

Stage 3

Security measures

Policies, access control and multi-factor authentication, encryption, backup, business continuity and supply chain security.

24h / 72h / 1 month

Incident reporting

Early warning, full notification and final report to the authority, for every significant incident.

Ongoing

Audit and training

Periodic security audits and mandatory management training, with the documentation that evidences both.


How we help

Our NIS 2 services. From scoping to demonstrable compliance.

Take the services separately or the whole path, run by one team. The difference from pure consultancy: the measures we recommend, we also implement — and then monitor.

Scoping and registration

We establish whether and how NIS 2 applies to you, and prepare the entity file.

  • Sector and size threshold analysis
  • Registration on the national platform
  • Appointment of the security officer

Maturity assessment and gap analysis

We measure the gap between what you run today and what the law requires, then prioritise it by risk.

  • Risk assessment against the methodology
  • Maturity level self-assessment
  • Remediation plan with effort and budget estimates

Implementing security measures

The controls required by Article 21, actually put into operation — not merely written into procedures.

  • EDR/XDR, next-gen firewall, network segmentation
  • Multi-factor authentication and access control
  • Immutable backup and continuity planning

Security officer as a service

An external security officer, for companies that cannot justify a full-time internal role.

  • Maintaining compliance and documentation
  • Day-to-day relationship with the authority
  • Periodic reporting to the board

Monitoring and incident response

We detect, contain and prepare the notification file within the legal deadlines.

  • 24/7 SOC monitoring
  • Vulnerability scanning and penetration testing
  • Notification procedures at 24h, 72h and one month

Compliance audit and training

Periodic verification of compliance and the mandatory training for your management body.

  • NIS 2 audit with report and action plan
  • Training for members of the management body
  • Phishing simulations for employees

What delay costs you

Essential entities€10m / 2% The higher of the fixed amount and the percentage of global annual turnover applies.
Important entities€7m / 1.4% The same mechanism with lower ceilings — applied to the same category of mid-sized companies.
Managementpersonal liability Members of the management body are accountable for approving and overseeing the measures. For essential entities the authority may temporarily suspend individuals from their duties.
Lost contractsknock-on effect In-scope entities are also accountable for their suppliers' security. Without evidence of compliance you drop out of tenders and supply chains you can access today.

Why iTech Media

NIS 2 compliance is not a documentation project. It needs someone who understands both the legal requirement and the infrastructure it lands on.

  • Advice and implementation from one supplier. We put the recommended measures into operation ourselves — you are not left holding a report and the job of finding someone to execute it.
  • 17+ years of combined experience in IT infrastructure and security across Romania, the UK and the US.
  • Continuous monitoring, not just audit day. A 24-hour deadline is only met if somebody sees the incident as it happens.
  • It builds on what you have. If you already hold ISO 27001 or GDPR compliance, we reuse the existing controls instead of rebuilding from scratch.

Frequently asked

What directors ask us most

Yes, but you start well ahead. ISO 27001 covers a substantial part of the required measures, yet the directive adds obligations the standard does not contain: registration with the national authority, incident reporting within 24 and 72 hours, supply chain security and mandatory management training. A gap analysis shows exactly what is missing.
Probably, but not automatically. The size rule exempts micro and small companies, but exceptions ignore size entirely: sole providers at national level, providers a critical service depends on, public administration and entities individually designated by the authority. And even out of scope, in-scope clients will ask you for contractual security guarantees.
It depends where you start. Scoping and registration take a few days. A gap analysis typically takes two to three weeks, and implementing the measures two to six months depending on how many controls are missing. Compliance is not a project that ends: monitoring, reporting and periodic audits continue.
The management body. NIS 2 places accountability at board level: management approves the security measures, oversees implementation, must undergo training and can be held liable for non-compliance. For essential entities the authority may also temporarily suspend individuals from management duties.
The clock starts. You have 24 hours for the early warning, 72 hours for the full notification with an initial assessment, and one month for the final report. For monitored clients we detect, contain and prepare the notification file — you are not shopping for a supplier in the middle of an incident.
A thirty-minute conversation. Tell us your sector, company size and what you already have in place; we tell you whether NIS 2 applies, what it requires of you and how long it would take. If you are out of scope, we say that too — cheaper for everyone than a project nobody needed.

A regulator's inspection gives no notice. Our audit does.

A thirty-minute conversation and a free initial assessment show you exactly where you stand against the NIS 2 requirements and what reaching compliance would involve.

We reply within 15 minutes. We do not send unsolicited offers.

The information on this page is general and indicative. It does not constitute legal advice and does not replace the legislation in force or official guidance from the competent authority.