Register with the authority
Enrol the entity on the national platform, with contact details and sector of activity.
The NIS 2 Directive requires essential and important entities to register with their national authority, implement cybersecurity measures and report incidents against fixed deadlines. In Romania it applies through GEO 155/2024, with the National Cyber Security Directorate as competent authority. We turn the legal text into a plan with owners, priorities and deadlines — and see it through with your team.
Directive (EU) 2022/2555 · Romania: GEO 155/2024 · authority: DNSC
Three questions, thirty seconds. Tap every statement that is true for your company.
This result is indicative and does not constitute legal advice. The official classification is made by the entity itself, on its own responsibility, through the national authority's platform.
The difference between "essential" and "important" changes the fine ceiling, the supervisory regime and the consequences for the board. Getting it wrong costs in both directions: penalties for obligations you missed, or money spent on measures you never needed.
Scope is decided by two criteria applied together: sector of activity and company size. Sectors of high criticality produce essential entities at large companies; the same sectors at medium companies, plus the other critical sectors, produce important entities.
Large companies — from 250 employees or above €50 million turnover — plus entities individually designated by the authority, regardless of size.
Medium companies — from 50 employees or above €10 million turnover. This is where most companies caught out by NIS 2 sit: firms that never thought of themselves as critical infrastructure.
Size thresholds are not absolute: sole providers at national level, providers a critical service depends on and public administration are in scope regardless of headcount.
This is not a list of good practice but a set of obligations with deadlines. Two of them start a clock you cannot stop: registration and incident reporting.
Enrol the entity on the national platform, with contact details and sector of activity.
Assess security risks and self-assess your maturity level against the official methodology.
Policies, access control and multi-factor authentication, encryption, backup, business continuity and supply chain security.
Early warning, full notification and final report to the authority, for every significant incident.
Periodic security audits and mandatory management training, with the documentation that evidences both.
Take the services separately or the whole path, run by one team. The difference from pure consultancy: the measures we recommend, we also implement — and then monitor.
We establish whether and how NIS 2 applies to you, and prepare the entity file.
We measure the gap between what you run today and what the law requires, then prioritise it by risk.
The controls required by Article 21, actually put into operation — not merely written into procedures.
An external security officer, for companies that cannot justify a full-time internal role.
We detect, contain and prepare the notification file within the legal deadlines.
Periodic verification of compliance and the mandatory training for your management body.
NIS 2 compliance is not a documentation project. It needs someone who understands both the legal requirement and the infrastructure it lands on.
A thirty-minute conversation and a free initial assessment show you exactly where you stand against the NIS 2 requirements and what reaching compliance would involve.
We reply within 15 minutes. We do not send unsolicited offers.
The information on this page is general and indicative. It does not constitute legal advice and does not replace the legislation in force or official guidance from the competent authority.