NIS 2 Compliance

The NIS 2 Directive, transposed in Romania through Emergency Ordinance 155/2024, requires essential and important entities to implement a coherent security programme. We support you in building compliance and, as an auditor accredited by the national authority (DNSC), we carry out the audit as an activity independent of implementation.

What NIS 2 involves

The NIS 2 Directive does not ask for a set of documents, but for a security programme that works and can be demonstrated. The main obligations of essential and important entities are the following.

  1. Classification and registration

    Establishing the status of essential or important entity and registering with the National Cyber Security Directorate (DNSC).

  2. Technical and organisational measures

    Multi-factor authentication, endpoint protection, backups, encryption, access control and the other controls required by law.

  3. Periodic audit

    A security audit carried out by a DNSC-accredited auditor, concluded with a formal report.

  4. Incident reporting

    Notifying DNSC in stages: early warning within 24 hours, notification within 72 hours and a final report within 30 days of detection.

  5. Supply chain

    Assessing supplier risks and including security clauses in contracts.

  6. Management accountability

    Management approves the measures and is accountable for their application, and security training becomes mandatory.

Consultancy: building compliance

We work alongside the organisation from the initial assessment to maintaining compliance over time.

  • Gap analysis and initial assessment

    We assess the current situation against NIS 2 requirements and deliver a compliance plan with priorities and deadlines.

  • Implementing the measures

    We implement the missing technical and organisational controls, with technologies from our partner portfolio.

  • Policies, procedures and documentation

    We draft the security policies, incident response procedures and documentation required by law, adapted to the organisation.

  • Maintaining compliance

    We monitor, report and update the measures as legislation and the organisation evolve.

Independent audit

The audit is an activity distinct from consultancy. We carry it out as a DNSC-accredited auditor, separately from implementation projects, to preserve the objectivity and the separation of roles required by the regulatory framework.

  1. Cybersecurity audit

    We assess actual compliance, technical and organisational, against NIS 2 requirements, as an accredited third party.

  2. Formal compliance report

    We deliver the audit report, with the documented level of compliance and the supporting evidence.

  3. Recommendations and remediation plan

    We prioritise non-conformities and indicate the remediation steps, which your team or a supplier of your choice can implement.

Where do you stand with NIS 2?

We offer an initial assessment, free of charge, so that you clearly understand the current situation and the next steps.

Contact

To discuss your organisation's needs, call us or write to us. We reply within the same business day.