← All resources
Practical guide · NIS2 & cybersecurity

NIS2 for medium-sized businesses: from scope to preparation

How to assess potential NIS2 coverage, understand Romania’s framework and prepare through clear processes, responsibilities and evidence.

IT infrastructure in an industrial environment
A guide for company management, IT and operations teams. Updated on 28 September 2026.
Audience
Medium-sized businesses
Context
Romania · NIS2
Focus
Scope and preparation
01 / What NIS2 means

Cybersecurity becomes a management responsibility.

NIS2 is Directive (EU) 2022/2555, which aims to establish a high common level of cybersecurity across the European Union. It broadens the organisations covered and focuses on risk management, service continuity, supplier security and significant incident reporting.

For a medium-sized business, this translates into practical decisions: who approves ERP access, who can connect remotely to production systems, how long recovery takes and who coordinates an incident response.

Management must be involved in approving and overseeing the measures. Outsourcing IT operations does not transfer all the organisation’s responsibilities to its supplier. The EU Directive must be read alongside the national legislation applicable in Romania.

02 / Who may be in scope

Start with what the business actually does.

NIS2 does not automatically apply to every SME. The assessment combines the type of entity and services provided, sector, size and specific statutory exceptions.

  1. Identify relevant activities and services

    Compare actual operations with Annexes 1 and 2 to Romanian Emergency Ordinance no. 155/2024. Review all relevant business lines: a primary activity code or a commercial description is not enough.

  2. Check size using the applicable rules

    Having 50–249 employees is a familiar reference for medium-sized enterprises, not a sufficient legal test. Financial indicators also matter, together with the specific rules in Article 8 of the ordinance and its references to Law no. 346/2004. Document the group structure and check its treatment before reaching a conclusion.

  3. Check exceptions and entity classification

    Some entities are covered regardless of size. A medium-sized enterprise is not automatically only an “important entity”: specific cases can be “essential”, including certain communications services and managed security services. The classification affects supervision.

Keep a scoping note recording the activities, data, legal references and unresolved questions. For borderline cases, seek DNSC clarification and specialist legal advice. See Articles 5–8 and the annexes to Emergency Ordinance no. 155/2024, as amended.

03 / Industries and services

Manufacturing and automotive warrant careful review.

This table supports initial screening. Exact coverage depends on the definitions and conditions of each entry in the statutory annexes.

ActivitiesWhat to check
Industrial manufacturingComputers, electronic and optical products; electrical equipment; machinery; motor vehicles, trailers and semi-trailers; other transport equipment; certain medical devices.
Chemicals and foodThe manufacture, production and distribution of chemicals as defined in the annex; industrial food production, processing and wholesale distribution.
Digital and IT servicesCloud, data centres, DNS, trust services, electronic communications, managed IT and managed security services; certain online platforms.
Energy, water and transportThe operators and services specified in legislation for energy, drinking water, wastewater and transport. Not every road haulage company is automatically covered.
Health, finance and other sectorsHealth, banking, financial market infrastructures, postal and courier services, waste management, research, space and public administration, within the statutory definitions.

Supplying an automotive manufacturer does not, by itself, establish direct applicability. Actual activity and size need checking. Separately, an in-scope customer may request security evidence from its suppliers through contractual requirements.

Direct statutory coverage and supply-chain requirements are distinct assessments. Even a business outside direct scope may have contractual duties covering access, incident notification and continuity. Reference: Annexes 1 and 2 to Emergency Ordinance no. 155/2024.

04 / Romanian framework

From the directive to national obligations.

Romania’s core framework is Emergency Ordinance no. 155/2024 on the cybersecurity of networks and information systems in the national civilian cyberspace, approved with amendments by Law no. 124/2025. Use the consolidated text applicable at the time of a specific assessment.

  • DNSC Order no. 1/2025: notification and entity registration requirements.
  • DNSC Order no. 2/2025: service disruption criteria and the entity risk assessment methodology.
  • DNSC Order no. 3/2025: supervision, verification and control rules.
  • DNSC Order no. 1/2026: cybersecurity risk management measures, the maturity self-assessment methodology and amendments to the risk assessment methodology. It was published in August 2026.

Registration, risk assessment, maturity self-assessment and implementation are separate stages. Submitting a form does not demonstrate that every control is operational. Track deadlines against the entity’s circumstances and DNSC communications; there is no single generic deadline for the whole process.

Check sector-specific rules too, including the relationship with DORA for financial entities. ISO/IEC 27001 certification or a TISAX assessment may provide useful evidence, but neither replaces the assessment of NIS2 obligations. Official references are listed at the end.

Further amendments include Law no. 123/2026, which supplements Article 36 of the ordinance and the Criminal Code in relation to vulnerability research and reporting. This is another reason to use the consolidated text rather than the original 2024 version alone.

05 / Practical preparation

A programme with owners, deadlines and evidence.

Preparation starts with a verifiable picture of how the business operates. Technical controls need to connect to the services and processes they protect.

  1. Assign responsibilities and a budget

    Involve management, IT, operations, finance and relevant suppliers. Define who decides, implements and checks. Plan training for management and staff.

  2. Map systems and dependencies

    Include ERP, identities and accounts, email, servers, cloud, network equipment and IT/OT connections. Identify the processes that stop when any of these components fail.

  3. Assess risks and gaps

    Consider account compromise, ransomware, ERP downtime and uncontrolled supplier access. Distinguish entity risk assessment from control maturity self-assessment and use the applicable methodology.

  4. Implement proportionate controls

    Review access rights, multifactor authentication, updates, vulnerabilities, segmentation, cryptography, logging and incident detection. Include security in system acquisition, maintenance and development. Coordinate changes to industrial equipment with production teams and suppliers.

  5. Test continuity and supplier arrangements

    Check backup restoration, system recovery order and alternative ways of working during disruption. Clarify external access, subcontractors, escalation times and contractual responsibilities.

  6. Keep evidence and track remediation

    Maintain an action register with an owner, deadline and closure evidence. Review control effectiveness regularly and update documents following changes or incidents.

Example: ERP unavailable at the start of a shift

In this illustrative scenario, a company cannot release orders to production. Which services are affected? Who authorises temporary working arrangements? What data can be restored, and how is recovery validated? A restoration report and a documented exercise provide more useful evidence than a statement that backups exist.

The 2026 DNSC measures cover governance, identification, protection, detection, response and recovery. The steps above are a practical starting point, not the complete control catalogue.

  • A scoping note and register of applicable obligations.
  • An IT/OT inventory and critical dependency map.
  • A risk assessment and approved action plan.
  • Tested incident and continuity procedures.
  • Evidence of access reviews, restoration, training and remediation.
06 / Incident reporting

Prepare communications before an incident.

An internal procedure should identify who recognises a potentially significant incident, assesses it, submits notifications and covers for key people.

At directive level, the general significant-incident reporting sequence includes an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within one month of notification. Special rules apply, including for certain trust services and ongoing incidents. Check national procedures, significance criteria and sector-specific rules.

These are not waiting periods: internal organisation must support prompt action and escalation. Record the timeline, known impact and actions taken. A technical alert is not automatically a significant incident, and a NIS2 notification does not replace other applicable reporting.

References: Article 23 of the NIS2 Directive and the European Commission’s explanation.

07 / DNSC tools

Use the official route for registration and assessment.

DNSC — Romania’s National Cyber Security Directorate plays a central role in applying the national NIS2 framework. Check its official NIS2 legislation page for regulations, instructions and updates.

  • NIS2@RO Platform: the enrolment, information and cooperation platform provided for by DNSC regulations.
  • NIS2@RO tool: supports assessment and generation of notification data. This is distinct from entity risk assessment.
  • ENIRE@RO: the entity risk assessment tool under the relevant methodology.
  • Maturity self-assessment: use the official tools and instructions under the 2026 framework for the level applicable to the entity.

Download tools from official sources and check the available version. Retain submissions, acknowledgements and decisions in a controlled record. Tools support the process; its quality depends on the organisation’s data and evidence.

08 / Official sources

Documents to start your assessment.

Editorial references checked on . For a company-specific assessment, check the legislation and official instructions in force at that time.

This guide provides operational orientation. Legal classification and specific obligations require an entity-specific assessment; the article is not a legal opinion or a confirmation of compliance. Romanian legislation links are in Romanian.

NIS2 preparation becomes useful when requirements connect to real processes, clear owners and evidence that can be checked.

Want to clarify where preparation should start?

An IT & ERP Assessment can help us discuss your systems, dependencies and operational priorities. Tell us about your activities, company size and any requests from DNSC or customers. The initial assessment does not replace legal classification or a statutory audit.

Request an IT & ERP assessment →