In brief

  • The State settles 75% of the cost of a cybersecurity assessment, up to 45,000 euro for one company. The budget of the scheme is 2,000,000 euro, split into four service packages: 7,500 euro for the smallest, then 18,750, 33,750 and 45,000 euro. The scheme applies from 28 September 2026 until the money runs out, but no later than 31 March 2028, and payments are made up to 30 June 2029.
  • The company cannot lodge the application on its own. The funding application is lodged by a specialised cybersecurity service provider, as the leader of a consortium formed with at least 3 and at most 5 small and medium-sized enterprises. The money goes to the provider, while the enterprise receives services and pays out of its own pocket at least 25% of their value. The de minimis aid is nevertheless deducted from the enterprise’s ceiling, not from the provider’s.
  • What is bought is analysis and diagnosis, while the remediation stays at the company’s expense. Eligible for settlement are the gap analysis against Regulation (EU) 2024/2847, the vulnerability scans, the penetration tests, the audit of the software development process and the training of the teams. Not eligible are software development, research, equipment and licences, the implementation of the remediation measures and certification through notified bodies. Eligible companies are those with one of the 18 CAEN codes in the annex to the scheme.
Act: Decision of the President of the Authority for the Digitalisation of Romania no. 516/2026 on approving the de minimis aid scheme for initial assessments of conformity with Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) no. 168/2013 and (EU) 2019/1020, as well as Directive (EU) 2020/1828 (Cyber Resilience Act)
Published: Official Gazette of Romania (Monitorul Oficial), Part I, no. 821 of 28 September 2026, pages 4-14
In force from: from publication, 28 September 2026, because Article 4 of the decision and Article 14 of the scheme both provide that the scheme applies from the date of publication in the Official Gazette of Romania, Part I

On 28 September 2026 the Authority for the Digitalisation of Romania published the scheme through which it pays small companies part of the cost of the conformity assessment against the European cyber resilience regulation. Until now, Romanian acts on this subject imposed obligations, as did the decision by which the National Cyber Security Directorate laid down on 21 September 2026 how a subsidiary demonstrates compliance with group policies. Here the State puts 2,000,000 euro on the table to cover three quarters of the bill for a diagnosis, without adding any obligation.

The money comes from the Digital Europe Programme and from the State budget, in equal parts, through the project „Consolidarea capacităților Centrului Național de Coordonare NCC-RO”, the strengthening of the capacities of the national coordination centre, grant agreement no. 101.227.737. The administrator of the scheme is the National Cybersecurity Coordination Centre of Romania, a structure within the Authority for the Digitalisation of Romania, known by the acronym NCC-RO.

What can be bought with this money. The scheme finances four types of activity, all of them assessment. The first is the applicability and gap analysis, that is establishing the role of the company, as manufacturer, distributor or integrator, the inventory of products with digital elements and their comparison with the essential requirements in Annex I to Regulation (EU) 2024/2847. The second covers the technical assessments: authenticated and unauthenticated vulnerability scans, prioritised by CVSS score, and penetration tests, that is the simulation of attack scenarios. The third concerns the internal software development process, from threat modelling through to the security of the continuous integration pipeline and the management of patches. The fourth is training, and the management training session is compulsory in all packages.

What stays outside the scheme is just as important: the development of software or of new functionalities, research, investment in infrastructure, the purchase of equipment and licences, the implementation of the remediation measures found at the assessment and the certification of products through notified bodies. The company learns what it has to repair, but pays for the repair itself.

The four packages and what each side puts in. The activities are grouped into four packages, from P1 to P4, and each beneficiary receives a single package per project. P1 has a maximum eligible value of 10,000 euro and a grant of at most 7,500. P2 adds the vulnerability assessment and the technical training, at 25,000 euro of eligible value and 18,750 euro of grant. P3 adds the full audit of the development process and penetration testing, at 45,000 euro and a grant of 33,750. P4 adds the optimisation of processes for complex portfolios, at 60,000 euro and a grant of 45,000. The ratio is the same everywhere, 75% of the eligible value, and the remaining 25% at least is borne by the company, together with the non-eligible VAT and the information and publicity costs.

Who can receive and who lodges the application. The beneficiaries are microenterprises and small and medium-sized enterprises registered in Romania which develop, manufacture, integrate, distribute or use digital products, services or solutions subject to cybersecurity requirements. The activity condition is checked through the CAEN code, the Romanian classification of economic activities: the annex to the scheme holds 18 codes, of which 9 in manufacturing, from electronic components and computers through to optical fibre cables, 4 in software and IT services and 5 in telecommunications and digital platforms. The code must be authorised on the date the application is lodged, relevant for the project and consistent with the compliance measures.

The rest of the conditions are the usual ones for public funds: no outstanding budgetary obligations above one twelfth of the liabilities of the last twelve months to the tax authority and above one sixth of those of the last half-year to local budgets, no insolvency or liquidation, no unenforced recovery order for earlier aid, no double funding for the same activities.

The unusual part is the lodging mechanism. The application is lodged by a specialised cybersecurity service provider, as consortium leader, together with at least 3 and at most 5 partner enterprises, and the company that receives the aid remains a partner in somebody else’s file. The leader signs the funding contract alongside the authority and the companies, performs the services and collects the grant, but the scheme says clearly that it does not have the status of beneficiary of the de minimis aid. The aid is deemed granted to each company on the date the funding contract is signed and consumes that company’s de minimis ceiling, even though the money never passes through its account. To be eligible, the leader must hold either an ISO/IEC 27001 certification or a senior expert with a certification of the CISSP, CISA, CISM or OSCP type.

How payment is made. The support is granted as a lump sum, not as a settlement of invoices. Payment comes in two instalments, both conditional solely on deliverables, without any check of the costs actually borne: 30% after acceptance of the preliminary assessment report and of the preliminary gap register for each company in the project, then 70% after the final technical report, within 60 days of its approval. No pre-financing is granted. The compulsory deliverables number seven, from L1, the assessment report of at least 15 pages required in all packages, to L7, the penetration testing report, required only in P3 and P4 and only if the product assessed falls within a risk class that justifies it.

Where implementation is partial, the grant falls in proportion to the degree to which the deliverables have been produced. Where there is no implementation, the grant is not awarded at all, and the administrator may claim back the whole interim instalment, with interest calculated by adding 100 basis points to the one-year money-market rate, compounded annually. Recovery decisions have the character of an enforceable title.

What it changes in practice

The first effect is financial and can be measured. At 2,000,000 euro and an intensity of 75%, the scheme mobilises services of roughly 2,666,667 euro, of which some 666,667 euro come out of the companies’ pockets. The budget is split by year: 600,000 euro in 2026, of which 300,000 euro European funds and 300,000 euro national co-financing, and 1,400,000 euro in 2027, again in equal parts. The figures add up, and the conversion into lei is made at the InforEuro rate for the month in which the call opens, so the equivalent in lei is not yet known.

The second effect has to do with the de minimis ceiling and is the one that most often takes people by surprise. The aid received here is added to all the de minimis aid of the single undertaking over the last three years, and the total may not exceed 300,000 euro, the ceiling set by Article 3(2) of Regulation (EU) 2023/2831. A company that has already taken grants for digitalisation, energy efficiency or internationalisation uses up here a further 45,000 euro at most of that ceiling, without cashing a single leu. The check is made before the award, through the State Aid Register and through the declaration on own responsibility lodged for each company in the consortium.

The third effect is on the market of cybersecurity service providers. The scheme requires them to organise themselves: to find between 3 and 5 clients willing to put up 25% of the money, to sign partnership agreements with each of them, to build a cost estimate by man-hours and categories of expert and to go through a competitive evaluation. The price of the services is checked by the administrator against the reference values of the packages and against market rates, precisely so that the provider does not obtain an indirect economic advantage. In exchange, the execution risk stays entirely with it: the maximum value of the package may not be exceeded, whatever the real costs.

The fourth effect is informational and reaches beyond the companies financed. For each beneficiary, the consortium leader sends an anonymised data sheet in JSON format, with the package contracted, the sector, the size of the company, the maturity scores and the number of gaps found. Sending it is a condition for validating the final report. The result, at the end of the scheme, is the first public measurement of the level of cyber preparedness of the Romanian industry of digital products.

What has changed compared with the previous situation

Until 28 September 2026 there was no Romanian public instrument dedicated to the cost of complying with the Cyber Resilience Act. Companies that wanted to know where they stood against the European requirements either paid for the assessment in full or put it off. The scheme changes no obligation, because the obligations come from the European regulation and apply in any event; it changes only who pays for the diagnosis.

The method of verification has changed too. Classic de minimis schemes settle expenditure proven by invoices and bank statements. Here a fixed sum is paid per package, and control moves entirely onto deliverables, results and indicators, without any check of individual costs. The rule appears five times in the text of the scheme, in Articles 10, 12 and 18, a sign that the issuing authority wanted to leave no room for interpretation. For companies it means less justification paperwork, and for the provider a price risk it cannot pass on.

What has changed, thirdly, is the position of the beneficiary in the procedure. In ordinary schemes the enterprise lodges the application and receives the money. Here it signs a partnership agreement, then the funding contract, receives services and sees its de minimis ceiling reduced, while the application, the cost estimate and the reporting belong to somebody else. It is a construction that lowers the administrative cost for the authority, since it assesses between 54 and 88 projects instead of several hundred individual applications, but one that ties the fate of every company to the quality of the leader it has chosen.

Advantages and disadvantages

What it improves

  • It covers precisely the step small companies skip: the diagnosis. A serious gap analysis costs as much as an engineer’s monthly salary, and 75% of it paid by the State moves the decision from „maybe next year” to „now”.
  • The lump sums and payment on deliverables spare the company the settlement file. What is asked for is the report, the gap register and the data sheet, not invoices, timesheets and statements for every expert hour.
  • The packages are calibrated on real sizes, from 10,000 to 60,000 euro of eligible value, and the minimum content of each is written into the act, not left to the guide.
  • The requirements on the provider are verifiable and not invented: an ISO/IEC 27001 certification at organisation level or an expert with a recognised certification. A footnote to the scheme states that experience with the European regulation is not a knock-out criterion, since the regulation is new, and it accepts experience with ISO 27001, IEC 62443, NIST CSF or NIS2.
  • The anonymised data sheet, compulsory for each beneficiary, turns the scheme into a source of public statistics on the cyber maturity of Romanian companies, and not merely into an item of expenditure.

What remains a problem

  • The company cannot enter on its own. If no provider takes it into a consortium, it is left outside, however eligible it may be. The scheme provides for no public list of interested providers and no matching mechanism.
  • The de minimis ceiling is used up without the company cashing any money. Up to 45,000 euro of the 300,000 euro available over three years go on a service, and the company may discover later that it no longer has room for an investment grant.
  • Only the diagnosis is financed. The act expressly excludes the implementation of the remediation measures and the certification, that is precisely the expensive part. A company may end up with a gap register it has no money to close.
  • The time limits are asymmetrical. The administrator has 60 days for the final payment, but the act sets it no time limit for approving the technical report, for accepting the preliminary deliverables or for paying the interim instalment.
  • The estimated number of beneficiaries, 266, is calculated on the assumption that every company takes the cheapest package. If they all took package P4, the money would reach 44 companies, that is six times fewer.
  • The act applies until 31 March 2028, but the budget table has lines only for 2026 and 2027. For the first quarter of 2028, in which the scheme stays open, there is no allocation written down.

Practical advice

  1. Check your CAEN code and its status first. It must be one of the 18 in the annex to the scheme and must be authorised at the trade register on the day the application is lodged, not merely entered in the articles of association.
  2. Ask for the tax clearance certificates from the tax authority and from the town hall before talking to a provider. The thresholds are one twelfth of the liabilities of the last twelve months to the State and one sixth of those of the last half-year to the local budget, and a small arrear takes you out of the consortium.
  3. Work out the de minimis ceiling for the single undertaking, not only for your own company. Companies with which you have links of control come in here as well, and the period is counted continuously, over the last three years from the date of the award, not over calendar years.
  4. Choose the package once you have the product in mind, not according to the budget. Packages P3 and P4 include penetration testing only if the product assessed falls within a risk class that justifies it, so a large package taken for a simple product may end in deliverables you will not be able to tick off.
  5. Put into the partnership agreement what happens if a partner leaves the project. The consortium needs at least 3 companies, and the scheme does not say who bears the consequences if one becomes ineligible after the contract is signed.
  6. Prepare the qualified electronic signature of the legal representative of the consortium leader and the single declaration on own responsibility for each final beneficiary. Without them the application cannot be lodged in the IT system.

Frequently asked questions

Can I lodge the application myself, as a small company?
No. Article 10(1) and Article 18(2) of the scheme provide that the eligible applicants are specialised cybersecurity service providers, which lodge as consortium leaders, in partnership with at least 3 and at most 5 small and medium-sized enterprises. The beneficiary company signs the partnership agreement and the funding contract, but does not lodge the application.
How much do I actually receive and how much do I pay myself?
The aid covers at most 75% of the eligible value of the services. In package P1, 7,500 euro out of 10,000; in P2, 18,750 out of 25,000; in P3, 33,750 out of 45,000; in P4, 45,000 out of 60,000. The rest, at least 25%, is borne by you, alongside the non-eligible VAT and the information and publicity costs. The money is paid to the provider for the services performed, while the company is left only with the service.
From when do I have to comply with the Cyber Resilience Act?
Article 71(2) of Regulation (EU) 2024/2847 provides that the regulation applies from 11 December 2027. Two pieces are an exception: Article 14, which applies from 11 September 2026, and Chapter IV, Articles 35 to 51, on the notification of conformity assessment bodies, applicable from 11 June 2026. Article 14 requires the manufacturer to notify any actively exploited vulnerability, with an early warning within 24 hours and a full notification within 72 hours, to the response team designated as coordinator and to the European Union Agency for Cybersecurity. The essential requirements in Annex I, among them the coordinated vulnerability disclosure policy and the software bill of materials, become compulsory on 11 December 2027.
What happens if my company has already received de minimis aid?
It adds up. The ceiling is 300,000 euro over any period of three years, at the level of the single undertaking, that is together with the companies with which you have relations of control. The check is made before the award, through the State Aid Register and through the declaration on own responsibility. If the new aid were to exceed the ceiling, Article 3(7) of Regulation (EU) 2023/2831 says that the new aid no longer benefits from the regulation, so the clean solution is to ask for a smaller package or to wait until you are out of the three-year window.
When does the call open?
The act gives no date. The scheme applies from 28 September 2026, and the competitive call is organised by the Authority for the Digitalisation of Romania through NCC-RO. The moment of launch matters for the money as well: the conversion from euro into lei is made at the InforEuro rate for the month in which the call opens, so the ceilings in lei are fixed then.
What happens if the project is not carried through?
Where implementation is partial, the grant is reduced in proportion to the degree to which the deliverables and indicators have been produced. Where there is no implementation, the grant is not awarded, and the administrator may claim back in full the interim instalment of 30%. The sums recovered bear interest, calculated by adding 100 basis points to the one-year money-market rate and compounded annually, and the recovery decisions are enforceable titles.

Errors and inconsistencies in the published text

  • Article 4(2), Article 7(s) and (t) and Article 12(1)(d): the date from which the European obligations apply and the articles invoked. The scheme states three times that the obligations of coordinated vulnerability disclosure and of managing the inventory of software components „intră în vigoare începând cu septembrie 2026”, enter into force starting in September of that year, and attributes them to Articles 14 and 15 and to Article 13(6) of Regulation (EU) 2024/2847 respectively. Article 71(2) of the regulation provides that it applies from 11 December 2027, and that from 11 September 2026 only Article 14 applies. The coordinated vulnerability disclosure policy is required by Annex I, Part II, point 5, and the software bill of materials by Annex I, Part II, point 1, so both become compulsory on 11 December 2027. Article 13(6) deals with something else entirely, namely the manufacturer’s obligation to report a vulnerability in a component to whoever produces or maintains it, while Article 15 is voluntary reporting. What actually begins on 11 September 2026 is the notification of actively exploited vulnerabilities, within 24 and 72 hours respectively. The consequence is practical: the management training, compulsory in all four packages, is built on a wrong deadline, and the beneficiary company is left with the impression that it is already in breach for obligations that start in 14 months’ time.
  • Article 10(21): aid granted „pentru acea fracțiune care nu determină depășirea plafonului”, for that fraction which does not cause the ceiling to be exceeded. Article 3(7) of Regulation (EU) 2023/2831 provides that, where the granting of new aid would exceed the ceiling, „that new aid shall not benefit from this Regulation”, that is only the part which fits under the ceiling cannot be granted. The scheme offers two alternative solutions for the same situation, and the first contradicts the regulation that Article 2(2) of the same scheme declares applicable. A company close to the ceiling cannot find out from the act whether it receives a reduced grant or whether its application is rejected.
  • Article 12(6) and Article 18(10): references to the payment mechanism. The mechanism of the two instalments is laid down in Article 10(16). The first of the two refers to Article 10(11), which governs the drawing up of the applicant’s guide, while Article 18(10) refers to Article 10(8), which concerns the avoidance of an indirect economic advantage for the consortium leader. The immediately following paragraphs of the same articles, Article 12(7) and Article 18(13), refer correctly to Article 10(16). Article 12(6) is the only place where the reference is left without content, because it does not itself repeat the percentages.

Editorial analysis

The scheme solves a real problem and solves it at the right point. The cost of complying with the Cyber Resilience Act does not lie in licences or in equipment, but in the expert hours that establish what exactly has to change, and those are precisely what a manufacturer of equipment with twenty employees cannot afford. The lump-sum mechanism, with payment on deliverables and no settlement file, is the best part of the act. The rest, however, leaves the impression of a text written in haste.

The figure of 266 beneficiaries in Article 16 is not an estimate but a division. The budget of 2,000,000 euro divided by 7,500, the grant of package P1, gives 266.67, hence 266. In other words, the maximum estimated number assumes that absolutely all companies take the cheapest package. If they all took P4, the money would reach 44 companies. The real range is between 44 and 266, a difference of six times, and from it one can see that the figure displayed says nothing about how many companies will be helped. The same arithmetic, applied to consortia, gives between 54 and 88 projects in the optimistic scenario and between 9 and 14 in the pessimistic one, since a consortium counts between 3 and 5 companies.

The second observation comes from combining the calendar with the budget table. The scheme applies from 28 September 2026 until 31 March 2028 at the latest, that is 550 days. Of those, 94 fall in 2026, that is 17% of the duration. For 2026 the table allocates 600,000 euro, that is 30% of the budget. For that to be spent, in those 94 days the call must be launched, the projects lodged and assessed and the funding contracts signed, since the aid is deemed granted on the date the contract is signed. In package P1, 600,000 euro means 80 companies, that is between 16 and 26 consortia contracted by 31 December 2026. The deadline is tight to the point of being improbable, and the table has no line for the first quarter of 2028, although the scheme stays open until 31 March 2028.

The third observation concerns the fit between the list of CAEN codes and the substantive condition. The annex holds 18 codes, of which the group „Software și servicii IT”, software and IT services, has four, all of them service codes: bespoke software, consultancy, management of computing facilities and other IT services. Immediately afterwards, Article 9(3) narrows the support, for exactly this group, to the case where the product assessed is a product with digital elements placed on the market or a software component integrated into one, while the provision of services that does not lead to a product placed on the market stays outside the scheme. The entry filter and the substantive condition therefore pull in opposite directions, and a company that fits by code may fall by substance.

The fourth observation has to do with the asymmetry of the time limits. The administration is required to upload the measure to the State Aid Register within 10 working days, the granting acts within 7 and the payments within 10, and to send the decision to the Competition Council within 5 days at most. Towards the beneficiary, the only time limit in the scheme is the one of 60 days for the payment of the final instalment, which starts running only from the approval of the final technical report. When the report is approved, within what time the preliminary deliverables are accepted and within what time the interim instalment of 30% is paid is written nowhere. The provider therefore advances the services in full, without pre-financing and without any payment horizon.

What should be changed

  • Correcting the European dates in Articles 4, 7 and 12. The text should say that from 11 September 2026 Article 14 of Regulation (EU) 2024/2847 applies, the obligation to notify actively exploited vulnerabilities, and that the coordinated disclosure policy and the software bill of materials become compulsory on 11 December 2027. Without the correction, the training module compulsory in all packages teaches companies a wrong calendar, paid for out of public money.
  • A time limit for each step taken by the administrator. 30 working days for validating the preliminary deliverables, 30 for approving the final report and 30 for paying the interim instalment would make the scheme an instrument a small provider can finance from its own treasury. As it is written now, it favours providers with a cash reserve, that is precisely those who need it least.
  • A rule for the consortium that falls below three members. The scheme requires at least 3 companies at the time of lodging, but does not say what happens if one becomes ineligible or withdraws after the contract is signed. Three variants are possible, from replacing the partner through to terminating the whole project, and the choice among them cannot be left to the guide.
  • The estimated number of beneficiaries calculated on a distribution of packages, not on the cheapest one. An estimate of the type „40% P1, 30% P2, 20% P3, 10% P4” would give a verifiable figure and would show whether the scheme is aiming at a surface diagnosis or at a serious assessment. The present figure, 266, promises six times more than the scheme can deliver in the scenario in which companies actually buy what they need.
  • A route for the company without a consortium. A public list of providers looking for partners, kept by NCC-RO and updated for the duration of the call, would cost nothing and would solve the only barrier the scheme raises without acknowledging it: a company eligible in every respect, but unknown to any provider, has no way of reaching this money.

Original text of the legal act

The text below is reproduced in Romanian, the official form of publication.

The full text, as published in the Official Gazette of Romania

Official Gazette of Romania no. 821 of 28 September 2026, pages 4-14 16 pages PDF, 123 KB the act starts on page 4

Open the official PDFDownload the PDF

The viewer is not shown on small screens. Use the buttons above to open or download the file.

This article is for informational purposes only and does not constitute legal advice. For specific situations, consult a licensed attorney or tax advisor.