In brief
- A company that belongs to a group no longer has to write all its own cybersecurity policies. It can demonstrate compliance using the group’s documentation, provided it formally adopts it, and the decision sorts the requirements into three kinds: inherited from the group, implemented locally and shared.
- The evidence and the measurements stay with the company, wherever the policy is written. The act says expressly that the maturity level is measured for the entity, that evidence of implementation and metrics must exist at its level, and that responsibility for effective application does not pass to the group.
- It applies from 21 September 2026, with no transition period and no new requirements. The 218 controls, the maturity stages and the target scores stay as they were set by the order of 27 August 2026; what changes is who supplies the document and who supplies the proof.
Published: Official Gazette of Romania (Monitorul Oficial) no. 798 of 21 September 2026, pages 7-10
In force from: 21 September 2026, the date of publication, because the decision provides for no later date
Companies that form part of a group of enterprises have had, since 21 September 2026, their own way of demonstrating that they meet the cybersecurity requirements. Decision of the director of the National Cyber Security Directorate no. 3/2026, published in the Official Gazette of Romania no. 798 of 21 September 2026, approves precisely the rules to which the order of 18 September 2026 referred without saying when they would appear. Three days passed between the two acts, although both were signed on 14 September 2026.
The decision has four articles and an annex running to three pages. It adds no security requirement and changes no threshold. Article 3 states plainly that the rules neither amend nor supplement the controls, the maturity stages, the target scores and the calculation rules in the order that turned the 218 requirements into a closed list; they set out how those requirements apply when governance, strategy and risk management are defined at group level and cascade down to the subsidiary.
The audience is wider than it looks. These rules cover any essential or important entity that forms part of a group, including small firms that do not think of themselves as part of one: the Romanian subsidiary of a foreign manufacturer, the service company inside a local holding, the distributor owned by a regional chain. For all of them, the implicit rule until now was that each entity produces its own documentation.
The core of the decision is a model with three types of control. Inherited controls are those whose governance, decision making, management and assurance are exercised at group level, with the entity relying on them directly. Implemented controls are governed by group standards but carried out, supervised and assured through the entity’s own structures. Shared controls are those where responsibilities are split between the entity and the group. Whatever the type, the text repeats one general principle: the entity is answerable for demonstrating effective implementation within its own scope.
The annex then works through the six functions of the catalogue and says, for each, where the control usually sits. Govern, with six categories, and Detect, with two, are normally defined and operated respectively at group level. Identify, with three categories, is implemented mainly locally, using the group’s methods and tools. Protect, with five categories, Respond, with four, and Recover, with two, are shared. Added up, the catalogue’s 22 categories break down as follows: 8 can normally rest on the group’s shoulders, 11 are shared, and 3 remain, in practice entirely, the task of the Romanian company.
The rule for assessing maturity is put in a single sentence that changes a great deal in practice: the maturity level reflects the degree to which a control is documented, implemented, measured and improved for the entity, whether it is defined at group level or at its own. An entity can reach any level using group controls, on two conditions: the documentation must be formally applicable to it, and evidence of implementation and metrics must exist at its level.
A three row table turns this into scoring criteria. For an inherited control, documentation maturity is measured against the group documentation formally applicable to the entity, and implementation maturity against its effective and consistent use within the entity’s scope. For an implemented control, the documentation is the entity’s and so is the implementation. For a shared control, the documentation is the group’s together with the entity’s additions, and implementation means joint operation and execution by the entity.
The rest of the annex sets out the five maturity stages, from Initial to Optimising, read through the lens of the group, with the same exception thresholds as in the August order: under 5% for documentation and under 10% for implementation at stage 3, under 3% and under 5% at stage 4, under 0.5% and under 1% at stage 5. Two short notes, printed separately, are the ones that matter most to a subsidiary: stage 4 requires measurement at local level even where the tools belong to the group, and stage 5 can be reached only if the entity contributes actively rather than merely taking the group’s controls as they come.
The annex closes with an example of a wrong assessment, put there precisely because it is the typical mistake: the entity has no policy of its own, so it scores itself at stage 1. The correct assessment, the act says, is a different one: the entity formally adopts a group policy, so documentation maturity turns on approval, applicability, review and the handling of exceptions.
What it changes in practice
The immediate effect is that a subsidiary already working to the group’s policies no longer risks a score of 1 on documentation for each of the 218 controls. The score is given on the group document, provided it has been officially approved and declared applicable to the entity. The difference is large: the self-assessment calls for two whole scores from 1 to 5 for every control, that is, 436 scores at the Essential level, each justified in writing.
The second effect, less comfortable, is that formal adoption becomes something to document. It is not enough for the group policy to exist and to be good; there must be an internal act by which the Romanian entity takes it on, with a written trace. A group document used in practice but never formally adopted falls to stage 1 exactly as if it did not exist.
The third effect touches the technical side. For detection controls, which the decision describes as centrally operated, the entity has to demonstrate three things of its own: that its systems and services are genuinely within the scope of the group’s monitoring, that there are local responsibilities for handling and escalating alerts, and that it has acted on detection results relevant to its own environment. A service contract with the group’s security operations centre does not, on its own, cover any of the three.
The fourth effect is on the score. For the Essential level, the August order requires an overall score of at least 3.5 and at least 3 in every category. Since the overall score is the average of the 22 categories, an entity sitting at the minimum of 3 in most of them reaches 3.5 only if it takes at least 6 categories to the maximum, that is, to 5. Group support helps with documentation, but those 6 top categories call for local metrics, and local metrics cannot be outsourced.
The fifth effect concerns liability. The act repeats three times, in three different formulations, that the entity remains answerable. The practical consequence is that the fine under the cybersecurity law falls on the Romanian entity, not on the group, even for a control inherited in full from the group.
What has changed compared with the previous situation
Until 18 September 2026, the August order said nothing about groups. Every essential or important entity implemented the controls of its assurance level, under Article IV of that order, and the self-assessment was carried out on its own documents. A subsidiary with no policies of its own, working from the group’s manuals, had nothing in the text to let it score its documentation at anything other than 1.
On 18 September 2026 a paragraph (3) was added to Article III of the order, referring entities within groups to applicability rules approved by a decision of the director. The paragraph was operative from the date of publication, but the decision did not yet exist. Three days later, it appeared.
What is new in substance amounts to four things: an official vocabulary for the types of control, a rule that ties maturity to the entity rather than to where the document is written, a correspondence table between the type of control and the two dimensions of the score, and a reading of the five stages written from the group’s perspective. What is not new: no requirement, no threshold, no deadline.
What has not changed, and would have mattered just as much, is the annual obligation. The self-assessment of the maturity level is carried out and sent to the Directorate every year, under Article 12(4) of Government Emergency Ordinance no. 155/2024, and essential entities also send a remediation plan within 30 days of completing it. The decision touches neither the frequency, nor the deadline, nor the content of the plan.
Advantages and disadvantages
What it improves
- It solves a real and very widespread problem: hundreds of Romanian subsidiaries work to policies written in another country, and the August methodology did not recognise them.
- It frames the rule in terms of outcome, not form: maturity is measured for the entity, wherever the document was drafted.
- It supplies a common vocabulary, inherited, implemented and shared, which was missing and which auditors and the Directorate can now use in the same way.
- It weakens nothing. Article 3 expressly blocks any use of the rules as a loophole, and the two notes on stages 4 and 5 cut off the convenient reading.
- It expressly corrects the costliest self-assessment mistake, scoring documentation at 1 because none exists locally.
- The exception thresholds reproduced in the annex match, all five of them, those in the August order, so the rules do not put a second set of figures into circulation alongside the first.
What remains a problem
- The notion that triggers the whole thing, the group of enterprises, is defined neither in the decision, nor in the order that empowers it, nor in the emergency ordinance underpinning the entire framework.
- The text reads like a guide rather than a rule. Formulations of the „în mod obișnuit” and „în general” kind, usually and in general, describe common practice but do not say what happens when an entity departs from it.
- There is no deadline anywhere. None for the formal adoption of the group documentation, none for putting in place the local metrics stage 4 demands.
- The heading of the assessment chapter speaks of „grup de entități”, a group of entities, while the rest of the act speaks of „grup de întreprinderi”, a group of enterprises, and „entity” is a defined term in the ordinance.
- The exception thresholds are reproduced without the basis of calculation from the parent order, where they are counted „din cazuri”, out of cases, which leaves room for working the percentage out on controls instead.
- Nothing covers the situation where the group refuses or drags its feet. A subsidiary that cannot obtain the approved document from the parent company is left with the low score and no lever written into the act.
Practical advice
- First check whether you are an essential or important entity and at what assurance level. The rules do not change the classification, but it still determines how many controls you owe: 34 at Basic, 133 at Important and all 218 at Essential.
- Take stock of the group documents you rely on and check, for each one, whether there is an act of adoption at the level of the Romanian company. That is the only thing separating stage 1 from the stages above it.
- Classify every control as inherited, implemented or shared before you start scoring. The correspondence table in the annex says what is scored in each case, and a wrong classification changes both scores.
- Do not confuse coverage with evidence. Where monitoring is done by the group, ask for reports that concern your own systems, not a generic confirmation that the service exists.
- Put on paper the local responsibilities for handling and escalating alerts, even if the monitoring sits with the group. The decision requires them expressly, and they cannot be borrowed.
- If you are aiming at the Essential level, start with metrics. Stage 4 requires local measurement even where the tool belongs to the group, and without local metrics you will not get past stage 3 even on inherited controls.
- Document the deviations and exceptions specific to the Romanian company. Stages 3, 4 and 5 require them to be documented, approved and tracked, not merely tolerated in practice.
- Negotiate access to the evidence of periodic review of the documentation with the group early. Without it stage 4 is out of reach, and the review calendar is not yours to set.
Frequently asked questions
From when does it apply?
Is there a transition period?
What does „group of enterprises” mean for the purposes of the decision?
Can my company drop its own security policies?
What stays compulsory at the level of each company?
Does the number of requirements I have to meet change?
Who is answerable if the group fails to do its part?
How large are the fines?
Is the self-assessment done differently now?
What do I do if I am not sure my company is part of a group?
Errors and inconsistencies in the published text
- The title of the decision, Article 1, Article 2 and the annex, throughout. The act defines its scope by the phrase „entitățile care fac parte dintr-un grup de întreprinderi”, entities forming part of a group of enterprises, but it does not define that phrase and refers to no text that would. Nor does Article III(3) of Order of the director of the National Cyber Security Directorate no. 1/2026, the basis invoked in the preamble, and the phrase does not appear at all in Government Emergency Ordinance no. 155/2024, where neither Article 3, the definitions article, nor the rest of the text uses it. Romanian law has close and defined notions, linked enterprises and partner enterprises, in Articles 44 and 43 of Law no. 346/2004, and the ordinance refers to that law in Article 8, for classifying entities by size; the decision makes no such reference. The consequence is that an entity with common shareholders cannot work out from the text whether the rules apply to it, even though how it scores documentation maturity for every applicable control depends on the answer, and failure to comply with the obligation in Article 11(1) of the ordinance is an administrative offence under Article 60(1)(a), punishable by a fine of up to 10,000,000 euro or 2% of net turnover.
Editorial analysis
The decision solves a genuine problem and solves it in the right direction. The August methodology was written for an entity that drafts its own rules, whereas the economic reality of Romania’s essential and important entities is largely another: subsidiaries, branches and group companies that receive the policy from above and carry it out below. Refusing to recognise group documentation would have produced, mechanically, a mass of self-assessments at stage 1 that would have said nothing about the actual security of those networks. The fact that the act puts liability back on the entity, three times and in three formulations, shows the authors also saw the opposite risk, that of the group becoming an excuse.
The quality of the execution is uneven, though, and this shows up most clearly in the counting. The annex describes, function by function, where the control usually sits, but it never says how much that amounts to. Adding up the categories it itself lists, 6 under Govern, 3 under Identify, 5 under Protect, 2 under Detect, 4 under Respond and 2 under Recover, you reach the catalogue’s 22 categories, split into 8 that can rest on the group, 11 shared and 3 that stay local. In other words, on half the catalogue responsibility is joint, and on a little over a third it can be taken over by the group. This is the figure a compliance officer looks for in the first minute, and the act leaves the reader to work it out.
The second uncalculated figure is the heavier one. At the Essential level, the August order requires an overall score of at least 3.5, obtained as the average of the scores of the 22 categories, and at least 3 in each category. If an entity sits at the permitted minimum in most categories, the average reaches 3.5 only if at least 6 of the 22 are taken to the maximum, that is, to 5. Group support does not help there: a score of 5 requires, according to the very note printed in the annex, that the entity contribute actively and demonstrate continuous improvement with metrics of its own. The rule that appears to ease compliance does not touch the most expensive part of it at all.
The third thing visible only when you set the acts side by side is the timing. The order of 18 September 2026 introduced a paragraph written in the present tense, obliging entities within groups to implement the requirements in accordance with rules approved by decision, and the decision appeared three days later. For those three days, the rule pointed to a text that did not exist. This is not an isolated slip: both acts were signed on 14 September 2026, so the order of publication was a choice, not a constraint. And from the entry into force of the catalogue, on 27 August 2026, to these rules, 25 days passed in which entities within groups worked to a methodology that did not recognise their situation. The comparison with the deadlines imposed on the addressee says the rest: the company is required to self-assess every year, to justify each score in writing and, if it is essential, to produce a remediation plan within 30 days, while the administration set itself no deadline at all for its own additions.
What should be changed
- Defining the group by reference to a text that exists. A single sentence pointing to Articles 43 and 44 of Law no. 346/2004 would close the act’s largest uncertainty and spare thousands of companies a question they currently have nowhere to put.
- Numbering the annex by articles and paragraphs. The rules are written as a guide with headings and lists, without a single citable unit. A supervisory authority cannot invoke „the second bullet under stage 4”, and a normative act that cannot be cited cannot be applied uniformly either.
- Replacing „usually” with a rule and an exception. The annex says Detect is usually operated centrally. It should say what happens when it is not: the entity is on its own for that control and scores it as implemented, not as inherited.
- A deadline for the formal adoption of the group documentation. The act makes formal adoption the condition for any score above 1, without saying by when. A deadline, even one of 90 days from publication, would turn a tacit expectation into a verifiable obligation.
- Settling on one phrase. The heading of the assessment chapter says „grup de entități”, the rest of the act says „grup de întreprinderi”, and „entity” is a defined notion in the ordinance. A single term, used throughout, removes a needless ambiguity.
- Closing the sanction gap on the annual self-assessment. This is not a matter for the present decision, but it bears on it directly: Article 60(2) of Government Emergency Ordinance no. 155/2024 allocates the fines by letter, and letter (e), failure to carry out and submit the annual self-assessment, appears for essential entities and appears under none of the categories provided for important entities. An important entity that never carries out the self-assessment this decision explains has, as the ordinance now stands, no applicable fine.
Original text of the legal act
The text below is reproduced in Romanian, the official form of publication.
The full text, as published in the Official Gazette of Romania
Official Gazette of Romania no. 798 of 21 September 2026, pages 7-10 16 pages PDF, 102 KB the act starts on page 7
Open the official PDFDownload the PDF
The viewer is not shown on small screens. Use the buttons above to open or download the file.
This article is for informational purposes only and does not constitute legal advice. For specific situations, consult a licensed attorney or tax advisor.
