In brief

  • Companies and institutions that the law calls essential or important entities now have a closed list of 218 cybersecurity requirements A later order, DNSC Order no. 2/2026, shows under what conditions some of these requirements can be declared non-applicable., grouped into six functions and 22 categories, each with its own code and its own implementation guidance.
  • The requirements apply on three levels of rigour: 34 controls at the Basic level, 133 at the Important level and all 218 at the Essential level. The level of each entity follows from the risk assessment carried out under the 2025 methodology.
  • Compliance is not declared, it is calculated: every requirement receives two marks from 1 to 5, one for documentation and one for implementation, and the averages have to clear fixed thresholds, 2.5 at Basic and 3.5 at Essential. Whoever falls short draws up a remediation plan.
Act: DNSC Order no. 1/2026
Published: Official Gazette of Romania (Monitorul Oficial) no. 712 and no. 712 bis of 27 August 2026
In force from: 27 August 2026

Until now, a company covered by the cybersecurity law knew it had to manage its risks, but did not know exactly what was being asked of it. From 27 August 2026 it knows, requirement by requirement, across the 321 pages of the annexes. Order no. 1/2026 of the director of the National Cyber Security Directorate, published in Official Gazette of Romania no. 712 of 27 August 2026, approves the catalogue of cybersecurity risk-management measures for essential and important entities, together with the methodology by which every entity measures for itself how far it is from compliance. It is the piece that was missing from the structure begun with Government Emergency Ordinance no. 155/2024 and continued, over the summer, with the single register of public digital infrastructure.

The order itself has six articles and fits on a single page. The weight sits in the two annexes, published separately, in edition no. 712 bis of the same day, which run to 324 pages. Annex no. 1 contains the measures. Annex no. 2 contains the methodology for self-assessing maturity.

The structure of Annex no. 1 follows a pattern that anyone who has worked with the international security standards will recognise: six functions, called Govern, Identify, Protect, Detect, Respond and Recover. Each function splits into categories, each category into subcategories, and at the end of the chain sit the controls, that is, the requirements themselves. A control can be a process, a policy, a device or a practice. Each has a code of the form GV.OC-01.1, in which the first two letters give the function, the next two the category, and the digits the subcategory and the position.

The count, taken from the applicability table at the end of the annex: 218 controls, distributed 79 to Protect, 55 to Identify, 40 to Govern, 22 to Detect, 14 to Respond and 8 to Recover. Of these, 29 are marked as key measures, meaning they have to be treated as a priority, and 15 correspond to the management aspects that standard ISO/IEC 17021-1 requires of auditors: impartiality, competence, responsibility, openness, confidentiality, the handling of complaints and a risk-based approach.

What it changes in practice

The first practical consequence is that the conversation about compliance moves from principles to a list. There is no longer room to interpret what „măsuri adecvate”, appropriate measures, means: there are 218 rows, each with the wording of the requirement and with implementation guidance explaining what should be taken into account.

The same move from principle to list was made for the sustainability data asked of a small company: a large customer may ask a supplier with at most 1,000 employees for no more than 23 data points.

The second consequence is that not all entities owe the same thing. The controls apply across three assurance levels, in increasing order of rigour. The Basic level covers 34 controls and rests on technologies and processes that are generally available already. The Important level rises to 133 and targets attackers with limited resources. The Essential level covers all 218 controls and is built to withstand sophisticated attacks. The levels nest inside one another, so an entity at Essential also owes everything that those at Basic owe.

Which level applies to a particular entity is not decided by this order. The level follows from the risk level, determined under the methodology approved a year ago by DNSC Order no. 2/2025, published in Official Gazette of Romania no. 776 of 20 August 2025.

The third consequence touches the financial sector. The order amends Article 6 of that methodology and lifts the obligation to assess their own risk level from the entities in the banking sector and in the financial market infrastructures to which the European regulation on digital operational resilience, known as DORA, applies. They apply the measures in the regulation, not these ones. The same exemption goes to firms in digital infrastructure and in the management of ICT services between companies, when they are designated essential ICT third-party service providers under the same regulation. The idea is simple: whoever is already under an equivalent European regime does not go through the same check twice.

The fourth consequence is the appearance of a statement of applicability. Where an entity is also subject to special or sectoral rules on top of the general ones, the requirements implemented as a result of those are set out in a document of its own, drawn up by the entity.

The same logic of evidence of its own was carried further to firms that form part of a group: through Decision no. 3/2026, the Directorate established that a subsidiary may rely on the group’s policies, but the evidence has to be its own.

At banks, cybersecurity has meanwhile entered the capital calculation as well. From 23 September 2026, losses from fraud, error and system failures are counted on a common grid of 26 categories, and one of the additional tags is named after ICT risk related to cybersecurity.

What has changed compared with the previous situation

Before this order, the framework existed but was hollow inside. Government Emergency Ordinance no. 155/2024, approved with amendments and additions by Law no. 124/2025, established the obligation of essential and important entities to manage their cybersecurity risks and referred, for the content, to acts that the director of the Directorate was to issue. In August 2025 the first piece appeared, the criteria and methodology for assessing the risk level, which said how exposed an entity is. What was missing was the answer to the next question, namely what it actually has to do given that exposure.

The second thing that changes is the way of measuring. Until now, compliance was an assertion. From now on it is a number, obtained through the same arithmetic for everyone, which makes two entities from different sectors comparable.

The third thing is the tool. The Directorate provides the NIS2@RO platform and, if the platform does not work, assessment tools downloadable from the institution’s website, one for each level: EVAL_MMS_B for Basic, EVAL_MMS_I for Important, EVAL_MMS_E for Essential. The alternative to the platform is written into the act, not left to an announcement.

Advantages and disadvantages

What it improves

  • The requirements are listed, not vaguely described. A company can draw up a checklist and can know what an auditor will look at.
  • Every control comes with implementation guidance, so the act explains the how as well, not only the what.
  • Proportionality is real: 34 requirements for the least exposed, against 218 for the most exposed.
  • The exemption for entities already under the DORA regulation avoids regulating the same banks and market infrastructures twice.
  • The self-assessment has public numerical thresholds, so an entity knows in advance where the line is, instead of finding out during an inspection.
  • There is an offline route as well, through the downloadable tools, for when the platform is unavailable.

What remains a problem

  • The order enters into force on publication, with no transition period. The 218 controls become due on the day they were printed.
  • The self-assessment methodology sets no deadline: neither when the first assessment is made, nor how often it is repeated.
  • Nowhere does it say that the result of the self-assessment or the remediation plan is sent to the Directorate. It remains an internal exercise, with an effect that is hard to verify.
  • The annexes are published in a separate edition, which has to be bought. The act that tells companies what to do is not as accessible as the order approving it.
  • The compliance threshold for each key measure rests on a quantity that the methodology does not define.
  • The statement of applicability has no form, no minimum content, no deadline and no addressee.

Practical advice

  1. Check first whether you are an essential or an important entity and at what risk level. Without that you do not know whether 34 or 218 requirements concern you, and the difference in effort between the two ends is enormous.
  2. If you are a bank, a financial market infrastructure or a designated ICT service provider under the DORA regulation, stop here: do not carry out the risk assessment and apply the European regulation instead. Do check your classification in writing, though, because the exemption depends on it.
  3. Start with the 29 key measures, not with the first page of the catalogue. They have a threshold of their own and are required to be treated as a priority.
  4. Write down your justifications from the outset. The methodology requires every mark from 1 to 5 to be argued in writing, and reconstructing the arguments six months later costs more than writing them now.
  5. Look at the exception thresholds in the definition of the stages: stage 3 tolerates under 5% documented exceptions and under 10% process deviations, stage 4 drops to 3% and 5%, and stage 5 to 0.5% and 1%. In practice, that is where the mark comes from.
  6. If you already hold a certification against an information security standard, do the mapping onto the 22 categories first. The 15 controls linked to the management aspects come from the same family and can be covered with existing evidence.
  7. Draw up the statement of applicability even though the act gives it no form. It is the only place where it shows why you implemented a requirement from a sectoral rule and not from this catalogue.

Frequently asked questions

From when does it apply?
From publication, that is, from 27 August 2026. The order sets no transition period and does not postpone the application of any control.
Who falls under these measures?
The essential and important entities defined by Government Emergency Ordinance no. 155/2024, approved with amendments and additions by Law no. 124/2025. The sectors are those in Annex no. 1 to the ordinance.
How many requirements do I have to meet?
It depends on the assurance level that applies to you: 34 controls at the Basic level, 133 at the Important level and 218 at the Essential level. The levels nest, so the top one contains those below it.
How do I find out which level I am at?
From the assessment of the entity’s risk level, carried out under the methodology approved by DNSC Order no. 2/2025, published in Official Gazette of Romania no. 776 of 20 August 2025. The present order does not change that assessment, it only exempts from it the entities under the DORA regulation.
What does key measure mean?
A control marked as a priority on the basis of the common types of cyberattack. There are 29, of which 13 apply from the Basic level already. They have a compliance threshold of their own, separate from the overall score.
How is the maturity score calculated?
Every control receives two whole marks, from 1 to 5, one for documentation and one for implementation. The average is taken per subcategory, then per category, then the average of the two marks gives the category score, and the average of the category scores gives the entity’s total score.
What threshold has to be reached?
At the Basic level, a total score of at least 2.5. At the Important level, at least 3. At the Essential level, at least 3 on each category and at least 3.5 overall. Key measures have a separate threshold: 2.5 at Basic and 3 at the other two.
What happens if I do not reach the thresholds?
The entity is required to draw up a plan of measures for remedying all the shortcomings that led to the non-compliance, with the actions to be taken and the deadlines it undertakes for implementation.
Where do I find the full text of the 218 controls?
In Official Gazette of Romania no. 712 bis of 27 August 2026, the edition with the annexes, 324 pages long. That edition is attached to this article in PDF format, below.

Errors and inconsistencies in the published text

  • Annex no. 2, Article 2 paragraph (11). The compliance thresholds are referred to the „scorul-țintă al fiecărui Control marcat ca Măsură cheie”, the target score of every control marked as a key measure, that is, to a single score per control. Nowhere does the methodology define such a quantity. Paragraph (1) assigns each control two distinct values, documentation maturity and implementation maturity, and paragraphs (6) to (9) describe how these are aggregated at subcategory, category and entity level. The average of the two marks is calculated explicitly only at category level, through paragraph (8), not at control level. The consequence is that a key control marked 2 for documentation and 3 for implementation can be read equally as meeting the 2.5 threshold of the Basic level, if the average is taken, and as failing it, if the threshold is required on each of the two marks separately. The two readings lead to opposite results, and on the result hangs the obligation in Article 3 of the same annex, drawing up the remediation plan. That the quantity is missing can also be seen from paragraph (10), which speaks of the „scorurile pe Controale”, the scores per control, without their ever having been defined, and from the fact that the 2.5 threshold cannot be reached by a whole mark from 1 to 5, the only kind of value that paragraph (1) assigns to a control.

Editorial analysis

The act solves a real problem, and solves it well. For almost two years, a company covered by the cybersecurity law had an obligation without content: it had to manage its risks, but nobody told it at what level of detail. The catalogue now closes that gap with 218 numbered requirements, each with implementation guidance, and with a three-level scale that genuinely differentiates the effort, from 34 controls to 218. The choice to borrow the six-function structure from the established international framework is not convenience, it is a practical advantage: an entity that already holds a certification can map its evidence instead of starting again from scratch.

The weak part is not the content, but the timetable and the flow of information. The order enters into force on publication, and Article VI provides for no staging. An entity at the Essential level owes, from 27 August, 218 controls, some of which call for policies approved by management, formalised processes and evidence for all activities. Nobody builds that overnight, so the rule is born with a mass non-compliance that nothing in the act acknowledges or manages. The previous order in the same series, the one from August 2025, had a whole year before this one followed it; entities are not given even a month.

The second gap is just as visible. The self-assessment methodology describes in minute detail how the marks are calculated, but is entirely silent on what happens to them. It does not say when the first assessment is made, at what interval it is repeated, to whom the result is sent, or what becomes of the remediation plan, whose deadlines are, in the wording of the act, self-assumed, that is, set by the very party that has to meet them. A compliance mechanism that ends in a file left on the entity’s computer measures something, but changes nothing.

What should be changed

  • A deadline for application, differentiated by level. Six months for the Basic level and twelve for Important and Essential would turn a rule that is broken from the first day into an achievable one, without lowering the final standard.
  • A definition of the score per control. A single sentence in Article 2 of Annex no. 2, saying that the score of a control is the arithmetic mean of the two marks, would close the ambiguity above and make the 2.5 threshold applicable without interpretation.
  • A deadline and a frequency for the self-assessment. Without them the obligation exists in theory and cannot be breached in practice, because there is no way of establishing when it should have been carried out.
  • A clear route for the result. Either sending the score to the Directorate at a fixed interval, or keeping it available to the inspection bodies, with a retention period. Today the act provides for neither the one nor the other.
  • Free publication of the annexes on the Directorate’s website. Requirements binding on thousands of entities sit in an edition of the Official Gazette of Romania that has to be bought. The Directorate already publishes the assessment tools on its own website, so it would be natural to publish the list those tools measure as well.
  • A minimum content for the statement of applicability. Article III requires it but gives it neither form, nor deadline, nor addressee, so two entities will draw it up in ways that cannot be compared.

Original text of the legal act

The text below is reproduced in Romanian, the official form of publication.

The full text, as published in the Official Gazette of Romania

Official Gazette of Romania no. 712 and no. 712 bis of 27 August 2026 16 pages PDF, 114 KB the act starts on page 5

Open the official PDFDownload the PDF

The other editions cited: nr. 712 bis/2026

The viewer is not shown on small screens. Use the buttons above to open or download the file.

This article is for informational purposes only and does not constitute legal advice. For specific situations, consult a licensed attorney or tax advisor.