In brief
- Companies and institutions covered by the cybersecurity law can leave out of the self-assessment the requirements that have nothing to do with their activity, but very few of them: one at the Basic level, three at the Important level and five at the Essential level. Every exclusion is justified in writing, with the reason why the requirement does not fit.
- The heaviest requirements can never be taken out. The 29 key measures stay mandatory at any level, and at the Essential level so do the 15 requirements about the way the organisation is run. The Basic level has 34 requirements, 13 of them key measures, so the choice is made among the other 21 and can fall on a single one.
- Companies that belong to a group get separate rules, which do not yet exist. The order says they will implement their requirements under applicability rules approved by a decision of the director of the Directorate, without saying when that decision appears or what happens until then.
Published: Official Gazette of Romania (Monitorul Oficial), Part I, no. 792 of 18 September 2026, page 10
In force from: 18 September 2026, the date of publication, because the order provides for no later date
The National Cyber Security Directorate has opened a way out of the list of requirements it imposed on companies in August. Order no. 2/2026 of the director, published in Official Gazette of Romania no. 792 of 18 September 2026, supplements the act by which the 218 cybersecurity requirements became a closed list for essential and important entities and adds two things to it: a limit on how far an organisation can declare that a requirement does not apply to it, and a new rule for organisations that belong to a group.
The order has two articles, fits on one page and contains no new security requirement. Its entire content is two interventions in the August order. The first adds a paragraph to Article III of that order. The second adds a whole article, Article 4, to Annex no. 2, the methodology by which each organisation measures for itself how far it is from compliance. The order was signed on 14 September 2026 by the director, Dan-Petre Cîmpean.
The part that changes something for thousands of companies is the new article in the methodology. Until now the self-assessment was done by giving every applicable requirement two whole marks, from 1 to 5, one for documentation and one for implementation. From now on a requirement can be taken out of the reckoning, by ticking the non-applicability option for both marks, within fixed limits: at most one control at the Basic level, at most three at the Important level and at most five at the Essential level.
The limits sound generous until the first count. The applicability table in Annex no. 1, published in edition no. 712 bis of 27 August 2026, shows 34 requirements at the Basic level, 133 at the Important level and all 218 at the Essential level. Of these, 29 are marked as key measures and 15 as management aspects, one of them marked in both ways. The new order forbids taking out key measures at any level, and at the Essential level it also forbids taking out management aspects. That leaves 21 eligible requirements at the Basic level, 111 at the Important level and 175 at the Essential level, out of which one, three and five respectively can be given up.
A requirement that is taken out does not disappear from the calculation; it enters with a value set by the order: 2.5 at the Basic level and 3 at the Important and Essential levels. The exclusion is justified in writing and recorded in the statement of applicability, the document the organisation already drew up for requirements coming from special or sectoral rules. And if an organisation goes over the ceiling or touches a forbidden requirement, the order says the exclusions are not taken into account and the self-assessment is not treated as compliant until it is put right.
The long title of the order can mislead, because it also mentions the methodology for assessing the risk level of entities. Nothing changes there: that phrase is part of the August order’s own title and does not describe what the new order does.
What it changes in practice
The first effect is an acknowledgement that was missing: not every requirement in the catalogue fits every organisation. A company with no industrial control systems, a hospital that does not develop its own software or a transport operator with no online shop had to give marks, until 17 September 2026, to a requirement with no subject matter in their case, and the low marks pulled the average down. From 18 September that requirement can be taken out of the reckoning.
The second effect is that the way out is too narrow to become a strategy. One control out of 34, three out of 133 and five out of 218 amount to between 2.3 and 2.9% of the applicable requirements at all three levels. The ceilings are, in other words, proportional to one another, which rarely happens in an implementing act. No organisation can rewrite its obligations through exclusions.
In another field the cap works the other way round, in the small firm’s favour: sustainability questionnaires stop at 23 data points, and at 9 for suppliers with at most 10 employees.
The third effect touches the most severe level and works the opposite way round from what it looks like. The compliance thresholds in the methodology are a total score of at least 2.5 at the Basic level, at least 3 at the Important level, and at the Essential level at least 3 in each category and at least 3.5 overall. The value with which an excluded requirement enters is 2.5 at Basic and 3 at the other two. At the first two levels the value coincides with the threshold, so the exclusion is neutral. Only at Essential does the value of 3 sit half a point below the general threshold of 3.5, and there every requirement taken out pulls the average down.
The fourth effect is documentary. The written justification and the statement of applicability become the place where it shows why an organisation considered that a requirement did not concern it. That matters, because the self-assessment does not stay inside the company’s computer: Article 12(4) of Government Emergency Ordinance no. 155/2024, approved with amendments and additions by Law no. 124/2025, requires it to be carried out annually and sent to the Directorate, and paragraph (5) of the same article gives essential entities 30 days to send the remediation plan as well. A badly argued exclusion therefore lands on the authority’s desk.
The fifth effect has not happened yet. The rule for organisations in groups refers to a decision of the director of the Directorate that had not appeared in the Official Gazette of Romania by 18 September 2026, and the order sets it no deadline. Until it is published, a company owned within a group has to go on reading Article IV of the August order, the one that ties the obligation to the entity’s own assurance level.
The decision appeared three days later, on 21 September 2026, and says that a subsidiary can prove its cybersecurity with the group’s policies, provided the evidence is its own.
What has changed compared with the previous situation
Until 17 September 2026 the self-assessment methodology knew no exceptions. Article 2(2) of Annex no. 2 said, without any reservation, that filling in the two marks for every control was mandatory, and paragraph (1) of the same article allowed only whole values from 1 to 5. A requirement that made no sense for a particular organisation still had to be marked, and the low mark went into the averages by subcategory, by category and by entity. From now on there is an exit, with a ceiling, with a list of untouchable requirements and with a replacement value.
The second change concerns who owes what. The August order tied the obligation to a single quantity, the entity’s assurance level, and the size of the entity is established, under Article 8 of Government Emergency Ordinance no. 155/2024, by reference to Law no. 346/2004 on stimulating the setting-up and development of small and medium-sized enterprises. Neither the ordinance nor the 2004 law uses the notion of a group of enterprises: the law speaks of linked enterprises and partner enterprises. The new order brings in, for the first time in this framework, the idea that belonging to a group changes the way requirements are implemented, but leaves the content of that change to a future act.
The third change is one that has not taken place, although the title suggests it. The Methodology for assessing the risk level of entities, approved by Order no. 2/2025 of the director of the Directorate and published in Official Gazette of Romania no. 776 of 20 August 2025, stays as it was left in August, with the exemption from assessment for the banks and market infrastructures covered by the European regulation on digital operational resilience. The act published on 18 September touches no article in it.
The issuer’s working rhythm has changed as well. The August order was signed on 6 August 2026 and published on 27 August, 21 days later. This one was signed on 14 September and published on 18 September, 4 days later, and 22 days after the act it supplements entered into force.
An IT incident does not stop at the compliance report. For credit institutions it turns into money set aside: the capital required for operational risk is 12% of the business indicator as long as that stays below one billion euro, then 15% and 18% on the tiers above, and from 23 September 2026 the losses that feed that calculation are classified on a single European grid.
Advantages and disadvantages
What it improves
- It acknowledges a fact: a catalogue of 218 requirements written for every sector also contains things with no subject matter at a particular organisation.
- The ceilings are proportional, between 2.3 and 2.9% of the applicable requirements at each level, so the mechanism cannot be used to empty out the obligation.
- The heaviest requirements stay out of the discussion: all 29 key measures, at any level, plus the 15 management aspects at the Essential level.
- An exclusion is not an anonymous tick: it calls for a written reason and goes into the statement of applicability, so it leaves a trail that can be checked.
- The value with which an excluded requirement enters the calculation is written into the act, not left to the logic of the calculation tool.
- The order says what happens when the ceiling is exceeded, instead of leaving the consequence unwritten.
What remains a problem
- The non-applicability option does not exist in the methodology. Article 2(1) allows only whole marks from 1 to 5, paragraph (2) requires both marks to be filled in for every requirement, and neither has been amended.
- The replacement value of 3 sits, at the Essential level, below the general threshold of 3.5, so an exclusion meant as relief weighs the score down.
- The notion of a group of enterprises is defined neither in the order, nor in the ordinance behind it, nor in the law the ordinance refers to for the size of entities.
- The applicability rules for groups have no adoption deadline and no transitional rule, although the order speaks in the present tense.
- Nowhere does it say whether an exclusion holds until it is challenged or is taken again at each annual self-assessment, with the justification redone.
- The 9 management requirements within the Important level can be taken out of the self-assessment, although Annex no. 1 requires their status to be reviewed at every audit of the assurance level.
Practical advice
- Check first which assurance level you are at. It determines both how many requirements you owe and how many you can take out of the self-assessment: one, three or five.
- Count what you are actually left to choose from, not the whole catalogue. Eligible are 21 requirements at the Basic level, 111 at the Important level and 175 at the Essential level, once the key measures and, at Essential, the management aspects are removed.
- If you are at the Essential level, do the sums before you tick. The requirement taken out enters with 3 while the general threshold is 3.5, so every exclusion calls for extra points elsewhere.
- Write the justification on the day you take the decision, not when the inspection arrives. The order requires the reasons why the requirement is not applicable to be stated, and reconstructing them a year later costs more than writing them down now.
- Do not go over the ceiling, not even by one requirement. The consequence is a self-assessment that is not compliant until it is put right, not a score adjustment, so the work has to be done again.
- If the company belongs to a group, do not wait for the decision on the applicability rules. Until it is published, the obligation remains the one in Article IV of the August order, that is, your own assurance level.
- Record the exclusions in the statement of applicability, next to the requirements coming from sectoral rules. It is the only document in which both directions, what is added and what is taken out, can be seen together.
Frequently asked questions
When does it apply from?
How many requirements can I take out of the self-assessment?
Which requirements cannot be taken out at all?
How is a requirement marked as not applicable?
With what value does an excluded requirement enter the calculation?
What happens if I exceed the ceiling?
My company belongs to a group. What changes for me?
Has anything changed in the methodology for assessing the risk level?
Is the self-assessment sent to anyone?
Errors and inconsistencies in the published text
- Article I point 1, the new paragraph (3) of Article III. An entity that belongs to a group of enterprises implements the requirements „în conformitate cu regulile de aplicabilitate aprobate prin decizie a directorului DNSC”, in accordance with the applicability rules approved by decision of the DNSC director. The provision is written in the present tense, so it works from 18 September 2026, yet it refers to a decision which, being normative, ought to be published in the Official Gazette of Romania, Part I, under Article 7(4) of Government Emergency Ordinance no. 104/2021, and which had not appeared there on that date. There is no deadline for adopting the decision and no rule for the interval until it appears. Beyond that, the notion of a group of enterprises is defined neither in Government Emergency Ordinance no. 155/2024, nor in Law no. 346/2004, to which the ordinance refers through Article 8 for classifying entities by size and where the notions used are those of linked enterprises and partner enterprises. A company whose majority shareholder is a legal person can conclude either that it still owes the controls of its own assurance level, under Article IV of Order no. 1/2026, or that its obligation is determined by rules that have not yet been written.
- Article I point 2, the new Article 4(1) of Annex no. 2. The exclusion is made by selecting the „N/A” option for both parameters laid down by Article 2(1), but Article 2(1) knows no such option: it assigns each of the two parameters a whole-number value from 1 to 5. Worse, Article 2(2) of the same annex says that filling in the two score variables is mandatory for every control, without any reservation, and the new order does not amend it. A reader in good faith can conclude either that Article 4, as a new and special text, derogates from Article 2(2), or that the duty to fill them in has remained whole and that a self-assessment with blank marks is incomplete. Whether the annual self-assessment required by Article 12(4) of Government Emergency Ordinance no. 155/2024 is compliant depends on that outcome.
Editorial analysis
The order solves a real problem. A catalogue of 218 requirements written for every sector listed in the annexes to the ordinance inevitably contains requirements with no subject matter at a particular organisation, and the August methodology forced them to be marked anyway, with a direct effect on the average. The ceilings chosen, one, three and five requirements, are well calibrated too: set against the 34, 133 and 218 applicable requirements at the three levels, they come to 2.9%, 2.3% and 2.3%, a share that is almost constant. Someone did the arithmetic before writing the text, which is not the rule in implementing acts.
What was not calculated is the replacement value. The three figures in Article 4(3), 2.5 at Basic and 3 at Important and Essential, are exactly the thresholds that Article 2(11) sets for each key measure: 2.5, 3 and 3. Except that the key measures are precisely the requirements that cannot be taken out of the self-assessment. The value was therefore taken from the column that does not apply. Taken from the right column, that of the entity’s total score, the figures would have been 2.5, 3 and 3.5. At the first two levels the two columns coincide and the discrepancy does not show. At the Essential level they part by half a point, and the consequence is that relief turns into a penalty.
How large the penalty is cannot be read off the act, because the total score is an average of averages, not an average of the 218 requirements: it is taken by subcategory, then by category, then by entity. The control codes show, at the Essential level, 22 categories and 90 subcategories. The weight of one requirement in the final score is therefore not 1/218, or 0.46%, but depends on how many requirements its subcategory holds, and a requirement alone in its subcategory, within a category that has two subcategories, weighs 1/44, or 2.27%. Five exclusions picked among the heaviest cover 11.4% of the total score, and that portion stays fixed at 3. An organisation that would have scored exactly 3.5 on everything else comes out at 3.44 and fails the threshold, without having lowered its mark on anything. Using the way out pushes it out of compliance.
The second imbalance is one of timing, and it is an old one in this series of acts. The organisation is asked for a written justification for every exclusion, an annual self-assessment sent to the authority and, for essential entities, a remediation plan within 30 days. For the group applicability rules, on which what some of those same organisations actually owe depends, the order gives the administration no deadline at all. The August order also entered into force on publication, with no transition period, and its first supplement came 22 days later, signed and published within 4 days. The haste on one side sits next to the silence on the other.
What should be changed
- Raising the replacement value to 3.5 for the Essential level. It would make an exclusion neutral, as it already is at the other two levels, and would remove the situation in which an organisation fails the threshold precisely because it used a facility the law gives it.
- The non-applicability option should be written into Article 2 of Annex no. 2. One sentence in paragraph (1), adding it next to the values from 1 to 5, and an exception in paragraph (2) would close the contradiction with the duty to fill in the marks for every control.
- A deadline for the decision on groups and a rule for the interval until it comes. Either 90 days and the application of Article IV until then, or postponing the paragraph until the decision is published. As things stand, the text requires compliance with rules that do not exist.
- Defining the group by reference to notions that already exist. Articles 43 and 44 of Law no. 346/2004 define partner enterprises and linked enterprises, and the cybersecurity framework refers to that law in any case. A cross-reference would spare everyone a new and undefined term.
- A deadline for putting right exclusions above the ceiling. As things stand the self-assessment is not compliant until it is put right, with no indication of by when, which leaves an annual obligation suspended for an indefinite period.
- Stating whether an exclusion is taken again at each self-assessment. A requirement that is not applicable in 2026 can become applicable in 2027 if the organisation changes what it does, and the act does not say whether the justification has to be redone each year.
Original text of the legal act
The text below is reproduced in Romanian, the official form of publication.
The full text, as published in the Official Gazette of Romania
Official Gazette of Romania no. 792 of 18 September 2026, page 10 16 pages PDF, 151 KB the act starts on page 10
Open the official PDFDownload the PDF
The viewer is not shown on small screens. Use the buttons above to open or download the file.
This article is for informational purposes only and does not constitute legal advice. For specific situations, consult a licensed attorney or tax advisor.
