Regulation · 28 August 2026 · 8 min read
The NIS2 measures are now law — what changes from August 27
Romania's DNSC Order 1/2026 is in the Official Gazette: 218 concrete requirements, clear compliance thresholds, and a mandatory remediation plan. In plain language.
ClearSecurity Vision
On August 27, 2026, Official Gazette no. 712 (with the annexes in 712 bis) published Order no. 1/2026 of Romania’s National Cybersecurity Directorate (DNSC) — in force from day one. If the name means nothing to you, here is the translation: the concrete list of security measures that GEO 155/2024 (Romania’s NIS2 law) had been promising for almost two years is no longer a draft. It is law.
This article tells you, without legal language, what actually changed — and what to do first. At a few points along the way, the decision is yours.
What it was until yesterday, and what it is today
Until now, a company covered by NIS2 knew that it had to take security measures, but the official list of those measures existed only in working drafts. With a little goodwill, you could postpone: “we’re waiting for the final version.”
The final version has arrived. The order approves 218 concrete requirements — from “who is responsible for security in the company” to backups, passwords and what you do in an incident — organised into three levels of rigour: Basic, Important and Essential. Your level depends on how your company is classified and on its risk: the more society depends on you (energy, healthcare, transport, digital services…), the higher you go. The order also approves the scoring methodology: how it is measured, in black and white, whether you are compliant or not.
The excuse “nobody knows exactly what is required” expired on August 27.
Your company’s school grades
The methodology looks surprisingly like school. Every requirement gets two grades from 1 to 5: one for how well the rule is written down in your company (is there a procedure, is it owned, is it kept up to date?) and one for how well it is applied in reality. What counts is their average — you can have impeccable procedures on paper and it means nothing if nobody follows them.
As in school, there are also “core subjects”: 29 key measures where you are not allowed to do poorly, no matter how good your averages are elsewhere. The passing thresholds, in short:
- Basic: every key measure at least 2.5 and an overall average of at least 2.5;
- Important: every key measure at least 3 and an overall average of at least 3;
- Essential: every key measure at least 3, every chapter at least 3, and an overall average of at least 3.5.
You do not need to memorise the numbers. You need to remember the idea: there is now an official passing mark, and your company, like a pupil, has a report card — even if nobody has opened it yet.
The order is out. What do you do first?
A. Nothing. If an inspection ever comes, we'll deal with it then.
Until now, "we'll deal with it then" had an escape hatch: the list of requirements wasn't final. That hatch just closed. At an inspection or after an incident, the question will no longer be "did you know what you had to do?" but "why didn't you do it?" — and the fines in GEO 155/2024 are calculated from turnover.
B. I check whether and how the company is covered, then we grade ourselves, honestly, to know where we start from.
Exactly the right order: first find out whether the law applies to you, then do an honest self-assessment. You don't need a consultant to start: the free self-assessment gives you a first picture in about 10 minutes, no account needed.
C. I buy a ready-made set of procedures and put it in a binder. Compliance done.
That is precisely what the methodology cuts off at the root: you are graded both on paper and on reality — and the average is what counts. A beautiful binder with zero implementation doesn't pass the mark; worse, it becomes evidence that you knew what you had to do.
Failed the mark? The remediation plan is no longer optional
The good news: if your grades are below the threshold, the fine does not arrive the next day. The serious news: the order says that, when non-compliant, you are required to produce a remediation plan — what you fix, in what order, with what deadlines. Only one thing changed from yesterday, but it is a big one: the plan is no longer a best practice consultants recommend, it is a legal requirement.
Your company is at the Important level (threshold 3). Your key-measure average comes out at 2.8. What do you do?
A. Round it up. From 2.8 to 3 is a matter of interpretation.
Grades are given against written criteria in the methodology, not by feel — and at a verification, a "polished" assessment is worse than a low score: it shows bad faith, not a gap you are fixing.
B. I declare 2.8 and build the remediation plan on the gap: whatever lifts the key measures below 3 fastest, with deadlines and owners.
That is what the law asks, word for word: honesty plus a plan. An owned 2.8 with a plan and deadlines is a defensible position. A declared 3 unsupported by reality is not.
C. I redo the assessment with different answers until it comes out above 3.
The self-assessment is not a test you retake until you pass — it is your thermometer. If you shake it until it shows 36.6°C, the only person fooled is you: the real gaps remain, except now nobody in the company can see them.
”The banks are off the hook” — yes, but not the companies working for them
A less visible but important change: banks and financial-market institutions do not apply the measures in this order — they already have their own, stricter European regulation, called DORA. From this, some concluded that “IT companies working with banks are off the hook too.” It is exactly the other way around.
You run an IT company with banking clients. Does the order concern you?
A. No. Our clients are under DORA, so we are too.
The exemption belongs to the bank, not to you. Your company is still judged by its own NIS2 classification — and if you fall under the law as an IT service provider, the measures in the order are yours, thresholds included.
B. Yes, doubly: we answer for NIS2 for our own company, and the bank will additionally ask us for its own evidence, under DORA.
That is the reality: you are under two magnifying glasses at once. The upside — whoever does their NIS2 homework already has most of the answers the bank will demand at its next supplier review. Compliance becomes a sales argument, not just a cost.
C. I wait for the bank to ask for something and deal with it then.
Questionnaires from big clients arrive with short deadlines and no mercy — and the serious measures (accounts, backups, procedures) cannot be built in two weeks. Whoever waits for the question always answers badly.
3 things to do this week
- Establish in writing whether your company falls under GEO 155/2024 — and under which classification. If you did the exercise last year, redo it: the exemption for financial institutions (DORA) has just changed the board for some players.
- Grade yourself before someone else does. The free self-assessment is an honest 10-minute start; for the full report card, across all 218 requirements, with documents and deadlines, there is CERTO — one plan, with a 14-day trial, no card required.
- Name the person who owns this topic and give them their first deadline: the remediation plan for the gaps you found.
The short moral
For two years, NIS2 compliance looked like an exam announced without a syllabus: you knew it was coming, you didn’t know exactly what would be asked. Since August 27, the syllabus is published, the grades have criteria, and the passing mark is written in the Official Gazette. There is no need for panic — there is need for a report card you have actually started. The pupils who fail are not the ones with a 2.8 average and a catch-up plan; they are the ones who never opened the notebook.
This article is a plain-language explanation, not legal advice: for your company’s exact situation, the reference texts remain DNSC Order no. 1/2026 (Official Gazette 712 and 712 bis of 27.08.2026) and GEO 155/2024.
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.