RO EN

Initial Assessment

Free

The first step toward NIS2 compliance. We quickly assess whether your organization falls under the NIS2 Directive and identify the main priorities.

What's included:

  • Classification determination (essential vs. important entity)
  • Preliminary assessment of cybersecurity maturity level
  • Identification of applicable requirements
  • General recommendations for next steps
Duration: 1-2 hours
Request free assessment

NIS2 gap analysis

Thorough analysis of the organization's security posture vs. NIS2 requirements. We identify exactly what's missing and establish a prioritized action plan.

What's included:

  • Complete assessment against all Art. 21 NIS2 requirements
  • Mapping to standards (ISO 27001, NIST CSF)
  • Supply chain security assessment
  • Detailed report with identified gaps and recommendations
  • Prioritized remediation plan with timeline
Duration: 2-6 weeks
Request a custom quote

Compliance Implementation

We implement the measures from the remediation plan: policies, technical controls and governance structures, ready for DNSC.

What's included:

  • Development/update of security policies and procedures
  • Risk management framework implementation
  • Technical controls implementation guidance
  • Supply chain security program
  • Business continuity & disaster recovery
  • Governance structure establishment
  • DNSC documentation preparation
Duration: 3-12 months
Request a custom quote

Outsourced NIS2 Officer

Monthly subscription

GEO 155/2024 (approved by Law 124/2025) requires each entity subject to NIS2 to designate a NIS2 Officer (responsible person). This function can be fully outsourced, without the need to hire and train specialized internal personnel.

Why is this function mandatory?

According to Romanian NIS2 transposition legislation, each organization subject to NIS2 must have a NIS2 Officer who:

  • Has cybersecurity competencies and managerial authority in relation with management
  • Coordinates all NIS2 compliance activities of the organization
  • Represents the organization in relation with DNSC
  • Manages incident reporting according to legal deadlines (24h/72h/1 month)
  • Ensures periodic review of security measures

Why outsource the NIS2 Officer function?

Reduced cost vs. hiring

An internal cybersecurity specialist typically costs 3,000–5,000 EUR/month gross salary. Outsourcing starts from 290 EUR/month — a fraction of the cost, with certified competence.

Immediate designation

The DNSC notification deadline (September 2025) has expired, and the officer must be designated within 30 days of DNSC's decision. Through outsourcing, you fulfill the designation obligation immediately and start compliance work without months of recruitment and training.

Experience across organizations

An outsourced officer works with multiple organizations, accumulating diverse experience across different sectors and risk types — experience that is hard to build in a single in-house role.

Choose the right level:

Basic

from 290 EUR/month
  • Certified NIS2 Officer
  • DNSC registration and notifications
  • Quarterly review
  • Risk register maintenance
  • Quarterly compliance report
  • Email support (24h response)
  • Legislative changes updates
Request quote

Premium

from 800 EUR/month
  • Everything in Standard, plus:
  • Monitoring every two weeks
  • 2 internal assessments/year
  • Board meeting participation (1/quarter)
  • Priority support (2h response, incl. weekends)
  • Full incident response coordination
  • Annual tabletop exercise
  • Annual employee awareness session
Request quote

Why we start with a NIS2 diagnostic

GEO 155/2024 requires the entity to submit to DNSC its risk level assessment (art. 11, ENIRE@RO methodology) and its yearly maturity self-assessment (art. 12). At contract start we deliver these assessments as a NIS2 diagnostic that includes:

  • Risk level assessment — ENIRE@RO methodology (DNSC)
  • Maturity level self-assessment
  • Critical gap identification and prioritization
  • Remediation plan with deadlines

NIS2 diagnostic cost: from 990 EUR (depending on organization size and complexity). Billed once, at contract start.

Monthly subscription price depends on organization size and complexity. Minimum 12-month contract. The NIS2 diagnostic is performed at contract start.

Cybersecurity Consulting & Awareness

Art. 14 of GEO 155/2024 requires both management and all staff to have adequate cybersecurity knowledge. We offer consulting and awareness sessions adapted to each level within the organization.

Types of sessions:

  • NIS2 awareness sessions for management and board
  • Cybersecurity technical consulting for IT teams
  • Incident response awareness sessions
  • Cyber hygiene sessions for employees
  • Tabletop exercises and incident simulations
Request a custom quote

Cyber Incident Support

NIS2 requires reporting within 24h/72h. We provide response procedures and support in case of incidents.

What's included:

  • Response plans aligned with NIS2 deadlines
  • Incident detection and classification procedures
  • Support for reporting to DNSC / national CSIRT
  • Post-incident review and lessons learned
Request a custom quote

All prices are expressed excluding VAT.

Request a free NIS2 assessment

Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.

Request free assessment