NIS2 Services
One partner for NIS2 compliance: diagnostic, implementation and an outsourced officer
Initial Assessment
FreeThe first step toward NIS2 compliance. We quickly assess whether your organization falls under the NIS2 Directive and identify the main priorities.
What's included:
- Classification determination (essential vs. important entity)
- Preliminary assessment of cybersecurity maturity level
- Identification of applicable requirements
- General recommendations for next steps
NIS2 gap analysis
Thorough analysis of the organization's security posture vs. NIS2 requirements. We identify exactly what's missing and establish a prioritized action plan.
What's included:
- Complete assessment against all Art. 21 NIS2 requirements
- Mapping to standards (ISO 27001, NIST CSF)
- Supply chain security assessment
- Detailed report with identified gaps and recommendations
- Prioritized remediation plan with timeline
Compliance Implementation
We implement the measures from the remediation plan: policies, technical controls and governance structures, ready for DNSC.
What's included:
- Development/update of security policies and procedures
- Risk management framework implementation
- Technical controls implementation guidance
- Supply chain security program
- Business continuity & disaster recovery
- Governance structure establishment
- DNSC documentation preparation
Outsourced NIS2 Officer
Monthly subscriptionGEO 155/2024 (approved by Law 124/2025) requires each entity subject to NIS2 to designate a NIS2 Officer (responsible person). This function can be fully outsourced, without the need to hire and train specialized internal personnel.
Why is this function mandatory?
According to Romanian NIS2 transposition legislation, each organization subject to NIS2 must have a NIS2 Officer who:
- Has cybersecurity competencies and managerial authority in relation with management
- Coordinates all NIS2 compliance activities of the organization
- Represents the organization in relation with DNSC
- Manages incident reporting according to legal deadlines (24h/72h/1 month)
- Ensures periodic review of security measures
Why outsource the NIS2 Officer function?
Reduced cost vs. hiring
An internal cybersecurity specialist typically costs 3,000–5,000 EUR/month gross salary. Outsourcing starts from 290 EUR/month — a fraction of the cost, with certified competence.
Immediate designation
The DNSC notification deadline (September 2025) has expired, and the officer must be designated within 30 days of DNSC's decision. Through outsourcing, you fulfill the designation obligation immediately and start compliance work without months of recruitment and training.
Experience across organizations
An outsourced officer works with multiple organizations, accumulating diverse experience across different sectors and risk types — experience that is hard to build in a single in-house role.
Choose the right level:
Basic
- Certified NIS2 Officer
- DNSC registration and notifications
- Quarterly review
- Risk register maintenance
- Quarterly compliance report
- Email support (24h response)
- Legislative changes updates
Standard
- Everything in Basic, plus:
- Monthly review (not quarterly)
- Monthly compliance report
- Incident management support (24h/72h)
- 1 annual internal assessment
- Annual documentation update
- Email + phone support (4h response)
- 1 management awareness session/year
Premium
- Everything in Standard, plus:
- Monitoring every two weeks
- 2 internal assessments/year
- Board meeting participation (1/quarter)
- Priority support (2h response, incl. weekends)
- Full incident response coordination
- Annual tabletop exercise
- Annual employee awareness session
Why we start with a NIS2 diagnostic
GEO 155/2024 requires the entity to submit to DNSC its risk level assessment (art. 11, ENIRE@RO methodology) and its yearly maturity self-assessment (art. 12). At contract start we deliver these assessments as a NIS2 diagnostic that includes:
- Risk level assessment — ENIRE@RO methodology (DNSC)
- Maturity level self-assessment
- Critical gap identification and prioritization
- Remediation plan with deadlines
NIS2 diagnostic cost: from 990 EUR (depending on organization size and complexity). Billed once, at contract start.
Monthly subscription price depends on organization size and complexity. Minimum 12-month contract. The NIS2 diagnostic is performed at contract start.
Cybersecurity Consulting & Awareness
Art. 14 of GEO 155/2024 requires both management and all staff to have adequate cybersecurity knowledge. We offer consulting and awareness sessions adapted to each level within the organization.
Types of sessions:
- NIS2 awareness sessions for management and board
- Cybersecurity technical consulting for IT teams
- Incident response awareness sessions
- Cyber hygiene sessions for employees
- Tabletop exercises and incident simulations
Cyber Incident Support
NIS2 requires reporting within 24h/72h. We provide response procedures and support in case of incidents.
What's included:
- Response plans aligned with NIS2 deadlines
- Incident detection and classification procedures
- Support for reporting to DNSC / national CSIRT
- Post-incident review and lessons learned
All prices are expressed excluding VAT.
Request a free NIS2 assessment
Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.
Request free assessment