Now that we as a society have managed to get past the margarine vs. butter dilemma, we can turn our attention back to the more down-to-earth problems organizations face.
Last week, on August 27, 2026, DNSC took another step toward completing the picture of the NIS2 governance framework and published Order No. 1/2026 in the Official Gazette (Part I, No. 712), the act that finally adds more concrete details to Romania’s NIS2 framework. If until now many companies have been asking themselves, “yes, but what do we actually need to do?”, this order is the answer.
Here’s a brief overview of what has changed and, more importantly, what you need to do.
What’s New in Order No. 1/2026
The order approves three essential pieces of the NIS2 puzzle:
- Cybersecurity risk management measures (Annex 1) — essentially, the concrete list of technical and organizational controls that essential and important entities must implement. The measures are structured around six functions: governance, identification, protection, detection, response, and recovery. For the first time, companies have a clear reference framework, rather than just the general principles taken from the directive.
- Maturity self-assessment methodology (Annex 2) — a tool that allows each entity to assess for itself how mature its implementation of security measures is across each of the six functions above.
- Amendment of the Risk Level Assessment Methodology (the one from August 11, 2025, approved through DNSC Order No. 2/2025) — DNSC is adjusting the rules used to determine an entity’s risk level, which directly influences how complex its compliance obligations will be.
Why It Matters for Your Company
If your company is already registered with DNSC as an essential or important entity (or is currently being assessed for such classification), this order is no longer theory — it is your homework assignment:
- You now have a clear standard against which to compare your existing security measures, instead of working “by guesswork” based on the wording of the European directive.
- The maturity self-assessment is now an official tool, rather than an optional internal exercise — DNSC will use it as a reference in its supervisory and control activities.
- The risk level calculated for your company can directly influence the complexity of the requirements you need to meet — it is worth checking whether the changes to the methodology affect your classification.
What We Recommend You Do in the Coming Weeks
- Read Annex 1 and map the required measures across the six functions (governance, identification, protection, detection, response, recovery) against what you already have in place. In most cases, a significant portion of the controls already exists in another form (ISO 27001, internal policies) — they simply need to be “translated” into the language of the order.
- Run the maturity self-assessment from Annex 2 as soon as possible. It will clearly show you where you are strong and where you have gaps, before DNSC asks you the same questions during an inspection or as part of an official audit.
- Check your risk classification — if you operate in a sector with increased requirements (banking, financial market infrastructures, energy), the changes to the methodology are worth reading carefully, as they may change the applicable thresholds.
- Don’t leave this to one person. Governance is the first of the six functions in the order, and not by accident — company leadership needs to be involved, not just the IT team.
A Final Thought
NIS2 has not been “something that’s coming” for quite some time now. It’s here, the rules are written in black and white, and there is a schedule of assessments. The good news is that, unlike a year ago, you now have a concrete guide to build your compliance program around — not just vague principles to interpret.
If you want to go through Annex 1 and the self-assessment methodology together with someone who has already read them dozens of times, the FORT team is here to help.
Andrei, Chief Revenue Officer, FORT