Cora SRL

Cybersecurity requirements

Two different situations that are constantly confused. A company can be obliged by law, or obliged by its contract with a larger customer. The second case affects far more companies and almost none of them know it applies to them.

Who it is for

Companies that have received a security questionnaire, an annex to a contract, or a supplier audit request from a larger customer, and do not know what is actually being asked of them.

And companies that suspect they fall under the national cybersecurity rules but have never checked. Since the registration deadline has already passed, this group has a problem that grows with time.

How it works

  1. Scope determination half a working day [?]

    Two questions, in this order. Does the company operate in one of the sectors listed in the annexes of the ordinance. And does it meet the size threshold. There are also entities covered regardless of size, so the second question does not always end the matter. The answer is a written position, not an opinion given over the phone, because you may have to show it.

  2. If you are in scope depends on the current state

    Registration with the national cybersecurity authority, which is overdue for most companies, and a gap analysis against the technical and organisational measures required by the ordinance. We tell you which measures you already meet without knowing it, which is usually more than expected.

  3. If you are not in scope, but your customer is one to two working days [?]

    We take the questionnaire or the contract annex as it came and translate it into what it actually means for your company. Most questionnaires large customers send are derived from the same underlying requirements, so the answers are reusable rather than written from scratch every time.

  4. The plan delivered in ten working days [?]

    Measures in the order in which they should be done, separating what costs nothing from what needs a budget. Three things almost always come first: a named contact for incidents, a tested restore from backup, and a list of the applications actually in use.

What you need to have already

  • Access to the company's IT provider or internal administrator.
  • The contract or questionnaire received from the customer, in full, annexes included.
  • Someone in management able to decide, because most of the measures are organisational, not technical.

What it does not include

  • Penetration testing, security monitoring or incident response services.
  • Certification against ISO 27001 or any other standard. We are not a certification body.
  • Installing or operating security software.
  • Legal representation before the authority.

What it is based on

The European network and information security directive, known as NIS2, was transposed in Romania by Government Emergency Ordinance 155/2024, in force since 30 December 2024 and approved with amendments by Law 124/2025. The competent authority is the National Cyber Security Directorate. Two implementing orders issued in August 2025 set out the registration process and the methodology for assessing an entity's risk level.

The deadline for notifying the authority in order to be entered in the register of essential and important entities expired on 22 September 2025. The authority has stated publicly that the obligation remains in force after that date, and that failure to register is an offence punishable by a fine of up to 500,000 lei.

National Cyber Security Directorate, registration of entities

Official page on the registration obligation under GEO 155/2024, with the notification forms and the applicable orders.

Registration page of the authority

Being out of scope does not mean the requirements do not reach you. Companies in scope have to manage the security of their supply chain, so they pass the requirements on to their suppliers through contracts. That is a contractual obligation, not a legal one, and the difference matters: it is negotiable, it has no registration duty attached, and no authority will fine you for it. Your customer can still terminate the contract.

The legal references on this page were verified in September 2026. This is a fast-moving area: check the current text of the ordinance and the authority's own communications before relying on anything here.