Governance, Risk & Compliance

NIS2 Readiness & Implementation

From 'are we in scope?' to a registered, evidenced, defensible compliance position.

The situation

NIS2 is transposed and enforceable across the Union — in Romania through GEO 155/2024 as approved and amended by Law 124/2025, supervised by DNSC, with registration and risk-methodology procedures set by DNSC Orders 1/2025 and 2/2025. Management bodies are personally accountable and can be held liable.

We take an organisation from scope determination through registration, gap assessment, remediation and the evidence pack that makes an inspection uneventful.

What the client receives

Schedule of deliverables

  1. 01Scope and entity classification (essential / important) with written justification
  2. 02National registration support (DNSC in Romania; equivalent authority elsewhere)
  3. 03Gap assessment against the Art. 21 measures and Art. 23 reporting duties
  4. 04Prioritised remediation roadmap with owners, cost and dates
  5. 0524h / 72h / 1-month incident notification procedure and templates
  6. 06Management-body accountability briefing and training record
  7. 07Inspection-ready evidence pack

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • Directive (EU) 2022/2555
  • RO: GEO 155/2024, Law 124/2025
  • DNSC Orders 1 & 2/2025
  • Commission Implementing Regulation (EU) 2024/2690
  • ISO/IEC 27001

Discuss this engagement

Tell us about your entity, its sector and where you stand on registration and we will set out the scope, the method and the reporting format.

Contact us