NIS2 and Cybersecurity — Business Obligations in 2026

NIS2 and Cybersecurity — Business Obligations in 2026

NIS2 Directive — what every company needs to know

The NIS2 Directive (Network and Information Security Directive 2) is the most important European cybersecurity legislative framework, transposed into Romanian law through Law 362/2018 updated. From 2026, obligations expand significantly: not just critical infrastructure, but also supply chain companies, digital service providers, and medium entities in essential sectors.

Who falls under NIS2?

  • Essential entities — energy, transport, health, water, digital infrastructure, public administration, space
  • Important entities — industrial manufacturing, food, chemicals, postal/courier, waste management, research, digital services

Application threshold: entities with over 50 employees or turnover/assets exceeding 10 million EUR in targeted sectors. Note: suppliers to essential entities may be indirectly targeted through supply chain security requirements.

Main compliance requirements

  1. Risk assessment — periodic cyber risk analysis (minimum annual)
  2. Security policies — documented, management-approved, communicated to employees
  3. Incident management — detection, reporting (24h initial notification, 72h full report), and response procedures
  4. Business continuity — backup plans, disaster recovery, periodic testing
  5. Supply chain security — IT vendor assessment, contractual security clauses
  6. Encryption and access control — multi-factor authentication, least privilege principle
  7. Staff training — periodic cybersecurity training (mandatory annual)

Non-compliance penalties

  • Essential entities — fines up to 10 million EUR or 2% of global turnover
  • Important entities — fines up to 7 million EUR or 1.4% of global turnover
  • Management liability — executives can be held personally responsible

Practical NIS2 compliance steps

  1. Assess whether your organization falls under NIS2 (sector + size)
  2. Conduct a cybersecurity audit (gap analysis vs NIS2 requirements)
  3. Implement priority technical measures (MFA, backup, firewall, endpoint protection)
  4. Document security policies and procedures
  5. Establish incident response team and DNSC notification procedures
  6. Schedule periodic employee training

Need IT and cybersecurity services? The Geseidl Consulting Group team, CECCAR Prahova leader for 18 consecutive years, is ready to help. Discover our services or contact us for a free consultation.

Geseidl Consulting Group

CECCAR #1 Prahova · CAFR Rating A · ANEVAR · CCF #233 · ISO 9001:2015

Learn more about us →

Professional Accreditations

CECCAR #1 Prahova
CAFR Rating A
ANEVAR
CCF #233
ISO 9001:2015
ASPAAS
ANPC SAL - Solutionarea Alternativa a LitigiilorANPC SOL - Solutionarea Online a Litigiilor

Copyright ©2017-2026 Geseidl Consulting Group. All Rights Reserved.