Executive overview
CRA Compliance Funding
ADR launches a €2 million scheme covering up to 75% of eligible cybersecurity assessment and preparation costs, with grants of up to €45,000 per SME.
NIS2 Rules - Group-Level Cybersecurity Controls
DNSC allows essential entities to rely on centrally managed group controls, while retaining entity-level responsibility for documentation and effective implementation.
NIS2 Self-Assessments - Limited Flexibility
DNSC allows entities to exclude a limited number of non-applicable controls from self-assessments, subject to strict thresholds and documented justification.
Legislative Updates
CRA Compliance Funding
What is changing
ADR has approved and published a €2 million de minimis scheme to help Romanian SMEs assess and prepare for compliance with the Cyber Resilience Act (CRA). The scheme covers up to 75% of eligible cybersecurity assessment and preparation services, with grants of up to €45,000 per SME, targeting sectors including software, IoT, telecom and digital platforms.
Why this matters
Digital companies within the CRA’s scope can use the scheme to assess compliance gaps and prepare for upcoming requirements, while cybersecurity providers may see increased demand for specialised assessment services. The scheme does not cover implementation or remediation costs.
NIS2 Rules - Group-Level Cybersecurity Controls
What is changing
DNSC President has signed the decision clarifying how essential and important entities within corporate groups can apply and demonstrate compliance with cybersecurity requirements when policies, controls and governance are managed centrally. Companies may rely on group-level controls, but remain responsible for documenting their local application and demonstrating their effectiveness. The decision was already published in the Official Gazette.
Why this matters
NIS2 entities can avoid duplicating group-level cybersecurity controls, but must maintain clear local responsibilities, risk assessments and evidence of effective implementation. This should reduce compliance duplication while increasing documentation and accountability at entity level.
NIS2 Self-Assessments - Limited Flexibility
What is changing
According to a recent DNSC order, Romania now has rules for implementing cybersecurity requirements across corporate groups. It also allows essential and important entities to exclude a limited number of non-applicable controls from their self-assessments. Each exclusion must be justified and documented, while responsibility for effective implementation remains with the individual entity. The Order was already published in the Official Gazette and entered into force.
Why this matters
Group entities can rely on common cybersecurity measures, reducing duplication, but must maintain entity-level accountability and documentation. Limited exclusions are subject to strict thresholds and cannot cover mandatory controls.
Flexible Compliance for Electrical Equipment
What is changing
MEDAT has proposed rules transposing EU Directive 2024/2749, introducing temporary compliance and market surveillance procedures for low-voltage electrical equipment designated as crisis-relevant goods. Companies will be able to rely on EU-established standards and common specifications to demonstrate conformity while the internal market emergency regime is in force.
Why this matters
Manufacturers and other suppliers of covered equipment may use alternative EU conformity mechanisms during a crisis, reducing compliance barriers for essential products. The rules apply only to products formally designated as crisis-relevant and only for the duration of the emergency regime.
Anti-Kaspersky Law Extension
What is changing
A new bill registered with the Senate would extend until 31 December 2035 the existing ban on public authorities purchasing, installing or using Russian cybersecurity products and services – known as the anti-Kasperky Law. The current restriction is due to expire at the end of 2026.
Why this matters
Cybersecurity suppliers to the public sector will continue to face restrictions on Russian-origin products and services, with no new compliance or cost requirements for other market operators.