Through Decision of the Director of the National Cyber Security Directorate no. 3/2026 for the approval of the Norms on the applicability of cybersecurity requirements for entities that are part of a group of undertakings, published in Official Gazette no. 798 of September 21, 2026, the manner in which subsidiaries in Romania can demonstrate compliance with cybersecurity obligations by using group-level policies and resources is clarified.
What does it stipulate?
The Decision establishes a framework through which a local entity, part of a group, can fulfill cybersecurity requirements (imposed by NIS 2 legislation) by relying on governance, strategies, and risk management defined at the central level. The fundamental principle is that, regardless of where policies are defined, the entity in Romania remains directly responsible for demonstrating their effective local implementation. The normative act does not introduce new obligations but offers a compliance methodology for group-type structures.
The Norms define three models for the applicability of security controls. Controls can be taken over, meaning entirely managed at the group level, with the local subsidiary directly adopting them (e.g., a centralized security operations center). They can be implemented, meaning governed by group standards, but executed and supervised by the subsidiary’s local structures (e.g., management of local IT assets according to group methodology). The third model is that of shared controls, where responsibilities are divided between the group and the local entity (e.g., management of a security incident).
The act details how these models apply to key security functions. As a rule, Governance policies are taken over from the group. Asset Identification and risk assessment activities are implemented locally, using the group’s methodology. Protection measures (access control, data security) are often shared. Threat Detection services are usually centralized (taken over), while incident Response and Recovery processes are coordinated at the group level, but executed jointly with the local team.
An important aspect is how to assess the maturity of controls in the context of mandatory self-assessment. An entity can achieve a high level of maturity even if it uses controls defined at the group level. The condition is that it can demonstrate that the group’s documentation is formally applicable at the local level and that there is concrete evidence (metrics, reports) of effective and consistent implementation within the operational perimeter of the entity in Romania.
To whom does it apply?
The Norms apply exclusively to essential and important entities (defined according to the legislation transposing the NIS 2 Directive) that are part of a group of undertakings, regardless of whether the group is national or multinational. Therefore, the target entities are subsidiaries, branches, or other legal entities in Romania that depend on a central structure (parent company) for defining and implementing cybersecurity policies.
What should you do?
- Clarify the cybersecurity governance model (taken over, implemented, or shared) applicable in the relationship with the group for each category of security control.
- Formally document how group-level policies, standards, and procedures are adopted and applied at the level of the entity in Romania, including any approved local exceptions or adaptations.
- Prepare specific evidence (inventories, local risk assessments, audit reports, minutes) to demonstrate the effective local implementation of controls for the purpose of self-assessment of maturity.
Source: Official Gazette, Part I, no. 798 of September 21, 2026.
Note: This material is strictly for informational purposes and does not constitute legal, fiscal, or business advice. As the interpretation and application of legal provisions can vary significantly depending on the specific circumstances of each entity, we recommend seeking specialized legal assistance before adopting any operational decisions based on these changes.