We get your systems NIS2-ready, before the auditor arrives.
Aity Security prepares organisations in Romania for NIS2 (GEO 155/2024): a one-day assessment, an internal NIS2 readiness report and remediation of the gaps alongside your team. The official audit is done by an authorised auditor of your choice.
- 01One-day assessmentInventory, configurations, main risks.
- 02NIS2 readiness reportScore per domain and gaps. Internal use.
- 03RemediationPolicies, technical controls, logging, backup.
- 04Evidence fileAvailable evidence, organised by requirement.
- →Authorised auditorChosen by you. They do the official audit.
Readiness and remediation, not an official audit or certification.
- We assess infrastructure and processes against GEO 155/2024
- We write an NIS2 readiness report for internal use
- We implement the measures, alongside your team
- We prepare the evidence file and support you during the audit
- We do not perform the official cybersecurity audit
- We do not replace your registration and reporting obligations to DNSC
- We do not issue certifications
We start with a 30-minute call about your activities, size and possible obligations. Classification may require documents and further checks.
Book the callInfrastructure and security assessment in a single day
One day of assessment within the agreed scope. The format, access requirements and report deadline are set out in the quote.
- Infrastructure and access inventory
- Baseline configuration review
- Top 10 risks, with concrete steps
- Technical report by the agreed deadline
- Everything in Standard
- 90-minute session with leadership
- Risk map in business terms
- 90-day plan, with owners
Where you are, what is missing and in what order to fix it.
An internal document for your team and leadership, recording the requirements assessed, the evidence and the assessment limits. It does not replace the official audit or guarantee its outcome.
- Readiness score for each NIS2 domain
- Gaps against requirements, with missing evidence
- Remediation plan prioritised by risk and effort
- Time and effort estimate for each measure
- One-page summary for leadership
We close the gaps with your team, not instead of it.
Verifiable measures, on your infrastructure or on Aity Cloud. Audit conclusions remain the auditor’s responsibility.
We start from the report and agree the order, owners and deadlines together. You approve it before we start.
Policies, technical controls, logging, backup, multi-factor authentication.
Available documents, configurations and records, organised by requirement, with gaps identified.
We stand by your team during the official audit, done by an authorised auditor of your choice.
Essential and important entities, across 18 sectors.
Classification depends on activities, size, financial data and relationships with other enterprises. Certain entities are in scope regardless of size. This sector list is indicative; we assess the specific situation under GEO 155/2024.
- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water
- Waste water
- Digital infrastructure
- ICT service management (B2B)
- Public administration
- Space
- Postal and courier services
- Waste management
- Chemicals
- Food
- Manufacturing
- Digital providers
- Research
Frequently asked questions
Is the NIS2 readiness report sent to DNSC?
Who does the official audit?
How long does preparation take?
Do we have to move to Aity Cloud?
30 minutes with a security engineer, not a sales rep.
We discuss possible classification, what you already have and where to start. The initial call does not create a contractual commitment.