Aity Security · NIS2 readiness

We get your systems NIS2-ready, before the auditor arrives.

Aity Security prepares organisations in Romania for NIS2 (GEO 155/2024): a one-day assessment, an internal NIS2 readiness report and remediation of the gaps alongside your team. The official audit is done by an authorised auditor of your choice.

  1. 01One-day assessment
    Inventory, configurations, main risks.
  2. 02NIS2 readiness report
    Score per domain and gaps. Internal use.
  3. 03Remediation
    Policies, technical controls, logging, backup.
  4. 04Evidence file
    Available evidence, organised by requirement.
  5. →Authorised auditor
    Chosen by you. They do the official audit.
Our role, in short

Readiness and remediation, not an official audit or certification.

What we do
  • We assess infrastructure and processes against GEO 155/2024
  • We write an NIS2 readiness report for internal use
  • We implement the measures, alongside your team
  • We prepare the evidence file and support you during the audit
What we do not do
  • We do not perform the official cybersecurity audit
  • We do not replace your registration and reporting obligations to DNSC
  • We do not issue certifications
Not sure NIS2 applies?

We start with a 30-minute call about your activities, size and possible obligations. Classification may require documents and further checks.

Book the call
Step 01 · One day

Infrastructure and security assessment in a single day

One day of assessment within the agreed scope. The format, access requirements and report deadline are set out in the quote.

Standard
For the technical team
  • Infrastructure and access inventory
  • Baseline configuration review
  • Top 10 risks, with concrete steps
  • Technical report by the agreed deadline
Price on request
Executive
For leadership
  • Everything in Standard
  • 90-minute session with leadership
  • Risk map in business terms
  • 90-day plan, with owners
Price on request
Step 02 · NIS2 readiness report

Where you are, what is missing and in what order to fix it.

An internal document for your team and leadership, recording the requirements assessed, the evidence and the assessment limits. It does not replace the official audit or guarantee its outcome.

  • Readiness score for each NIS2 domain
  • Gaps against requirements, with missing evidence
  • Remediation plan prioritised by risk and effort
  • Time and effort estimate for each measure
  • One-page summary for leadership
Sample · NIS2 readiness reportInternal
Governance and accountability72%
Risk management48%
Incident handling35%
Continuity and backup60%
Supply chain28%
Access control and MFA81%
Illustrative values. Each report has your own domains and scores.
Step 03 · Remediation and readiness

We close the gaps with your team, not instead of it.

Verifiable measures, on your infrastructure or on Aity Cloud. Audit conclusions remain the auditor’s responsibility.

01
Agreed plan

We start from the report and agree the order, owners and deadlines together. You approve it before we start.

02
Implementation

Policies, technical controls, logging, backup, multi-factor authentication.

03
Evidence file

Available documents, configurations and records, organised by requirement, with gaps identified.

04
Audit support

We stand by your team during the official audit, done by an authorised auditor of your choice.

Who is in scope

Essential and important entities, across 18 sectors.

Classification depends on activities, size, financial data and relationships with other enterprises. Certain entities are in scope regardless of size. This sector list is indicative; we assess the specific situation under GEO 155/2024.

  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space
  • Postal and courier services
  • Waste management
  • Chemicals
  • Food
  • Manufacturing
  • Digital providers
  • Research
FAQ

Frequently asked questions

Is the NIS2 readiness report sent to DNSC?
It is intended for internal use, not submission as an official audit report. The service does not replace legal duties to report or respond to requests from the authority.
Who does the official audit?
An authorised cybersecurity auditor of your choice. We prepare you and support you, but we do not audit.
How long does preparation take?
It depends on the gaps. The report includes a time and effort estimate per measure, so you can plan budget and deadlines.
Do we have to move to Aity Cloud?
No. We work on your infrastructure. Aity Cloud is an option if you also want Romanian hosting in the same project.
Book a call

30 minutes with a security engineer, not a sales rep.

We discuss possible classification, what you already have and where to start. The initial call does not create a contractual commitment.

What do you need?