# Aity Security: NIS2 readiness assessment in Romania

Source: https://aity.tech/security

A one-day assessment, an internal NIS2 readiness report and remediation with your team, under GEO 155/2024. An authorised auditor does the official audit.

## We get your systems NIS2-ready, before the auditor arrives.

ink

Aity Security · NIS2 readiness

Aity Security prepares organisations in Romania for NIS2 (GEO 155/2024): a one-day assessment, an internal NIS2 readiness report and remediation of the gaps alongside your team. The official audit is done by an authorised auditor of your choice.

steps

search

**One-day assessment**

Inventory, configurations, main risks.
report

**NIS2 readiness report**

Score per domain and gaps. Internal use.
wrench

**Remediation**

Policies, technical controls, logging, backup.
folderCheck

**Evidence file**

Available evidence, organised by requirement.
user

**Authorised auditor**

Chosen by you. They do the official audit.

Book a call

#apel

What the report contains

#raport

## Readiness and remediation, not an official audit or certification.

tint

Our role, in short

What we do

What we do not do

Not sure NIS2 applies?

We start with a 30-minute call about your activities, size and possible obligations. Classification may require documents and further checks.

- We assess infrastructure and processes against GEO 155/2024
- We write an NIS2 readiness report for internal use
- We implement the measures, alongside your team
- We prepare the evidence file and support you during the audit

- We do not perform the official cybersecurity audit
- We do not replace your registration and reporting obligations to DNSC
- We do not issue certifications

Book the call

#apel

## Infrastructure and security assessment in a single day

page

Step 01 · One day

One day of assessment within the agreed scope. The format, access requirements and report deadline are set out in the quote.

Standard

For the technical team

Price on request

- Infrastructure and access inventory
- Baseline configuration review
- Top 10 risks, with concrete steps
- Technical report by the agreed deadline
Executive

For leadership

Price on request

- Everything in Standard
- 90-minute session with leadership
- Risk map in business terms
- 90-day plan, with owners

## Where you are, what is missing and in what order to fix it.

raport

card

Step 02 · NIS2 readiness report

An internal document for your team and leadership, recording the requirements assessed, the evidence and the assessment limits. It does not replace the official audit or guarantee its outcome.

Sample · NIS2 readiness report

Internal

Illustrative values. Each report has your own domains and scores.

- Readiness score for each NIS2 domain
- Gaps against requirements, with missing evidence
- Remediation plan prioritised by risk and effort
- Time and effort estimate for each measure
- One-page summary for leadership

Governance and accountability

72
Risk management

48
Incident handling

35
Continuity and backup

60
Supply chain

28
Access control and MFA

81

## We close the gaps with your team, not instead of it.

page

Step 03 · Remediation and readiness

Verifiable measures, on your infrastructure or on Aity Cloud. Audit conclusions remain the auditor’s responsibility.

rule

240

list

01

**Agreed plan**

We start from the report and agree the order, owners and deadlines together. You approve it before we start.
wrench

02

**Implementation**

Policies, technical controls, logging, backup, multi-factor authentication.
folderCheck

03

**Evidence file**

Available documents, configurations and records, organised by requirement, with gaps identified.
user

04

**Audit support**

We stand by your team during the official audit, done by an authorised auditor of your choice.

## Essential and important entities, across 18 sectors.

ink

Who is in scope

Classification depends on activities, size, financial data and relationships with other enterprises. Certain entities are in scope regardless of size. This sector list is indicative; we assess the specific situation under GEO 155/2024.

- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water
- Waste water
- Digital infrastructure
- ICT service management (B2B)
- Public administration
- Space
- Postal and courier services
- Waste management
- Chemicals
- Food
- Manufacturing
- Digital providers
- Research

## Frequently asked questions

page

FAQ

**Is the NIS2 readiness report sent to DNSC?**

It is intended for internal use, not submission as an official audit report. The service does not replace legal duties to report or respond to requests from the authority.
**Who does the official audit?**

An authorised cybersecurity auditor of your choice. We prepare you and support you, but we do not audit.
**How long does preparation take?**

It depends on the gaps. The report includes a time and effort estimate per measure, so you can plan budget and deadlines.
**Do we have to move to Aity Cloud?**

No. We work on your infrastructure. Aity Cloud is an option if you also want Romanian hosting in the same project.

## 30 minutes with a security engineer, not a sales rep.

apel

ink

Book a call

We discuss possible classification, what you already have and where to start. The initial call does not create a contractual commitment.

**Aity Security call**

name

50

Name
email

50

Work e-mail

name@company.com
topic

Nu știu încă

Not sure yet
Evaluare într-o zi

One-day assessment
Raport NIS2 readiness

NIS2 readiness report
Remediere completă

Full remediation

What do you need?

Nu știu încă
consent

I agree to the processing of my data under the [Privacy Policy](/documents/privacy/).

Book the call

message

We have received your request. A security engineer will contact you to agree a time for the call.

audit

2026-09-27T19:34:43.656Z

2026-09-24T07:53:12.997Z
