Noi obligații pentru companiile din grupuri de întreprinderi: cine răspunde pentru securitatea cibernetică la nivel local
Essential entities in Romania must demonstrate effective implementation of cybersecurity measures established at the group level. The National Cyber Security Directorate (DNSC) has outlined evaluation criteria through Decision No. 3, published on September 21, 2026. The regulations categorize cybersecurity controls into three types: adopted, implemented, and shared. Each entity remains responsible for proving the effectiveness of these controls in their operations. The norms cover governance, identification, protection, detection, response, and recovery. Companies can achieve high maturity levels even with group policies, provided they have formal documentation and measurable indicators. The regulations emphasize that lacking a local policy does not equate to low maturity if the group policy is effectively applied locally.