IT infrastructure and NIS2/DORA compliance
We design and build IT infrastructure from the ground up for companies needing secure, documented systems aligned with European legal requirements: the NIS2 directive on network and information security and the DORA regulation on digital operational resilience in the financial sector.
Building IT infrastructure
Sound infrastructure is the foundation of a digital business. We design it with you, implement it and document it so it supports operations and provides evidence for audit:
- IT architecture design — networks, servers, workstations and services sized for actual needs, without hidden costs;
- Linux & Windows servers and systems — installation, configuration and security hardening following good practice;
- Networks and perimeter security — firewalls, segmentation, secure remote access and monitoring;
- Storage, backup and disaster recovery — regularly tested backup and recovery strategies for business continuity;
- Virtualization and consolidation — efficient use of hardware resources and straightforward scaling;
- Complete documentation — diagrams, administration procedures and compliance records.
NIS2 compliance
NIS2 establishes cybersecurity measures and incident reporting obligations for entities in essential and important sectors. We help you address the applicable requirements step by step:
- Gap analysis — assessing existing infrastructure and processes against NIS2 requirements;
- Risk management measures — implementing the required technical and organizational controls;
- Supply chain security — assessing and documenting risks introduced by external providers;
- Incident reporting procedures — preparing detection, notification and response workflows within applicable deadlines;
- Audit and inspection preparation — documentation, records and incident exercises.
DORA compliance
DORA establishes digital operational resilience requirements for financial entities and oversight arrangements for relevant ICT providers. We cover the technical aspects applicable to your organization:
- ICT risk management — a risk management framework and an inventory of assets and dependencies;
- Major incident reporting — classification, procedures and timelines aligned with DORA;
- Resilience testing — regular system testing and disruption scenarios;
- Third-party ICT risk — contracts, monitoring and exit strategies;
- Operational continuity — backup, redundancy and recovery plans tested in practice.
How we work
- Audit and assessment — understanding existing infrastructure and applicable legal obligations;
- Design — defining the target architecture, security measures and compliance plan;
- Implementation — building and configuring infrastructure, with documentation throughout;
- Validation — testing, checking compliance and preparing audit documentation;
- Ongoing maintenance — administration, monitoring and maintaining compliance over time.
Does NIS2 apply to your organization?
NIS2 applicability depends on sector, entity size, specific exceptions and national implementing legislation. Some entities are covered regardless of size. We assess the applicable rules and registration obligations for your organization; in Romania, the relevant authority is the National Cyber Security Directorate (DNSC).
Sectors of high criticality
- Energy (electricity, gas, oil and hydrogen)
- Transport (air, rail, water and road)
- Banking and financial market infrastructure
- Health
- Drinking water and wastewater
- Digital infrastructure and managed ICT services
- Public administration and space
Other critical sectors
- Postal and courier services
- Waste management
- Manufacture and distribution of chemicals
- Food production and distribution
- Manufacturing, including medical devices, electronics and vehicles
- Digital service providers and online platforms
- Research
Not sure whether your organization is in scope? We can carry out a preliminary assessment of your activities and infrastructure. Request an assessment.
How we work: stages of a compliance project
- Scope and inventory — determining whether and how NIS2 or DORA applies and inventorying systems, data and dependencies.
- Gap analysis — comparing the current situation with applicable requirements to produce a prioritized action list.
- Remediation plan — technical and organizational measures, effort and budget estimates, and an implementation schedule.
- Implementation — configuring infrastructure, security controls and operational procedures.
- Documentation and audit preparation — policies, procedures, records and incident exercises.
- Continuous monitoring — maintenance, regular reviews and documentation updates.
Frequently asked questions about NIS2 and DORA
What is the NIS2 directive?
NIS2 is the EU directive on measures for a high common level of cybersecurity across the Union. It establishes cybersecurity risk management, incident reporting and management accountability requirements for entities in the sectors it covers.
What is DORA and who does it cover?
DORA is the EU regulation on digital operational resilience for the financial sector. It covers financial entities such as banks, insurers, investment firms and payment service providers, and establishes requirements relating to their third-party ICT services.
How long does a NIS2 compliance project take?
The duration depends on organization size, infrastructure complexity and existing maturity. Gap analysis generally takes several weeks. Implementation is planned in stages according to the priority of the identified risks. We provide a concrete estimate after the initial assessment.
Do we need to register with DNSC?
For organizations operating in Romania, we assess whether national NIS2 registration obligations apply and help prepare the required information. Requirements in other countries depend on the relevant national authority and legislation.
Can you work alongside our internal IT department?
Yes. We can manage the entire project or work alongside your team as an independent consultant and auditor. We deliver documentation and procedures that your team can maintain.
Have another question? Write to us or call +40 744 222 112.
