Skip to content
Acasă » General Interest » Digitalization » Challenges in implementing the NIS 2 directive in the energy sector

Challenges in implementing the NIS 2 directive in the energy sector

    12 December 2025
    Analyses
    energynomics

    Amid the accelerated development of digital technologies and global socio-economic interconnection, cybersecurity has become essential, especially in critical sectors such as energy. This transformation is illustrated by a series of initiatives and legislation issued at the European Union (EU) level, aimed at strengthening cyber protection measures for critical infrastructures, argue Dragoș Ionica, Cyber ​​Attack Senior Manager and Octavian Popa, Cyber ​​Strategy Manager, Deloitte Romania, in a new analysis.

    A relevant example in this regard is the NIS 2 directive (NIS 2), which extends cybersecurity requirements for the energy sector, including electricity, oil and gas networks. This regulation is also a priority for Romania, which transposed NIS 2 into local legislation through Emergency Ordinance (OUG) no. 155, published in the Official Gazette at the end of 2024. On 7 July 2025, Law 124/2025 was published in the Official Gazette, marking the legislative validation of the measures provided for by the Emergency Ordinance and bringing to the fore the intensification of cyber protection obligations for entities managing critical infrastructures.

     

    Which organizations are covered by NIS 2?

    NIS 2 targets a wide range of entities in the energy sector with a crucial role in ensuring the efficient and secure operation of critical infrastructure. A first area of ​​interest falling within the scope of this directive is the electricity subsector, where companies supplying electricity are included according to the definitions stipulated in Law no. 123/2012. Distribution and transmission operators are responsible for the operation, maintenance and development of energy networks, and electricity producers are defined by their specific production activity, including cogeneration. Market participants, including designated electricity market operators and operators of recharging points, such as concessionaires and developers of offshore wind farms, are covered by the directive in view of their essential role in the stability and functioning of the energy market.

    The district heating and cooling sub-sector is another area of ​​interest where heat distribution is a critical component. The directive also covers the oil sub-sector, targeting operators of oil pipelines and central storage entities, as well as operators of oil production, refining and processing facilities. In the gas sector, NIS 2 applies to supply undertakings, distribution and transmission operators, as well as operators of natural gas storage, refining and processing, as well as those involved in the handling of liquefied natural gas (LNG).

    Last but not least, the hydrogen subsector targets production, storage and transport operators, along with beneficiaries of the modernization fund in accordance with national legislation. These sectors and entities are essential for the proper functioning, resilience and sustainability of the national energy system, all of which are covered by the directive to improve cybersecurity and protect critical infrastructures against cyber threats.

     

    Challenges in implementing the directive

    The implementation of the NIS 2 directive in the energy sector highlights the complexity and difficulties that entities must overcome to achieve the level of cybersecurity required by the legislation.

    The energy infrastructure is extremely complex, unique in the diversity of integrated and used equipment, from SCADA (Supervisory Control and Data Acquisition) systems and smart grids, to a mix of old technologies alongside modern solutions, which makes it extremely difficult to secure, a possible breach in these systems being likely to stop energy distribution or affect national stability.

    The transposition of the NIS 2 directive into national legislation imposes strict obligations on energy operators, such as the rapid reporting of incidents to the National Cyber ​​Security Directorate or the alignment with the requirements imposed by the Cyber ​​Fundamentals standard. However, Romania still faces specific challenges, such as the lack of a cybersecurity incident response team (CERT) at sectoral level, essential for a critical field such as energy.

    Also, the country’s ISAC (Information Sharing and Analysis Center), specifically for the energy sector, has not yet reached its expected usefulness due to low interest and the small number of registered entities, while cross-sectoral cooperation, but also within them, remains below the expected level. Limited human resources and cybersecurity skills represent another obstacle, with a clear need for training and designation of cybersecurity managers.

    Financial and logistical challenges put additional pressure on companies, both small and medium-sized, and state-owned, in the current economic climate, which should invest significantly in security and incident response technologies. Coordination between entities and interoperability are essential for the success of the directive, requiring close collaboration between energy operators, regulators and suppliers, in the context in which NIS 2 extends responsibilities to suppliers and subcontractors, increasing the risk that less secure partners become vulnerable to attacks.

    At the same time, the implementation of NIS 2 requires greater attention to the operational technology (OT) area, since in the energy sector SCADA systems and industrial infrastructures represent the core of critical physical processes. Periodic and rigorous testing of these systems, carried out under controlled conditions and using specialized methodologies for industrial environments, becomes essential to identify vulnerabilities that, if exploited, could generate major disruptions in energy production, transport or distribution. In addition, the lack of a strict demarcation between OT and IT infrastructure significantly increases the risk that attacks that compromise the IT area will spread to the operational environment, where the consequences can have physical, economic and even public safety impacts. Thus, the maturation of security mechanisms in the OT area, associated with a robust IT-OT segmentation architecture, becomes a strategic priority for all energy entities targeted by the directive.

     

    Conclusion

    The challenges in implementing the NIS 2 directive in the energy sector highlight the importance of a concerted and long-term strategy to strengthen cybersecurity in the face of increasingly sophisticated threats. Given the importance of interconnected and critical infrastructures for the functioning of modern society, it is essential that the energy sector overcomes technical, financial and organizational obstacles to align with the requirements imposed by European regulations.

    Leave a Reply

    Your email address will not be published. Required fields are marked *