Skip to main content
Back to blog
ComplianceFeatured

What is CyFunRO and how to calculate ENIRE@RO risk level

Complete guide to the official DNSC risk evaluation methodology. Learn how to calculate your CyFunRO score and how many controls you need to implement (38, 90, or 140).

Stefan Balan
Security Practice Lead at BetterQA
10 min read

Introduction

If you've checked your organization's NIS2 eligibility, you've probably heard about CyFunRO and ENIRE@RO. But what do these terms actually mean and why do they matter for your compliance?

In this guide, we explain the official DNSC methodology for calculating risk levels and why not all NIS2 organizations need to implement all 140 controls.

What is CyFunRO?

CyFunRO (Cybersecurity Function Romania) is the official cybersecurity level established by DNSC for each organization in the NIS2 scope. There are three levels:

LevelENIRE@RO ScoreRequired Controls
BASIC0-99 points~38 controls
IMPORTANT100-199 points~90 controls
ESSENTIAL200+ points~140 controls

Why does this matter? The CyFunRO level determines exactly which security controls you must implement. A Basic level organization doesn't need to implement all 140 controls -only the ~38 fundamental ones.

What is ENIRE@RO?

ENIRE@RO (Risk Level Evaluation for Romanian Entities) is the official DNSC tool for calculating risk scores. The current version is v1.2.

The methodology evaluates 4 main criteria:

1. Entity Size (10-100 points)

CategoryEmployeesScore
Micro/Small< 5010 points
Medium50-24950 points
Large>= 250100 points

2. Attack Nature (25-75 points)

Attack TypeDescriptionScore
Global/UntargetedMass malware, generic phishing25 points
Targeted/APTTargeted attacks, nation-state75 points

Attack nature depends on sector and organization profile. Critical infrastructure entities (energy, transport, healthcare) are more susceptible to targeted attacks.

3. Impact Level (25-150 points)

ImpactDescriptionScore
LowAffects < 10,000 people, losses < €1M25 points
MediumAffects 10,000-100,000 people, losses €1-10M75 points
HighAffects > 100,000 people, losses > €10M150 points

4. Incident Probability (25-150 points)

ProbabilityDescriptionScore
LowIncident unlikely in next 3 years25 points
MediumIncident possible in next 1-3 years75 points
HighIncident likely in next year150 points

CyFunRO Calculation Formula

The final score is calculated with the formula:

CyFunRO Score = (Size × Attacks × Impact × Probability) / 1000

Calculation Examples

Example 1: Medium IT Company

  • Size: 50 points (medium)
  • Attacks: 25 points (global)
  • Impact: 25 points (low)
  • Probability: 75 points (medium)

Score = (50 × 25 × 25 × 75) / 1000 = 2.34 points → BASIC

Example 2: Regional Hospital

  • Size: 100 points (large)
  • Attacks: 75 points (targeted - healthcare)
  • Impact: 150 points (high - human lives)
  • Probability: 75 points (medium)

Score = (100 × 75 × 150 × 75) / 1000 = 843 points → ESSENTIAL

Which Controls Apply at Each Level?

BASIC Level (~38 controls)

Fundamental security controls:

  • Basic security policies
  • IT asset inventory
  • Backup and data recovery
  • Antivirus and firewall
  • Incident response plan
  • Account security (passwords, access)
  • Updates and patches

IMPORTANT Level (~90 controls)

All BASIC controls plus:

  • Multi-factor authentication (MFA)
  • Network monitoring
  • Vulnerability scanning
  • Business continuity plan (BCP)
  • Internal security audits
  • Email security
  • Network segmentation

ESSENTIAL Level (~140 controls)

All IMPORTANT controls plus:

  • SIEM (Security Information and Event Management)
  • Threat intelligence
  • Periodic penetration testing
  • Digital forensics
  • Supply chain security
  • Red team / Blue team exercises
  • Zero trust architecture

Multi-Sector Organizations

If your organization operates in multiple NIS2 sectors (maximum 6), the situation is more complex:

  1. Separate evaluation for each sector
  2. Overall CyFunRO level = highest level across all sectors
  3. Applicable controls = union of controls for all levels

Example: A company operates in Transport (Basic level) and Energy (Important level). The overall level is Important, so they must implement ~90 controls.

The ENIRE@RO Document (Annex 2)

When registering with DNSC, you must submit Annex 2 containing:

  1. Organization data
  2. Sector(s) of activity
  3. Justification for each criterion (size, attacks, impact, probability)
  4. CyFunRO score calculation
  5. Resulting level

NIS2 Manager automatically generates this document in PDF format according to official DNSC requirements.

Why the ENIRE@RO Methodology Matters

1. Proportionality

Not all organizations present the same risk. A small courier company has a different risk profile than an electric grid operator.

2. Efficiency

Implementing 38 controls vs 140 means a major difference in effort and resources. Focus on what matters for your level.

3. Demonstrable Compliance

DNSC will verify if implemented controls correspond to your CyFunRO level. Implementing the wrong controls = non-compliance.

How NIS2 Manager Helps

Our platform:

  1. Automatically calculates CyFunRO score based on organization data
  2. Guides evaluation with specific questions for each criterion
  3. Filters controls so you only see those applicable to your level
  4. Generates Annex 2 in PDF format per DNSC requirements
  5. Supports multi-sector for complex organizations

Next Steps

  1. Check eligibility with our free calculator
  2. Perform ENIRE@RO evaluation to find your CyFunRO level
  3. Focus on relevant controls for your level
  4. Generate documentation for DNSC registration

Conclusion

Understanding the ENIRE@RO methodology and CyFunRO levels is essential for efficient NIS2 compliance. Don't overcomplicate with all 140 controls if your level is Basic -focus on what matters.


NIS2 Manager is a product by BetterQA, one of Europe's top software testing companies. The platform automatically calculates CyFunRO level and generates documentation required for DNSC.

Tags:
CyFunROENIRE@ROrisk levelcontrolsDNSCevaluation
Share this article:
Stefan Balan
Security Practice Lead at BetterQA

Security consultant specializing in NIS2 compliance and cybersecurity frameworks. Helps organizations navigate complex regulatory requirements.

Want to know if your company falls under NIS2?

Use our free calculator to check eligibility in just 3 minutes.

Check eligibility for free

Related Articles

160K+
organizations affected by NIS2 across the EU (ENISA, 2024)
EUR 10M
maximum penalty for NIS2 non-compliance or 2% of global turnover
24h
incident reporting deadline under NIS2 directive
18
critical sectors covered by NIS2 compliance requirements

The NIS2 Directive (EU 2022/2555) entered into force on January 16, 2023, with member states required to transpose it by October 17, 2024. According to ENISA's 2024 Threat Landscape report, ransomware attacks increased 73% year-over-year, while supply chain attacks grew by 85%. The European Commission estimates NIS2 compliance costs average EUR 120,000 per organization, but non-compliance penalties can reach EUR 10 million or 2% of global annual turnover. Only 34% of affected organizations reported full NIS2 readiness by the October 2024 deadline (EY Global Cybersecurity Survey, 2024). Romania's DNSC reported a 156% increase in cybersecurity incidents in 2024, making compliance tools essential for the 8,000+ Romanian organizations affected by the directive.

BetterQA
ISO 27001 & NATO certified security company
50+ Engineers
Cybersecurity & compliance specialists across 24 countries
Since 2018
Independent security testing & compliance expertise
NIS2 Ready
Full compliance lifecycle from assessment to certification