Skip to main content
Back to blog
ComplianceFeatured

What is CyFunRO and how to calculate ENIRE@RO risk level

Complete guide to the official DNSC risk evaluation methodology. Learn how to calculate your CyFunRO score and how many controls you need to implement (38, 90, or 140).

Stefan Balan
Security Practice Lead at BetterQA
March 10, 202610 min read

Introduction

If you've checked your organization's NIS2 eligibility, you've probably heard about CyFunRO and ENIRE@RO. But what do these terms actually mean and why do they matter for your compliance?

In this guide, we explain the official DNSC methodology for calculating risk levels and why not all NIS2 organizations need to implement all 140 controls.

What is CyFunRO?

CyFunRO (Cybersecurity Function Romania) is the official cybersecurity level established by DNSC for each organization in the NIS2 scope. There are three levels:

LevelENIRE@RO ScoreRequired Controls
BASIC0-99 points~38 controls
IMPORTANT100-199 points~90 controls
ESSENTIAL200+ points~140 controls

Why does this matter? The CyFunRO level determines exactly which security controls you must implement. A Basic level organization doesn't need to implement all 140 controls—only the ~38 fundamental ones.

What is ENIRE@RO?

ENIRE@RO (Risk Level Evaluation for Romanian Entities) is the official DNSC tool for calculating risk scores. The current version is v1.2.

The methodology evaluates 4 main criteria:

1. Entity Size (10-100 points)

CategoryEmployeesScore
Micro/Small< 5010 points
Medium50-24950 points
Large>= 250100 points

2. Attack Nature (25-75 points)

Attack TypeDescriptionScore
Global/UntargetedMass malware, generic phishing25 points
Targeted/APTTargeted attacks, nation-state75 points

Attack nature depends on sector and organization profile. Critical infrastructure entities (energy, transport, healthcare) are more susceptible to targeted attacks.

3. Impact Level (25-150 points)

ImpactDescriptionScore
LowAffects < 10,000 people, losses < €1M25 points
MediumAffects 10,000-100,000 people, losses €1-10M75 points
HighAffects > 100,000 people, losses > €10M150 points

4. Incident Probability (25-150 points)

ProbabilityDescriptionScore
LowIncident unlikely in next 3 years25 points
MediumIncident possible in next 1-3 years75 points
HighIncident likely in next year150 points

CyFunRO Calculation Formula

The final score is calculated with the formula:

CyFunRO Score = (Size × Attacks × Impact × Probability) / 1000

Calculation Examples

Example 1: Medium IT Company

  • Size: 50 points (medium)
  • Attacks: 25 points (global)
  • Impact: 25 points (low)
  • Probability: 75 points (medium)

Score = (50 × 25 × 25 × 75) / 1000 = 2.34 points → BASIC

Example 2: Regional Hospital

  • Size: 100 points (large)
  • Attacks: 75 points (targeted - healthcare)
  • Impact: 150 points (high - human lives)
  • Probability: 75 points (medium)

Score = (100 × 75 × 150 × 75) / 1000 = 843 points → ESSENTIAL

Which Controls Apply at Each Level?

BASIC Level (~38 controls)

Fundamental security controls:

  • Basic security policies
  • IT asset inventory
  • Backup and data recovery
  • Antivirus and firewall
  • Incident response plan
  • Account security (passwords, access)
  • Updates and patches

IMPORTANT Level (~90 controls)

All BASIC controls plus:

  • Multi-factor authentication (MFA)
  • Network monitoring
  • Vulnerability scanning
  • Business continuity plan (BCP)
  • Internal security audits
  • Email security
  • Network segmentation

ESSENTIAL Level (~140 controls)

All IMPORTANT controls plus:

  • SIEM (Security Information and Event Management)
  • Threat intelligence
  • Periodic penetration testing
  • Digital forensics
  • Supply chain security
  • Red team / Blue team exercises
  • Zero trust architecture

Multi-Sector Organizations

If your organization operates in multiple NIS2 sectors (maximum 6), the situation is more complex:

  1. Separate evaluation for each sector
  2. Overall CyFunRO level = highest level across all sectors
  3. Applicable controls = union of controls for all levels

Example: A company operates in Transport (Basic level) and Energy (Important level). The overall level is Important, so they must implement ~90 controls.

The ENIRE@RO Document (Annex 2)

When registering with DNSC, you must submit Annex 2 containing:

  1. Organization data
  2. Sector(s) of activity
  3. Justification for each criterion (size, attacks, impact, probability)
  4. CyFunRO score calculation
  5. Resulting level

NIS2 Manager automatically generates this document in PDF format according to official DNSC requirements.

Why the ENIRE@RO Methodology Matters

1. Proportionality

Not all organizations present the same risk. A small courier company has a different risk profile than an electric grid operator.

2. Efficiency

Implementing 38 controls vs 140 means a major difference in effort and resources. Focus on what matters for your level.

3. Demonstrable Compliance

DNSC will verify if implemented controls correspond to your CyFunRO level. Implementing the wrong controls = non-compliance.

How NIS2 Manager Helps

Our platform:

  1. Automatically calculates CyFunRO score based on organization data
  2. Guides evaluation with specific questions for each criterion
  3. Filters controls so you only see those applicable to your level
  4. Generates Annex 2 in PDF format per DNSC requirements
  5. Supports multi-sector for complex organizations

Next Steps

  1. Check eligibility with our free calculator
  2. Perform ENIRE@RO evaluation to find your CyFunRO level
  3. Focus on relevant controls for your level
  4. Generate documentation for DNSC registration

Conclusion

Understanding the ENIRE@RO methodology and CyFunRO levels is essential for efficient NIS2 compliance. Don't overcomplicate with all 140 controls if your level is Basic—focus on what matters.


NIS2 Manager is a product by BetterQA, one of Europe's top software testing companies. The platform automatically calculates CyFunRO level and generates documentation required for DNSC.

Tags:
CyFunROENIRE@ROrisk levelcontrolsDNSCevaluation
Share this article:
Stefan Balan
Security Practice Lead at BetterQA

Security consultant specializing in NIS2 compliance and cybersecurity frameworks. Helps organizations navigate complex regulatory requirements.

Want to know if your company falls under NIS2?

Use our free calculator to check eligibility in just 3 minutes.

Check eligibility for free

Related Articles