Menu ☰
lexnomia · · 3 min read

DNSC Publishes EVAL_MMS: NIS2 Self-Assessment Becomes Operational

On 27 August 2026, Official Gazette no. 712/712bis enacted DNSC Director Order no. 1/2026, launching three self-assessment instruments for cybersecurity risk management maturity: EVAL_MMS_B, EVAL_MMS_I, and EVAL_MMS_E.

CAI Technology · Last reviewed: 9/5/2026
Clean editorial photo of a professional working on a laptop in a bright modern office; no visible text, no third-party logos, anatomy looks natural. Fits a cybersecurity/NIS2

DNSC Publishes EVAL_MMS: NIS2 Self-Assessment Becomes Operational

On 27 August 2026, Official Gazette no. 712/712bis enacted DNSC Director Order no. 1/2026, launching three self-assessment instruments for cybersecurity risk management maturity: EVAL_MMS_B, EVAL_MMS_I, and EVAL_MMS_E. They are mandatory for all essential and important entities notified under GEO no. 155/2024.

This is not an optional exercise. The deadline runs from the date of publication, and the primary reporting channel is the NIS2@RO Platform. Entities that cannot access the platform in time use the downloadable files from the DNSC website and upload results later — but accountability remains with the entity’s management.

What Each Instrument Requires

The three files cover different levels of operational complexity:

Each file reflects the ten minimum measures from Art. 21 of Directive (EU) 2022/2555 — from risk management to supply chain security. The difference is not cosmetic: the E level requires documented evidence, not just compliance declarations.

The Actual Flow You See in an Audit

flowchart TD A[Essential/important entity notification] --> B{RVN Classification} B -->|Baseline| C[EVAL_MMS_B] B -->|Intermediate| D[EVAL_MMS_I] B -->|Extended| E[EVAL_MMS_E] C --> F[Submission via NIS2@RO] D --> F E --> F F --> G{DNSC validates evidence} G -->|Complete| H[Compliance confirmation] G -->|Gaps| I[Remediation plan] classDef ok fill:#dcfce7,stroke:#10b981 classDef risk fill:#fee2e2,stroke:#ef4444 class H ok class I risk

In practice, most entities get stuck on the supplier management section and on log evidence. These are the areas where declarations sound convincing, but proof — signed policies, contractual security clauses, technically demonstrated log retention — is missing.

For those already working on NIS2 compliance under Law 244/2024, EVAL_MMS turns a theoretical checklist into an officially filed document with direct management liability. For those just starting, the healthy order is the reverse of the intuitive one: first the asset and data-flow inventory, then the self-assessment — not the other way around.

What We Do Differently

On real engagements we have seen that companies filling out EVAL_MMS without a functional SOC toolset produce optimistic answers that do not survive the first round of evidence review. That is why at CAI Technology we couple the self-assessment with live telemetry from the AEGIS detection and response platform — answers become verifiable while you are filling them in, not after an inspection.

The methodological benchmark we follow is the ENISA implementation guidance for NIS2, because it maps every requirement to concrete controls, not intentions. If you want to see what a complete EVAL_MMS_I dossier looks like, with evidence linked to each requirement, head over to the Lexnomia page.

Further Reading

We start with a 30-minute conversation.

Free AI-readiness audit for companies with 50+ employees. We reply within 24 hours.