For electricity, gas, district heating, drinking water and wastewater operators in Romania, NIS 2 is no longer next year's project. Directive (EU) 2022/2555 was transposed through Emergency Ordinance 155/2024, in force since 30 December 2024 and amended by Law 124/2025. Essential and important entities registered with DNSC in September 2025 through the NIS2@RO platform, and DNSC Orders 1/2025 and 2/2025 (Official Gazette no. 776 of 20 August 2025) set the notification rules and the risk assessment methodology, with three tiers of security measures: basic, important and essential.
In short, the enrolment phase is over. What follows is the phase where you are asked to prove the measures work — and for essential entities, penalties reach EUR 10 million or 2% of global turnover, whichever is higher, with direct management accountability.
Why energy and utilities are a special case
In most sectors, a penetration test means web applications, Active Directory and the perimeter. In energy and utilities there is a second universe: operational technology (OT) — SCADA, RTUs, PLCs, telecontrol systems, historians, engineering workstations. Here, unavailability is not an IT incident; it is an interrupted essential service.
The practical consequence is that you cannot test OT the way you test IT. An aggressive port scan against an ageing PLC can take it offline. Fuzzing IEC 60870-5-104 can trip protections. A "standard" methodology copied from the corporate environment is, inside a substation, a genuine operational risk — and a perfect reason for engineering to refuse all future testing.
A serious provider says this up front. If someone offers you the same scope and the same methodology for the office network and the process network, you have already found a problem.
What actually gets tested
1. The IT–OT boundary. This is an attacker's highest-value target and the weakness we find most often. We check whether segmentation genuinely exists or is only drawn on a diagram; what firewall rules sit between zones and why; whether there are bypass paths through management VLANs, backup networks or monitoring systems that can see both sides; and whether a compromised IT account can reach a historian and continue from there.
2. Vendor remote access. Integrators and equipment manufacturers almost always hold maintenance access. We test how it is implemented: dedicated VPN or permanent tunnel, MFA or a shared password, named accounts or a generic one, recorded sessions or none, just-in-time access or standing access. NIS 2 Article 21(2)(d) explicitly requires supply chain security, and vendor access is the most concrete form of that risk.
3. Engineering workstations and jump hosts. These are the machines allowed to write configuration into process equipment. If one sits on the same domain as office laptops, there is a single step between phishing and the process.
4. Infrastructure management interfaces. Out-of-band consoles — IPMI, iDRAC, iLO — are exactly the layer nobody puts in the asset inventory. Research published on 28 July 2026 found more than 36,000 BMC interfaces exposed directly to the internet, of which nearly 25,000 disclose password-derived hashes before authentication, through a flaw in the IPMI v2.0 specification that is over a decade old. In a utility, an exposed management console means hardware-level access regardless of what operating system runs above it.
5. The IT that supports the service. Customer portals, billing systems, smart metering platforms, energy market integrations. Classic testing applies here — web security assessment and infrastructure penetration testing — plus scrutiny of consumer personal data.
6. The human factor. Dispatchers and field staff are social engineering targets with a specific context: calls "from the equipment vendor", urgent out-of-hours requests, USB drives delivered on site. A phishing simulation calibrated to field reality says more than generic training.
How to test OT without stopping anything
The base rule: production is not actively touched except with explicit approval from operations and inside an agreed window. In practice, a healthy OT and ICS penetration testing programme combines:
- Passive traffic analysis on the process network — it reveals protocols, devices and unexpected communications without sending a single packet.
- Architecture and configuration review — firewall rules, ACLs, accounts, firmware versions, matched against the real topology rather than the documented one.
- Active testing on a test rig or standby environment, where identical equipment exists, for anything carrying risk.
- Full active testing on IT and on the boundary, where risk is manageable.
- Maintenance windows for anything invasive, with a stop plan, a named operations contact and clear abort criteria.
What the report must contain to be useful at audit
DNSC does not assess how attractive the report is; it assesses whether you can demonstrate that your measures are effective. A useful report contains:
- Findings mapped to the Article 21 measures they prove or disprove — not just a list of CVEs.
- An explicitly stated scope, including what was excluded and why. A scope that quietly avoids all OT is an audit problem, not a saving.
- CVSS scoring plus operational context — the real impact on the essential service, not only the number.
- A prioritised remediation roadmap with estimated effort.
- A documented retest confirming the fixes worked.
- An executive summary management can read and approve, because Article 20 makes them personally accountable.
Add the link to Article 23: early warning within 24 hours, notification within 72 hours, final report within one month. You cannot report within 24 hours on systems you have never mapped. Testing feeds reporting capability directly.
How often
The directive gives no number. The defensible baseline for an essential entity in energy or utilities is: at least annually for the systems supporting the essential service, after any major change — a new SCADA, a migration, a new integrator, an acquisition — and more frequently for anything internet-facing. If additional sector requirements also apply to you, run a single testing programme that produces evidence for all of them rather than duplicating effort.
Where to start
If you have never tested anything on the OT side, the first step is not a penetration test — it is an inventory and a scoping conversation between security, IT and operations. Without buy-in from the people accountable for the process, any testing programme stalls at the first objection.
Our NIS 2 and DORA checklist covers all ten Article 21 measures and shows where testing fits. When you are ready to produce evidence, penetration testing and security audit and compliance map every finding back to your obligations. If you would like to discuss how to do this without putting production at risk, get in touch.
This article is general information, not legal advice. Your specific obligations depend on your sector, size and classification as an essential or important entity. Sources: Directive (EU) 2022/2555 (NIS 2), Articles 20, 21 and 23; Emergency Ordinance 155/2024; Law 124/2025; DNSC Orders 1/2025 and 2/2025 (Official Gazette no. 776 of 20 August 2025); public reporting by The Hacker News on exposed IPMI interfaces (28 July 2026).

