Self-check · 2 minutes 6 exposures found

Free · 2 minutes

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 has been in force since 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.

Cybersecurity and compliance consulting.

Penetration testing, an external CISO function and readiness for ISO 27001, SOC 2, NIS2 and GDPR.

Skip to the check

Free · 2 minutes

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 has been in force since 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.

Cybersecurity consulting

Cybersecurityandcomplianceconsulting.

Penetration testing, an external CISO function and readiness for ISO 27001, SOC 2, NIS2 and GDPR.

recon://target 6 exposures found

  • Login without MFA
  • Exposed remote access (RDP/SSH)
  • Weak & reused credentials
  • Exposed data & shadow IT
  • Outdated OS & TLS
  • Camera & mic exposure
Self-check ~2 minutes · no email

Free · 2 minutes

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 has been in force since 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.

ISO 27001SOC 2GDPRNIS2PCI DSSNIST CSFISO 27001SOC 2GDPRNIS2PCI DSSNIST CSF

Regulatory coverage

Regulations and standards we cover.

GDPR and NIS2 across the EU, ISO 27001 and SOC 2 for the customers who ask for them, and Moldova's Law 195/2024 and Law 48/2023 for companies operating there. We start from the obligations that apply to you and build one evidence file that serves all of them.

GDPR
Regulation (EU) 2016/679

General Data Protection Regulation (EU)

Applies to any organisation processing personal data of people in the EU: lawful basis, records of processing, data-subject rights, breach notification within 72 hours.

NIS2
Directive (EU) 2022/2555

Network and Information Security Directive (EU)

Essential and important entities in critical sectors: risk-management measures, incident reporting within 24 hours, management accountability, supply-chain security.

ASC
Law 48/2023HG 562/2025

Agency for Cybersecurity (Moldova)

Supervises Law 48/2023: minimum security measures (the HG 562/2025 annex), incident reporting, an external audit every three years.

CNPDCP
Law 195/2024

National Center for Personal Data Protection (Moldova)

Supervises Law 195/2024, in force since 23 August 2026: lawful basis, records of processing, people's rights, breach notification within 72 hours.

  1. 23 Aug 2026 Moldova: Law 195/2024 is in force. Breaches are notified within 72 hours; people's requests are answered within a month.
  2. 5 Apr 2027 Moldova: essential entities file their first compliance-assessment report (HG 562/2025, 18 months after entry into force).
  3. 5 Oct 2027 Moldova: the same report for important entities, at 24 months. A valid ISO 27001 certificate stands in for the technical annex.

General information, not legal advice. References to regulators and named frameworks are for identification only. Check your obligations against the official texts.

What we do

Five services, one person accountable.

vCISO

We take over your security function.

ISO 27001, SOC 2, NIS2 and GDPR all expect someone accountable for security, and often a data-protection officer. That function does not require a department. As your external CISO, we keep the policies, the risk register, the vendors, the audits and the relationship with auditors and regulators.

PenTest

Offensive Security

Penetration tests on applications, networks and cloud, plus phishing simulations. Every finding comes with steps to reproduce it and the order in which it is worth fixing.

Governance

Compliance & Audit

Readiness for ISO 27001, SOC 2, NIS2 and GDPR - and for Moldova's Law 195/2024 and HG 562/2025 where they apply: policies, risk register, controls and the evidence file your auditor will ask for.

Infra

Infrastructure Review

Network, cloud, identity, backups. We look at how it is actually configured, not at the diagram, and give you the hardening list in order of impact.

Agentic AI

AI-Agent Governance & Security

Copilots and AI agents reach real data. We define what they may touch, test what happens when someone tries to trick them, and write a policy you can actually enforce.

Salient.sec

A compliance platform for ISO 27001, SOC 2, NIS2 and GDPR.

Salient.sec takes ISO 27001, SOC 2, NIS2 and GDPR - and local regimes such as Moldova's Law 195/2024 and Law 48/2023 - and turns them into concrete controls with owners, deadlines and evidence. Records of processing, data-subject requests, breach notifications, vendors and policies live in one place, in English, Romanian and Russian.

Frameworks mapped to each other

Enable a framework and you get its requirements as a working list. What ISO 27001 already covers is ticked for SOC 2, NIS2 or a local regime too, so the same work is never done twice.

The data-protection module

Records of processing, DPIAs, data-subject requests with their statutory clocks, breach notification to the regulator within 72 hours, a consent register. Everything GDPR asks for, as a workflow with deadlines.

Evidence from the systems you already run

Connects to Microsoft 365, Google Workspace, Azure, AWS and GitHub and reads the real state of your controls: MFA, devices, access. Your auditor gets a read-only audit room.

The Salient.sec overview screen: compliance score and attention queue

Built on ISO 27001, SOC 2, GDPR, NIS2, NIST CSF and CIS. Local regimes mapped on top: Moldova's Law 195/2024, Law 48/2023 with HG 562/2025, NBM Regulation 29/2025.

Salient.sec is in open beta: we already run it with our first clients and build it at their pace.

Contact us.

Describe your situation briefly. As a rule we reply within one business day; where useful, we begin with a 30-minute call.

Your details are used solely to reply to you.