Self-check · 2 minutes 6 exposures found

Free · 2-minute self-check

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 becomes binding on 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.

We test, fix, and prove your security.

From a pentest to Moldova's new laws - we can help in more ways than one. Reach out, even just for advice.

Skip to the assessment

Free · 2-minute self-check

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 becomes binding on 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.

ISO 27001SOC 2GDPRNIS2PCI DSSNIST CSFISO 27001SOC 2GDPRNIS2PCI DSSNIST CSF

Not sure which of Moldova's new laws apply to you?

Compliance, built in

Built in Moldova. Built for Moldova's new rules.

We map your security program to the laws that now bind you here - and to the international frameworks your partners and auditors already expect.

ASC
Law 48/2023HG 562/2025

Agency for Cybersecurity (Moldova)

Cybersecurity and NIS2-style minimum measures, incident reporting.

CNPDCP
Law 195/2024

National Center for Personal Data Protection

GDPR-aligned data protection - breach notice and data-subject rights.

  1. 23 Aug 2026 Data-protection law (195/2024) applies - 72h breach notice, 1-month data-subject requests.
  2. 2026–2027 HG 562/2025 windows close - essential entities 12 months, important 18 months.
  3. ~Apr 2027 First cybersecurity compliance-assessment report due.

General information, not legal advice. References to the ASC, CNPDCP and named frameworks are for identification only. Confirm obligations against the official texts.

What we do

Security across the whole lifecycle.

vCISO

We take over your security function.

The new rules expect someone to own information security. As your external CISO, that someone is us: policies, risk, vendors, audits, and the regulator - run by senior practitioners while your team gets on with its work.

PenTest

Offensive Security

Penetration testing and red-team engagements that surface the gaps before an attacker does - not a checklist, a real adversary.

Governance

Compliance & Audit

ISO 27001, SOC 2, and GDPR readiness mapped to controls you can actually operate and maintain after we leave.

Infra

Infrastructure Review

We review your network architecture, cloud, identity, and backups - and give you the hardening priorities that matter, not a generic list.

Agentic AI

Agentic Governance & Security

Policy, access boundaries, and testing for AI copilots and agents - so you can adopt AI without leaking data or breaking the rules that bind you.

How we work

We test. We fix. We prove it.

Every engagement ends with proof - evidence you can hand to a board, an auditor, or a regulator.

200+ assessments delivered
1 senior practitioner, end to end
100% findings reproducible

From the Salient team · sister product

Salient.sec Beta

In development · Beta open

Training that survives the audit.

Salient.sec turns security-awareness training and phishing simulation into one thing your auditor actually asks for: a clean, RO-first evidence pack mapped to Moldova's rules.

Evidence, not just an LMS

Who was trained, when, their score, their phishing result - exported as an RO/EN PDF + CSV your auditor accepts as-is.

Mapped to the rules that bind you

Every record lines up with HG 562/2025 Ch. VIII, ISO 27001 A.6.3, and NIS2 Art. 20/21 - including the management body and key suppliers the law says you must train.

Works with the content you have

Assign your own decks, SCORM, links, or external "mark trained" - completions are recorded immutably, reminders go out on their own, and overdue people get chased for you.

HG 562/2025 Ch. VIII makes awareness training a minimum measure - covering your management body and key suppliers, with essential entities due around October 2026.

Salient.sec is in active development. Beta customers get it early and help shape what ships.

Ready to find out where you stand?

A scoped assessment takes two weeks. The clarity lasts much longer.

No spam. We use your details only to reply - usually within one business day.