Cybersecurity
Moldova's NIS2-style regime: minimum security measures and incident reporting, supervised by the Agency for Cybersecurity.
Who it covers
- Essential and important entities in critical sectors - energy, transport, health, finance, digital
- ICT and digital-infrastructure service providers
What it asks, in short
- Minimum technical and organisational measures (the HG 562/2025 annex)
- Incident reporting to the ASC: initial notice within 24 hours
- An external security audit at least every three years
First compliance-assessment report: 5 April 2027 (essential), 5 October 2027 (important)