New Energy Law to Include Cybersecurity in Grid Tariffs — NRG-IA

Legislație & Reglementări

Cybersecurity is set to become an explicitly recognized investment category in grid economics, with DNSC validating technical needs and ANRE controlling costs.

New Energy Law to Include Cybersecurity in Grid Tariffs — NRG-IA
Cybersecurity for energy infrastructure may explicitly enter the mechanism used to establish regulated network costs in Romania. The amended draft of the Electricity and Natural Gas Law assigns the National Cyber Security Directorate (DNSC) a technical role in setting requirements and approving investments, while the eligible expenditures of transmission and distribution system operators could be recognized in tariffs according to ANRE methodologies. This shift is more significant than a simple new cost category. It moves the digital protection of infrastructure from the realm of technical investments that operators must justify individually to a legislative architecture where cyber necessity and economic cost recovery are explicitly linked. However, the draft is not yet law. The amended version is currently making its way through parliament, including a vote in the plenary of the Chamber of Deputies, and differences from the text previously passed by the Senate could trigger its return to the upper house. Cybersecurity Becomes an Infrastructure Investment, Not Just an IT Expense Modern energy grids rely on digital systems for monitoring, communications, automation, and control. From this perspective, cyber protection is no longer just about computers and databases, but about the operator's ability to maintain control over the energy infrastructure when its digital systems are attacked. ANRE had already formulated this logic before it appeared so explicitly in the current legislative framework. In September, the institution's president, George-Sergiu Niculescu, informed operators that necessary cybersecurity investments should not be delayed out of fear that they would not be recognized, as long as they are necessary, properly justified, and documented. NRG-IA pointed out at the time that current methodologies already allow for the consideration of justified costs and the inclusion of eligible investments in regulated activity mechanisms. The ANRE president's message was direct: „We have created the regulatory framework. Operators must invest and protect their infrastructure.” However, the legislative draft currently under discussion adds something essential: it explicitly introduces the technical cybersecurity component into the investment pathway and assigns a role to the DNSC before the investment enters the economic mechanism managed by ANRE. DNSC Verifies Technical Necessity, ANRE Retains the Economic Filter The DNSC would establish the technical cybersecurity standards applicable to the targeted sectors and intervene in validating plans and investments in this area. ANRE would continue to decide, through its own methodologies, which costs are eligible and to what extent they can be recognized in regulated tariffs. This separation is important for both consumers and operators. A technical security approval does not automatically mean full cost recovery through the tariff. The investment must also pass through the regulator's economic filter. The current framework described by ANRE already requires a cost to be justified by necessity, opportunity, and efficiency, and eligible investments must be substantiated and documented. The public stance expressed in September ruled out the idea that any IT purchase made by an operator could be automatically passed on to the tariff. The new legislative formula reinforces this logic: the DNSC determines whether the investment meets security requirements, while ANRE determines its economic treatment within the regulated activity. Eligible Costs Can Be Passed Through to Network Tariffs Transmission and distribution system operators function under a regulated regime. Investments and costs accepted by ANRE are recovered over time through network tariffs. If cybersecurity investments receive an explicit legislative basis and meet both technical and economic criteria, eligible costs can enter this equation. However, based on available information, no distinct „cybersecurity fee” will appear on bills. The proposed mechanism concerns the recognition of costs within existing regulated tariffs. Furthermore, the financial impact cannot be calculated at this stage. The available documentation does not provide a total value for the investments to be introduced into tariffs, nor any calculation in RON/MWh or as a percentage of the final bill. Nevertheless, the economic consequence is clear: when a cyber investment is deemed necessary for the secure operation of the grid, the operator would have a more explicit legislative basis for recovering the eligible cost through the regulatory mechanism. The Draft Began with a Controversy Over Prosumers and Ended Up Targeting the Security of the Entire Infrastructure The evolution of the legislative text is also significant due to the shift in its center of gravity. In November 2025, the public dispute focused on fears that the new rules could lead to the auditing or control of prosumers' equipment. ANRE explicitly rejected this…

Read the full article on NRG-IA →