Services ▾
Weak currents and networks
Weak currents and networks
Certified and documented voice-data networks. View category →
Fire safety
Fire safety
Authorized IGSU · ISU approval and authorization. View category →
Cybersecurity
Cybersecurity
ISO/IEC 27001 certificate. View category →
IT Service and Outsourcing
IT Service and Outsourcing
Your IT department, outsourced — support, servers, M365, backup. View category →
HVAC maintenance
HVAC maintenance
Scheduled checks and interventions for air conditioning. View category →
Corporate Sales and SEAP
Corporate Sales and SEAP
IT equipment and security, including through SEAP. View category →
BlogContact
Blog Fire Safety

Risk analysis or safety data sheet? What changed in Law 333 of May 2026

Until May 2026, the answer to the question "do I need risk analysis?" was, for most companies, yes. Government Emergency Ordinance 37/2026 changed this: it introduced a new chapter in Law 333/2003, dedicated to the assessment of physical security risks (art. 491–4910), and divided the units into two categories with different obligations.

If you manage a building, a hall, a hotel or a commercial space, it's worth five minutes to know which category you're in. The wrong document costs money for nothing; the lack of the right document costs during inspection.

The two regimes, in brief

Physical security risk analysis remains mandatory for the units whose methodological rules establish minimum security requirements — regarding security, burglar alarm systems and constructive-architectural characteristics (art. 492). It is prepared exclusively by an evaluator registered in the National Register of Physical Security Risk Assessors.

Safety data sheet is the document of the other units. They implement measures according to their own needs, based on their own risk assessment, materialized in the sheet (art. 499). It doesn't require an authorized evaluator — but it doesn't exempt you from thinking seriously about security either.

The practical difference: the first is a technical document made by a qualified third party, the second is a documented self-assessment. The confusion between the two is the most common reason why companies pay what they don't need or are left without what they need.

How do you find out which category you are in?

Here's the awkward part. I do the remote work methodological rules, which establish who has minimum security requirements. The ordinance provides for the amendment of GD 301/2012 within 90 days of its entry into force, and the format of the security sheet is to be established by order of the Minister of Internal Affairs.

At the time of this article, these acts had not been published. Until they appear, existing regulations apply to the extent that they do not contradict the amended law — which means an area of interpretation in which it is best not to improvise on your own.

What you can do concretely now:

  • check whether your facility was already listed, under the previous regulation, among those with minimum security requirements — usually units that handle or store cash and valuables, commercial premises above certain thresholds, and public interest facilities;
  • if you already have a valid risk analysis, keep it: contracts and analyses carried out before the change remain valid;
  • If you don't have any documents, don't start by ordering an analysis — start by checking the framing.

Review deadlines have changed

The old Instruction MAI 9/2013 provided for a review at least once every 3 years, plus short deadlines for incidents and changes. The ordinance passed on deadlines related exclusively to events (art. 49)3):

  • no more than 90 days from changing internal or external parameters;
  • at most 60 days from the occurrence of a relevant physical security incident;
  • at most 30 days from modifying architectural-constructive characteristics or from not implementing the established measures.

The periodic review every three years does not appear in the text of the ordinance. Until clarified by regulations, the practical recommendation remains to keep the three-year cycle as good practice — but the deadlines that may cause you difficulty during an inspection are the ones above, and the shortest is 30 days.

Translation for the building manager: an office re-compartmentation, a hall expansion, or a burglary starts a one-month clock. Not three years.

Who else can prepare the analysis?

The conditions for the evaluator have become stricter. According to art. 493, the evaluator must cumulatively meet several requirements: Romanian citizenship or that of an EU/EEA member state, medical fitness, lack of convictions for intentional crimes, appropriate professional skills, quality of employee or manager at an entity with CAEN codes 7112 or 8009 and authorization from the Romanian Police.

The verification is simple and worth doing before paying: ask for proof of registration with RNERSF.

The incompatibility that no one talks about

The most important change for those who buy security services is art. 497: the evaluator cannot perform the analysis for units with which his company has ongoing security or burglar alarm system contracts — both during the analysis period and during the implementation of the measures.

Basically: the company that maintains your alarm system can no longer do your risk analysis while the contract is ongoing. And the analysis that recommends exactly the equipment sold by the person who wrote it was, anyway, a substantive issue — the law has now turned it into a compliance issue.

If you're used to getting everything from the same provider, it's time to separate roles. Ask your provider directly in what capacity they can work with you.

What remains valid from what you already have

  • Previously performed analyses remain valid; ongoing contracts for the performance of risk analyses continue to have their effects.
  • Existing licenses and certifications remain valid until expiration, with renewal to be made according to updated procedures.
  • Measures already implemented It doesn't get dismantled. What changes is the document on which you justify them and the pace at which you update it.

Three things to do in the coming weeks

  1. Determine which category you fall into. — risk analysis or safety data sheet. Without this, any expense is a gamble.
  2. Check the age of the current document and if something has happened in the meantime that triggers one of the 90, 60 or 30 day deadlines.
  3. Check if your appraiser can still work with you, in the light of art. 497.

How can we help you?

GreenSoft is an IGPR licensed company and works in Constanta and Dobrogea on physical security systems. We check the scope of your objective — if you need it physical security risk analysis or safety data sheet — without charging for this verification, and we tell you transparently, from the first discussion, in what capacity we can work with you without violating incompatibility rules.

If you are interested in what the document should actually contain, I have written separately about risk analysis structure, chapter by chapter.

Informative article, updated on August 30, 2026. The legislation is in a transitional period — the methodological norms and the order on the safety data sheet were not published at the time of writing. For your specific situation, request a verification of the classification.

Do you have a new project or an existing building?

Talk to GreenSoft for an initial technical assessment and a clear integration, implementation or maintenance plan.

Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton
Bentel Security
Teledata
NSC Sicherheitstechnik
FireClass
Fire Eater
Hilti
Promat
TOA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno
VIGI
Dahua Technology
Novus
DSC
Paradox
Ajax Systems
Rosslare Security
YLI
KaDe
Dell
Seagate
TP-Link
Omada
HP
EnGenius
3M
Fortinet
Grandstream
Panasonic
Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton
Bentel Security
Teledata
NSC Sicherheitstechnik
FireClass
Fire Eater
Hilti
Promat
TOA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno
VIGI
Dahua Technology
Novus
DSC
Paradox
Ajax Systems
Rosslare Security
YLI
KaDe
Dell
Seagate
TP-Link
Omada
HP
EnGenius
3M
Fortinet
Grandstream
Panasonic