Opens in a new tab
Blog · Physical Security

GEO 37/2026 amends Law 333: is your building's security system still adequate to current risks?

OUG 37/2026 modifică Legea 333: este sistemul de securitate al clădirii dumneavoastră încă adecvat riscurilor actuale?
GEO 37/2026 amends Law 333: is your building's security system still adequate to current risks?

GEO 37/2026 amends Law 333/2003 and introduces a new chapter in the law, dedicated exclusively to physical security risk assessment (art. 491–4910). Change of substance: the units no longer all have the same obligation. Those whose rules establish minimum security requirements remain obliged to hold risk analysis prepared by an evaluator registered in the RNERSF. The rest prepare a safety data sheet, based on its own assessment.

The ordinance came into effect in May 2026. Below you can find what specifically changes, what deadlines bind you, who can still sign the document, and what remains valid from what you already have.

If you want a risk analysis prepared by an evaluator registered with the RNERSF or just to find out what category you are in, see the service page risk analysis in physical security Constanta: the eligibility check is free.

What does GEO 37/2026 provide, by articles

The ordinance does not rewrite Law 333 in its entirety. It adds a chapter and changes a few rules that directly matter to the building administrator:

  • Article 491–4910 — new chapter dedicated to physical security risk assessment.
  • Article 492 — establishes that risk analysis remains mandatory for units to which methodological norms impose minimum security requirements (security, burglar alarm systems, constructive-architectural characteristics).
  • Article 493 — the deadlines for reviewing the analysis and the conditions that the evaluator must meet.
  • Article 497 — incompatibility between the quality of evaluator and ongoing security or alarm system contracts.
  • Article 499 — safety data sheet, document of other units.

The two regimes introduced by GEO 37/2026

Physical security risk analysis is a technical document prepared by a qualified third party — an evaluator registered in the National Register of Physical Security Risk Assessors. It is the basis of the security plan, the design physical security systems and the site's protective measures.

Safety data sheet is a documented self-assessment. It does not require an authorized assessor. The unit implements measures according to its own needs, based on its own risk assessment, materialized in the sheet.

Confusion between the two is the most common reason why companies pay for a document they didn't need or are left without one they needed. If you're not sure which category you fall into, we've detailed the distinction in the article about risk analysis or safety data sheet.

The review deadlines introduced by GEO 37/2026

This is the change that catches most administrators off guard. The old Instruction MAI 9/2013 required a review at least once every 3 years. The ordinance passed on deadlines related exclusively to events (art. 49)3):

  • no more than 90 days from changing internal or external parameters;
  • at most 60 days from the occurrence of a relevant physical security incident;
  • at most 30 days from modifying architectural-constructive characteristics or from not implementing the established measures.

The periodic review every three years no longer appears in the text of the ordinance. As a good practice, keep the three-year cycle. But the deadlines that make it difficult for you to control are the ones above, and the shortest is 30 days.

Translated for the building manager: an office re-compartmentation, a hall expansion, or a burglary starts a one-month clock. Not three years.

Who can still prepare the risk analysis according to GEO 37/2026?

The conditions for the evaluator have become stricter. According to art. 493, the evaluator must cumulatively meet: Romanian citizenship or that of an EU/EEA member state, medical fitness, no convictions for intentional crimes, appropriate professional skills, quality of employee or manager at an entity with CAEN codes 7112 or 8009 and authorization from the Romanian Police.

The verification is simple and worth doing before paying: ask for proof of registration with RNERSF.

The incompatibility introduced by art. 497

The most important change for those who buy security services: the evaluator cannot perform the analysis for units with which his company has ongoing security or burglar alarm system contracts — both during the analysis period and during the implementation of the measures.

Basically: the company that maintains your alarm system can no longer do your risk analysis while the contract is ongoing. The analysis that recommended exactly the equipment sold by the person who wrote it was a fundamental problem anyway. OUG 37/2026 turned it into a compliance issue.

If you're used to getting everything from the same provider, it's time to separate roles. Ask your provider directly in what capacity they can work with you.

What remains valid and what norms are still missing

  • Previously performed analyses remain valid; ongoing contracts for the performance of the analyses continue to have their effects.
  • Existing licenses and certifications remain valid until expiration, with renewal following updated procedures.
  • Measures already implemented It doesn't get dismantled. The document on which you justify them and the pace at which you update it change.

The effective separation between the two categories is made by methodological rules. The ordinance provides for the amendment of GD 301/2012 within 90 days of its entry into force, and the format of the safety data sheet is to be established by order of the Minister of Internal Affairs. At the time of updating this article, these acts had not been published. Until they appear, the existing regulations apply to the extent that they do not contradict the amended law — an area of interpretation in which it is better not to improvise on your own.

Does the existing risk analysis still reflect reality?

Many risk analyses were carried out years ago. In the meantime, buildings have changed. The following have emerged:

  • new tenants;
  • new flows of people;
  • new commercial spaces;
  • additional IT systems;
  • new access areas;
  • high value equipment.

Often, security systems have remained the same, even though the level of risk at the target has changed significantly. An analysis done five or ten years ago may no longer describe the real situation on the ground — and under the new terms, any of the above changes could already trigger the obligation to review.

The most common problems encountered in buildings

The same situations frequently occur in technical assessments:

  • video cameras with significant dead zones;
  • insufficient images to identify people;
  • incomplete or technologically outdated access control;
  • lack of access logging;
  • alarm systems that no longer correspond to the current configuration of the building;
  • changes to compartmentalization without updating security measures;
  • outdated documentation.

These problems are not apparent until the time of an incident or inspection. Access control, video surveillance and centralized monitoring provide complete traceability of events — exactly what an evaluator asks you to document.

When should you request a physical security risk analysis?

An audit is recommended if:

  • the existing risk analysis is old;
  • significant changes were made to the building;
  • new activities or tenants have emerged;
  • video systems are over 5–7 years old;
  • access control no longer meets current needs;
  • there are repeated security incidents;
  • A reassessment of protective measures is being prepared.

Frequently asked questions about GEO 37/2026

What is GEO 37/2026?

It is the emergency ordinance that amends Law 333/2003 on the guarding of premises, goods, values and the protection of persons. It introduces a new chapter dedicated to the assessment of physical security risks (art. 491–4910) and divides the units into two categories, with different documentation obligations.

When did GEO 37/2026 enter into force?

In May 2026. The methodological rules of application — amending GD 301/2012 and the order regarding the format of the safety data sheet — were not published at the time of updating this article.

Do I still need a risk analysis after GEO 37/2026?

It depends on the category you fall into. If the rules set minimum security requirements for you, yes — and it must be prepared by an evaluator registered with the RNERSF. If not, prepare a safety data sheet based on your own assessment.

Is the risk analysis done before GEO 37/2026 still valid?

Yes. Previously conducted analyses remain valid, and ongoing contracts continue to take effect. However, be aware of the 90, 60, and 30-day review periods that are triggered by events.

Can the company that maintains my alarm system do a risk analysis for me?

No, as long as the contract is ongoing. Art. 497 prohibits the evaluator from performing the analysis for units with which his company has security or burglar alarm system contracts, during the analysis period and within the implementation period of the measures.

What happens if I don't have any documents?

Don't start by ordering an analysis. Start by checking the classification: the wrong document costs money for nothing, the lack of the right document costs during the inspection.

How GreenSoft can help you

GreenSoft is an IGPR licensed company and works in Constanta and Dobrogea on physical security systems for commercial buildings, hotels, industrial units and public institutions. During an audit we evaluate:

  • existing CCTV systems;
  • access control;
  • burglar alarm systems;
  • security systems integration;
  • documentation and compliance with current legal requirements.

We verify the scope of your site — risk analysis or safety data sheet — without charging for this verification, and we tell you from the first discussion in what capacity we can work with you without violating incompatibility rules.

If you haven't reviewed your security systems and risk analysis in recent years, now is the time for one. physical security risk analysis carried out by an evaluator registered with the RNERSF. Contact GreenSoft for a physical security audit.

Informative article, updated on September 11, 2026. The legislation is in a transitional period — the methodological norms and the order on the safety data sheet were not published at the time of writing. For your specific situation, request a verification of the classification.

Did you like the article? Share:

GreenSoft Service

You need risk assessment and physical security in Constanta? Request a quote →

Do you have a new project or a building in operation?

Tell us what building you have and what is hurting you right now. You will receive an on-site technical assessment and offer within 3-5 business days.

Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton, detecție incendiu
Bentel Security
Teledata
NSC Sicherheitstechnik, centrale de incendiu
FireClass, detecție incendiu
Fire Eater, stingere incendiu
Hilti, protecție pasivă la foc
Promat, protecție pasivă la foc
TOA, sonorizare PA/VA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno, supraveghere video CCTV
VIGI
Dahua Technology
Novus, supraveghere video CCTV
DSC
Paradox
Ajax Systems
Rosslare Security
YLI, control acces
KaDe, control acces
Dell
Seagate
TP-Link
Omada
HP
EnGenius, WiFi profesional
3M
Fortinet, securitate cibernetică
Grandstream
Panasonic, centrale telefonice
Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton, detecție incendiu
Bentel Security
Teledata
NSC Sicherheitstechnik, centrale de incendiu
FireClass, detecție incendiu
Fire Eater, stingere incendiu
Hilti, protecție pasivă la foc
Promat, protecție pasivă la foc
TOA, sonorizare PA/VA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno, supraveghere video CCTV
VIGI
Dahua Technology
Novus, supraveghere video CCTV
DSC
Paradox
Ajax Systems
Rosslare Security
YLI, control acces
KaDe, control acces
Dell
Seagate
TP-Link
Omada
HP
EnGenius, WiFi profesional
3M
Fortinet, securitate cibernetică
Grandstream
Panasonic, centrale telefonice