Opens in a new tab
Physical security

Physical security risk analysis in Constanta

The document that Law 333/2003 requires before establishing the security and guarding systems of a facility. Prepared by an evaluator registered with the RNERSF.

since 2004ANRE · IGSU · IGPRISO/IEC 27001
Analiză de risc la securitate fizică în Constanța

Physical security risk analysis It transforms the vulnerabilities of an site into a set of proportionate, explained and enforceable measures. It is not a promise of zero risk nor a generic list of equipment.

You will also encounter the name "risk assessment", it is the same document. The term used by the legislation is physical security risk analysis.

GreenSoft carries out assessments for the sites and categories for which the applicable legislation requires this approach, through personnel with the necessary skills and registrations. The location, activity, assets, flows, incident history and existing measures are analyzed.

The report describes the risks and recommends organizational, mechanical, electronic and procedural measures. If the client wishes, GreenSoft can continue with the design and implementation of the systems, keeping the role of the assessment and the investment decision distinct.

Who is required to have a risk analysis?

Attention: the rule changed in May 2026. Until Government Emergency Ordinance 37/2026, risk analysis was required, in practice, for almost all units under Law 333/2003. The Ordinance introduced a separate chapter into the law (art. 491–4910) and divided the units into two:

  • Units for which the rules establish minimum security requirements, regarding security, burglar alarm systems and constructive-architectural features. For them, risk analysis remains mandatory (art. 492).
  • The rest of the units, implements measures according to its own needs, based on its own assessment, materialized in a safety data sheet (art. 49)9).

The starting point remains Law 333/2003, art. 2 paragraph (1), which lists the units that fall under the law:

  • ministries and other specialized bodies of central and local public administration
  • autonomous governments, companies and national societies
  • national research and development institutes
  • companies regulated by Law 31/1990, regardless of the nature of the share capital
  • other organizations that hold assets or valuables under any title

But falling under the law no longer automatically means you need a risk analysis. The separation is done by methodological norms, which establish who has minimal security requirements. The rules had not yet been updated at the date of this text., GEO 37/2026 provides for the amendment of GD 301/2012, and until then, the existing regulations apply to the extent that they do not contravene the amended law.

For this reason, the first thing we do is determine whether your site requires a risk analysis or a safety data sheet. There is no charge for checking the classification., and it can save you from a document you don't need.

What does the document contain?

right MIA Instruction no. 9/2013, art. 7 para. (1), the physical security risk analysis is materialized in three components:

  1. Risk assessment and treatment report, description of the site, the activity and values exposed, applicable threats, identified vulnerabilities, risk estimate and proposed measures.
  2. Evaluation grid specific to the object of activity.
  3. documents backing, questionnaires, statements, plans, photographs and the data on which the conclusions are based.

The analyses are carried out by experts registered in National Register of Physical Security Risk Assessors (RNERSF), Instruction 9/2013, art. 8 para. (1). A document signed by someone else has no effect.

When to review

GEO 37/2026 also rewrote the deadlines. According to Article 493 of Law 333/2003 in its current form, the analysis is revised:

  • within 90 days at most from changing internal or external parameters
  • within 60 days at most since the occurrence of a relevant physical security incident
  • within 30 days at most from the modification of architectural-constructive characteristics or from the failure to implement the established measures

Notice what's missing: periodic review every 3 years, provided for by MIA Instruction no. 9/2013, is not taken over in the text of the ordinance. Until the methodological norms are updated, the situation remains to be clarified, and our practical recommendation is to keep the three-year cycle as good practice, the cost is low, and the risk of non-compliance during the control, no.

The new deadlines are linked to events, not the calendar. A industrial building expansion, a re-compartmentation or a break-in starts the clock, and the shortest deadline is 30 days.

What does the service include?

  • Collecting the documents and data about the site
  • Field inspection and vulnerability analysis
  • Evaluation of existing measures
  • Report with risk levels and recommendations
  • Implementation plan and update when necessary

Why GreenSoft

The recommendations are written by people who know CCTV, access control, anti-burglary, networks and maintenance, so they are achievable and budgetable, not theoretical. However, the document remains a substantiated analysis, not a justification for equipment, and the incompatibility rules introduced by GEO 37/2026 are strictly respected.

How the project is progressing

  1. Clarification of the classification and required documents
  2. Inspection and discussions with those responsible
  3. Risk analysis and report writing
  4. Presentation of measures and planning of reviews

For which types of sites

  • Commercial units
  • storage spaces
  • OFFICE
  • hotels
  • institutions and other sites for which the assessment is required or useful

Tell us what your site is and if you have received any address from the Police. We will tell you for free if you need a risk analysis or a safety data sheet.

Request a quote

Where we work

We cover the entire county of Constanta: Constanta municipality, Mamaia, Năvodari, Ovidiu, Agigea, Eforie, Techirghiol, Mangalia, Medgidia and Cernavodă, including the port perimeter, based on the work license in the Port of Constanta. For larger works, we travel throughout Dobrogea.

Useful resources

Frequently asked questions

Who is required by law to have a physical security risk assessment?

Law 333/2003, art. 2 par. (1) lists the ministries and other specialized bodies of public administration, autonomous regies, national companies and societies, national research and development institutes, companies regulated by Law 31/1990 regardless of the nature of the share capital and other organizations that hold goods or values under any title. After GEO 37/2026, however, the risk analysis remains mandatory only for units whose norms establish minimum security requirements; the others draw up a security sheet based on their own assessment. Let's check together which category you fall into.

What are the fines provided by the legislation in case of lack of risk analysis?

The lack of a risk analysis is sanctioned with substantial fines, and the authorities may also impose additional measures until remediation. In addition to the fine, in the event of an incident, the lack of the document puts you at a legal disadvantage and in your relationship with the insurer. The cost of the assessment is much lower than that of the risk of non-compliance.

How long is the physical security risk assessment report valid?

According to GEO 37/2026, the deadlines are linked to events: no more than 90 days from the modification of internal or external parameters, no more than 60 days from a relevant physical security incident and no more than 30 days from architectural-constructive changes. The periodic review every 3 years from the old Instruction 9/2013 does not appear in the text of the ordinance, until the norms are updated, we recommend it as a good practice. We will notify you when a deadline is approaching.

What happens if the risk analysis finds that the current alarm systems are insufficient?

The report explicitly indicates the deficiencies and the minimum necessary measures, formulated through functions and levels of protection, not through brands. Implementation remains a separate decision of the client, who can choose any executor. OUG 37/2026 introduced strict rules of incompatibility between the role of evaluator and that of provider of security services or alarm systems for the same unit (art. 497), and we respect them, we tell you from the first discussion in what capacity we can work with you.

What are the concrete steps in carrying out a risk assessment for a company in Constanta?

The evaluator visits the location, analyzes the location, flows, values and vulnerabilities, then applies the legal methodology and prepares the report with the recommended measures. From the visit to the handover of the document, it usually takes:, 5–10 business days, depending on the complexity of the site. We guide you every step of the way, from scheduling to the final document.

Is there a standard risk analysis model?

The structure comes from the MIA Instruction no. 9/2013, evaluation report, evaluation grid and supporting documents, applicable until the update of the norms required by GEO 37/2026. However, there is no universal form to fill in: the content is built on the specific site, after the field visit. I explained in detail what the document should contain, chapter by chapter.

Does the assessment guarantee that there will be no incidents?

No. It identifies and treats risks to an acceptable level through proportionate measures; the risk cannot be completely eliminated.

Does the report force you to buy certain brands?

Recommendations should be formulated through functions and protection levels. The choice of technical solution is made later.

Shall we discuss your project?

Free initial technical consultation and quote within 3–5 business days.

Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton, detecție incendiu
Bentel Security
Teledata
NSC Sicherheitstechnik, centrale de incendiu
FireClass, detecție incendiu
Fire Eater, stingere incendiu
Hilti, protecție pasivă la foc
Promat, protecție pasivă la foc
TOA, sonorizare PA/VA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno, supraveghere video CCTV
VIGI
Dahua Technology
Novus, supraveghere video CCTV
DSC
Paradox
Ajax Systems
Rosslare Security
YLI, control acces
KaDe, control acces
Dell
Seagate
TP-Link
Omada
HP
EnGenius, WiFi profesional
3M
Fortinet, securitate cibernetică
Grandstream
Panasonic, centrale telefonice
Polon-Alfa
Inim Electronics
Schrack Seconet
Honeywell
Securiton, detecție incendiu
Bentel Security
Teledata
NSC Sicherheitstechnik, centrale de incendiu
FireClass, detecție incendiu
Fire Eater, stingere incendiu
Hilti, protecție pasivă la foc
Promat, protecție pasivă la foc
TOA, sonorizare PA/VA
Schneider Electric
Siemens
Schrack Technik
Riello UPS
Gewiss
Hikvision
Axis Communications
Luxriot
Veno, supraveghere video CCTV
VIGI
Dahua Technology
Novus, supraveghere video CCTV
DSC
Paradox
Ajax Systems
Rosslare Security
YLI, control acces
KaDe, control acces
Dell
Seagate
TP-Link
Omada
HP
EnGenius, WiFi profesional
3M
Fortinet, securitate cibernetică
Grandstream
Panasonic, centrale telefonice
Call now