{"id":320,"date":"2026-08-30T15:11:42","date_gmt":"2026-08-30T13:11:42","guid":{"rendered":"https:\/\/green-soft.ro\/analiza-de-risc-sau-fisa-de-securitate\/"},"modified":"2026-08-30T15:11:42","modified_gmt":"2026-08-30T13:11:42","slug":"analiza-de-risc-sau-fisa-de-securitate","status":"publish","type":"post","link":"https:\/\/green-soft.ro\/en\/analiza-de-risc-sau-fisa-de-securitate\/","title":{"rendered":"Risk analysis or safety data sheet? What changed in Law 333 of May 2026"},"content":{"rendered":"<p>Until May 2026, the answer to the question &quot;do I need risk analysis?&quot; was, for most companies, yes. <a href=\"https:\/\/green-soft.ro\/en\/oug-37-2026-legea-333-securitate-fizica\/\">Government Emergency Ordinance 37\/2026<\/a> changed this: it introduced a new chapter in Law 333\/2003, dedicated to the assessment of physical security risks (art. 49<sup>1<\/sup>\u201349<sup>10<\/sup>), and divided the units into two categories with different obligations.<\/p>\n<p>If you manage a building, a hall, a hotel or a commercial space, it&#039;s worth five minutes to know which category you&#039;re in. The wrong document costs money for nothing; the lack of the right document costs during inspection.<\/p>\n<h2>The two regimes, in brief<\/h2>\n<p><strong>Physical security risk analysis<\/strong> remains mandatory for the units whose methodological rules establish <em>minimum security requirements<\/em> \u2014 regarding security, burglar alarm systems and constructive-architectural characteristics (art. 49<sup>2<\/sup>). It is prepared exclusively by an evaluator registered in the National Register of Physical Security Risk Assessors.<\/p>\n<p><strong>Safety data sheet<\/strong> is the document of the other units. They implement measures according to their own needs, based on their own risk assessment, materialized in the sheet (art. 49<sup>9<\/sup>). It doesn&#039;t require an authorized evaluator \u2014 but it doesn&#039;t exempt you from thinking seriously about security either.<\/p>\n<p>The practical difference: the first is a technical document made by a qualified third party, the second is a documented self-assessment. The confusion between the two is the most common reason why companies pay what they don&#039;t need or are left without what they need.<\/p>\n<h2>How do you find out which category you are in?<\/h2>\n<p>Here&#039;s the awkward part. I do the remote work <strong>methodological rules<\/strong>, which establish who has minimum security requirements. The ordinance provides for the amendment of GD 301\/2012 within 90 days of its entry into force, and the format of the security sheet is to be established by order of the Minister of Internal Affairs.<\/p>\n<p>At the time of this article, these acts had not been published. Until they appear, existing regulations apply to the extent that they do not contradict the amended law \u2014 which means an area of interpretation in which it is best not to improvise on your own.<\/p>\n<p>What you can do concretely now:<\/p>\n<ul class=\"gs-check gs-check-hover\">\n<li>check whether your facility was already listed, under the previous regulation, among those with minimum security requirements \u2014 usually units that handle or store cash and valuables, commercial premises above certain thresholds, and public interest facilities;<\/li>\n<li>if you already have a valid risk analysis, keep it: contracts and analyses carried out before the change remain valid;<\/li>\n<li>If you don&#039;t have any documents, don&#039;t start by ordering an analysis \u2014 start by checking the framing.<\/li>\n<\/ul>\n<h2>Review deadlines have changed<\/h2>\n<p>The old Instruction MAI 9\/2013 provided for a review at least once every 3 years, plus short deadlines for incidents and changes. <strong>The ordinance passed on deadlines related exclusively to events<\/strong> (art. 49)<sup>3<\/sup>):<\/p>\n<ul class=\"gs-check gs-check-hover\">\n<li><strong>no more than 90 days<\/strong> from changing internal or external parameters;<\/li>\n<li><strong>at most 60 days<\/strong> from the occurrence of a relevant physical security incident;<\/li>\n<li><strong>at most 30 days<\/strong> from modifying architectural-constructive characteristics or from not implementing the established measures.<\/li>\n<\/ul>\n<p>The periodic review every three years does not appear in the text of the ordinance. Until clarified by regulations, the practical recommendation remains to keep the three-year cycle as good practice \u2014 but the deadlines that may cause you difficulty during an inspection are the ones above, and the shortest is 30 days.<\/p>\n<p>Translation for the building manager: an office re-compartmentation, a hall expansion, or a burglary starts a one-month clock. Not three years.<\/p>\n<h2>Who else can prepare the analysis?<\/h2>\n<p>The conditions for the evaluator have become stricter. According to art. 49<sup>3<\/sup>, the evaluator must cumulatively meet several requirements: Romanian citizenship or that of an EU\/EEA member state, medical fitness, lack of convictions for intentional crimes, appropriate professional skills, quality of employee or manager at an entity with CAEN codes 7112 or 8009 and authorization from the Romanian Police.<\/p>\n<p>The verification is simple and worth doing before paying: ask for proof of registration with RNERSF.<\/p>\n<h2>The incompatibility that no one talks about<\/h2>\n<p>The most important change for those who buy security services is art. 49<sup>7<\/sup>: <strong>the evaluator cannot perform the analysis for units with which his company has ongoing security or burglar alarm system contracts<\/strong> \u2014 both during the analysis period and during the implementation of the measures.<\/p>\n<p>Basically: the company that maintains your alarm system can no longer do your risk analysis while the contract is ongoing. And the analysis that recommends exactly the equipment sold by the person who wrote it was, anyway, a substantive issue \u2014 the law has now turned it into a compliance issue.<\/p>\n<p>If you&#039;re used to getting everything from the same provider, it&#039;s time to separate roles. Ask your provider directly in what capacity they can work with you.<\/p>\n<h2>What remains valid from what you already have<\/h2>\n<ul class=\"gs-check gs-check-hover\">\n<li><strong>Previously performed analyses<\/strong> remain valid; ongoing contracts for the performance of risk analyses continue to have their effects.<\/li>\n<li><strong>Existing licenses and certifications<\/strong> remain valid until expiration, with renewal to be made according to updated procedures.<\/li>\n<li><strong>Measures already implemented<\/strong> It doesn&#039;t get dismantled. What changes is the document on which you justify them and the pace at which you update it.<\/li>\n<\/ul>\n<h2>Three things to do in the coming weeks<\/h2>\n<ol class=\"gs-steps\">\n<li><strong>Determine which category you fall into.<\/strong> \u2014 risk analysis or safety data sheet. Without this, any expense is a gamble.<\/li>\n<li><strong>Check the age of the current document<\/strong> and if something has happened in the meantime that triggers one of the 90, 60 or 30 day deadlines.<\/li>\n<li><strong>Check if your appraiser can still work with you<\/strong>, in the light of art. 49<sup>7<\/sup>.<\/li>\n<\/ol>\n<h2>How can we help you?<\/h2>\n<p>GreenSoft is an IGPR licensed company and works in Constanta and Dobrogea on physical security systems. We check the scope of your objective \u2014 if you need it <a href=\"https:\/\/green-soft.ro\/en\/servicii\/securitate-fizica\/evaluare-risc-securitate-fizica\/\">physical security risk analysis<\/a> or safety data sheet \u2014 without charging for this verification, and we tell you transparently, from the first discussion, in what capacity we can work with you without violating incompatibility rules.<\/p>\n<p>If you are interested in what the document should actually contain, I have written separately about <a href=\"https:\/\/green-soft.ro\/en\/model-analiza-de-risc-la-securitate-fizica\/\">risk analysis structure, chapter by chapter<\/a>.<\/p>\n<p><em>Informative article, updated on August 30, 2026. The legislation is in a transitional period \u2014 the methodological norms and the order on the safety data sheet were not published at the time of writing. For your specific situation, request a verification of the classification.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>GEO 37\/2026 divided the units into two: those that need a risk analysis and those that draw up a security sheet. Plus new review deadlines and an incompatibility that changes the way you buy security services.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-320","post","type-post","status-publish","format-standard","hentry","category-fara-categorie"],"_links":{"self":[{"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/posts\/320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/comments?post=320"}],"version-history":[{"count":0,"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/posts\/320\/revisions"}],"wp:attachment":[{"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/media?parent=320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/categories?post=320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/green-soft.ro\/en\/wp-json\/wp\/v2\/tags?post=320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}