Document colectat · PNRR România, plan și decizii
Preliminary assessment of the second payment request of Romania
- Instituția sau publicația sursă
- PNRR România, plan și decizii
- Data preluării
- 26.09.2026 17:54
- Dimensiunea materialului
- 1.679,9 KB
Conținutul disponibil în colecție
Textul documentului
ailability of IT systems alongside
strategic considerations such as cybersecurity are taken into account.
The legislative and regulatory package to operationalise the Government Cloud is also described in
the first chapter. The Government Emergency Ordinance for the governance of the government
cloud and the interoperability law are described in section 1.3 of the report on “legislative package
including interoperability rules and government data governance model”. This section makes clear
that the development of a uniform framework for defining the government cloud architecture will
be provided by these two legislative acts.
The analysis shall present the possibilities for the construction, delivery, installation and
operation of civilian and technological infrastructures in accordance with the deadlines laid down
in the Plan
The second chapter of the report presents a timeline in accordance with the deadlines in the
recovery and resilience plan for the operationalisation of civilian and technological infrastructures,
including the possibilities for the construction, delivery and installation. According to the Annex to
the Council Implementation Decision, the deployment of the government cloud infrastructure
should be completed by the end of 2025, which is the timeline indicated on page 161 of the report.
The report presents the two market consultations carried out which provided: (i) information on the
budget estimates required for the procurement of ICT hardware and software products with
associated installation, configuration, commissioning services in the four Government Cloud Data
Centres (pages 163 to 171); and (ii) a wide range of solutions, services and technologies, to ensure
the cybersecurity of the Government Cloud (pages 172 to 178).
The analysis shall present the mapping of public digital applications/services currently offered by
state authorities, along with the design of processes and procedures implemented, in production
and/or at implementation stages
Section 1.4 of the report assesses the inventory of digital applications and systems ensuring the
16
provision of public services (pages 112 to 148). In turn, chapter 3 presents the mapping of digital
applications and services currently offered by Romanian public authorities, along with the design of
processes and current procedures implemented, both at production and implementation stages.
The analysis shall present the cloud development/migration plan of the mapped applications
Chapter 4 of the report dated 26 June on 2022 presents the cloud development and migration plan
of the mapped government applications and services describing the general steps and principles
that will guide the migration of the IT systems currently under the management of various central
public institutions (pages 190 to 207).
Commission Preliminary Assessment: Satisfactorily fulfilled
Related Measure: Development of a unitary framework for defining the
Number: 144
architecture of a government cloud system
Name of the Milestone: Entry into force of the law for the governance of cloud services for the
government area
Qualitative Indicator: Provision in the law indicating the entry into force of
Time: Q2 2022
the cloud services governance law
Context:
Milestone #144 is part of reform C7.R1 for the development of a unitary framework for defining the
architecture of a government cloud system. The reform’s overarching objective is to modernise the
public administration by adopting advanced technologies and focusing on the citizens and
businesses’ needs, while ensuring the prerequisites for data-driven policy development and
increasing the interoperability of existing digital technologies.
Milestone #144 requires the entry into force of the law for the governance of cloud services for the
government area. The new law establishes a general framework for the development and
management of a cloud infrastructure, consisting of a set of information technology,
communications and cybersecurity resources and services, shared by the public sector in
accordance with the European Cloud Computing Strategy and in line with the National
Interoperability Framework.
Milestone #144 is the third step in the implementation of reform C7.R1. It was preceded by
milestone #142 on the establishment and operationalisation of the taskforce to implement and
monitor Digital Transformation reforms and investments, and milestone #143 on the analysis for
the options for the government cloud architecture (see relevant preliminary assessment fiches). It
has been followed by milestone #145 on the entry into force of the interoperability law (see
relevant preliminary assessment fiche).
Evidence provided:
In line with the verification mechanism set out in the Operational Arrangements, the following
evidence was provided:
i) cover note duly justifying how the milestone was satisfactorily fulfilled.
ii) Government Emergency Ordinance (GEO) No. 89/2022, regarding the establishment,
administration and development of cloud IT infrastructures and services used by public
authorities and institutions, published in the Official Journal, Part I, No. 638 of 28 June 2022,
and entered into force on the same day, in accordance with Article 12(3) of Law 24/2000 on
the rules of legislative technique for the drafting of legislative acts.
17
Analysis:
The justification and substantiating evidence provided by the Romanian authorities cover all
constitutive elements of the milestone.
Government Emergency Ordinance No. 89/2022 for the governance of cloud services for the
government area was published in the Official Journal No. 638 on 28 June 2022 and came into effect
the same day.
The new law shall establish a general framework for the development and management of a
cloud infrastructure, consisting of a set of information technology, communications and
cybersecurity resources and services, shared by the public sector in accordance with the European
Cloud Computing Strategy and aligned with the National Interoperability Framework.
Article 1(2) of GEO No. 89/2022 establishes the platform for the use of cloud services by central and
local public authorities and institutions, consisting of the private government cloud component and
certified public resources and services from other public or private clouds.
Article 1(5) provides that “The private government cloud is operationally managed by the Authority
for the Digitalisation of Romania and consists of a set of information technology, communications
and cybersecurity resources owned by the Romanian state, interconnected at service level with
public clouds and/or private clouds”.
Article 1(9) mentions that resources and services are shared by public authorities, according to
European best practices, and the Commission’s cloud strategy. The supervisory function in
implementing interoperability belongs to the Ministry of Research, Innovation and Digitalisation, in
accordance with interoperability legislation, and is based on the information provided by the
Authority for the Digitalisation of Romania. The monitoring, controlling, and evaluating the
interoperability will be performed by the Authority for the Digitalisation of Romania and the main
tool offered for achieving interoperability is the National Interoperability Platform (NIP), whose sole
administrator is the Authority for the Digitalisation of Romania. Considering all these, the services
and resources shared by the public sector will be aligned with the National Interoperability
Framework.
Article 13 (3)b provides that the cloud computing infrastructures of the government private cloud
must be set up and implemented in such a way as to ensure interoperability of databases hosted by
the dedicated IT structure with other databases hosted by other dedicated IT infrastructures.
GEO No. 89/2022 penultimate recital states alignment with the Commission’s Cloud Computing
Strategy, published in May 2019, the European Cloud Computing Strategy, the European Strategy
for Data, the Joint Statement of the Member States of the European Union on the New Generation
of Cloud in Europe and the European Interoperability Framework.
Furthermore, the justification and substantiating evidence provided by the Romanian authorities
also cover the relevant constitutive elements of the description of the measure.
In line with the description of the measure, the objective of this reform is to modernise the public
administration by adopting advanced technologies and focusing on the citizens and businesses’
needs, while ensuring the prerequisites for data-driven policy development and increasing the
interoperability of existing digital technologies.
Article 1(1) of GEO No. 89/2022 states that the law deals with the establishment, administration
and development, at national level, of a hybrid cloud infrastructure, which translates in the
adoption of advanced technologies. Article 1(7) and 1(8) require the modernisation of the public
18
administration by adopting advanced technologies, notably the migration of e-public services to the
central government cloud. The Law regarding the governance of the Government Cloud platform
was put into public consultation in March 2022 by the competent institutions involved, to ensure its
focus on the needs of the citizens and of the businesses.
Article 3 (2) and 3(3) ensure the creation of the framework for developing data-driven policy
development and increasing interoperability with the already existing digital technologies.
In line with the description of the measure, the reform shall also support the development of an
integrated architecture of public digital services.
Article 1(1) of GEO No. 89/2022 states that the law will support the development of an integrated
architecture of the digital public services, in the form of a hybrid cloud infrastructure, the
Government Cloud Platform, referred to as the Platform.
In line with the description of the measure, the entry into force of the Government Cloud Act is
expected to set out the responsibilities and tasks regarding the design, implementation,
development and management of the cloud infrastructure, technologies and services.
Articles 4(1), 4(3), 4(7), and 6(4) of GEO No. 89/2022 set out the responsibilities and tasks regarding
the design, implementation, development and management of the cloud infrastructure,
technologies and services.
Notably, Article 4(3) states that the Authority for the Digitalisation of Romania ensures the
implementation, technical and operational management, maintenance, as well as the future
development of the Software as a Service (SaaS) services pertaining to the private governmental
cloud.
Article 5(2) establishes that the Special Telecommunications Service ensures the implementation,
technical and operational management, cyber security, maintenance as well as the further
development of the services pertaining to the private governmental cloud at Infrastructure as a
Service (IaaS) and Platform as a Service (PaaS) levels.
In line with the description of the measure, cybersecurity shall be provided for the external and
internal protection of the cloud, applying the most advanced and economically efficient cyber-
security available solutions.
As for cybersecurity of internal providers, Article 5(5) of GEO No. 89/2022 provides that the Special
Telecommunications Service ensures the cybersecurity of its own services and information systems
in the Government Private Cloud by preventing and thwarting cyberattacks.
As for cybersecurity of external providers, Article 6(1) provides that the Special Telecommunications
Service ensures the cybersecurity of the Government Private Cloud by knowing, preventing and
countering cyber-attacks, threats, risks and vulnerabilities, including complex Advanced Persistent
Threats, directed against the Government Private Cloud services, which applies the most advanced
and economically efficient cybersecurity available solutions by rules of public institution.
Commission Preliminary Assessment: Satisfactorily fulfilled
Related Measure: Development of a unitary framework for defining the
Number: 145
architecture of a government cloud system
Name of the Milestone: Entry into force of the interoperability law
Qualitative Indicator: Provision in the law indicating the entry into force of Time: Q2 2022
19
the interoperability law
Context:
Milestone #145 is part of reform C7.R1 for the development of a unitary framework for defining the
architecture of a government cloud system. The reform’s overarching objective is to modernise the
public administration by adopting advanced technologies and focusing on the citizens and
businesses’ needs, while ensuring the prerequisites for data-driven policy development and
increasing the interoperability of existing digital technologies.
Milestone #145 requires the entry into force of the information systems interoperability law
detailing the uniform set of standards and rules that public entities shall apply for the development
of applications in a secure and sustainable environment, while aligning with the European
Interoperability Framework.
Milestone #145 is the fourth and last step in the implementation of reform C7.R1. It was preceded
by milestone #142 on the establishment and operationalisation of the taskforce to implement and
monitor Digital Transformation reforms and investments, milestone #143 on the completion of the
analysis for the options for the government cloud architecture (see relevant preliminary assessment
fiche), and milestone #144 on the entry into force of the law for the governance of cloud services
for the government area (see relevant preliminary assessment fiche).
Evidence provided:
In line with the verification mechanism set out in the Operational Arrangements, the following
evidence was provided:
i) cover note duly justifying how the milestone (including all the constitutive elements) was
satisfactorily fulfilled.
ii) Law No. 242/2022 on the exchange of data between IT systems and the creation of the
National Interoperability Platform, published in the national Official Journal No. 752 on 20
July 2022 (hereinafter referred to as the “interoperability law”) and entered into force on
23 July 2022, in accordance with Article 12(1) of Law 24/2000 on the rules of legislative
technique for the drafting of legislative acts.
Analysis:
The justification and substantiating evidence provided by the Romanian authorities covers all
constitutive elements of the milestone.
Law No. 242/2022 on the exchange of data between IT systems and the creation of the National
Interoperability Platform was published in the Official Journal No. 752 on 20 July 2022 and came
into effect the same day, in accordance with Article 12(3) of Law 24/2000 on the rules of legislative
technique for the drafting of legislative acts.
The new law shall be aligned with the provisions of the European Interoperability Framework.
Article 4 of the interoperability law provides that, in order to ensure interoperability, public
authorities and institutions must comply with a set of reference rules (“reference rules for achieving
interoperability”, the “NRRI”). Article 14 of the interoperability law requires that the NRRI are
drafted to ensure that all the standards required by the interoperability law and the European
Interoperability Framework are met when implementing the NRRI. Additionally, when using the
NRRIs, public authorities and institutions are under the obligation to comply with the 12 principles
provided in Article 5 of the interoperability law. These principles are aligned with the 12 underlying
principles of the European Interoperability Framework. In consideration of the above requirements
20
established by the interoperability law, it is concluded that, which means that the entire law on
interoperability is aligned with the provisions of the European Interoperability Framework.
The new law shall put in place a framework/governance to support the selection of relevant
standards and rules for the development of applications and services by the public sector in a
secure and sustainable environment
Articles 4 and 5 of the interoperability law provide for the introduction of NRRI in order to ensure
interoperability between public authorities and institutions or private entities for the provision of
public services. The NRRI contain common elements consisting of standards, specifications,
vocabulary, concepts, principles and practices, binding for institutions and public authorities. In
accordance with Article 14 of the interoperability law, the Ministry of Research, Innovation and
Digitalization has the obligation to draw up the NRRI. Amongst the principles set by Article 5 of the
interoperability law, the principles of security and confidentiality ensure the NRRI are secure while
the principle of reuse guarantees that the NRRI are sustainable. This proves that the interoperability
law puts in place a framework/governance to support the selection of relevant standards and rules
for the development of applications and services by the public sector in a secure and sustainable
environment.
The new law shall operationalise the migration and integration into existing data structures of
data, while ensuring interoperability
Chapter IV of the interoperability law lays down the “public authorities and institutions responsible
for the establishment and implementation of the National Interoperability Platform and their
tasks”. By setting th
← Înapoi la începutul extrasului
Extrasul poate avea altă structură decât documentul original. Data preluării nu reprezintă perioada statistică sau data publicării de către instituție.
Identificarea exactă a documentului colectat
Amprenta SHA-256 permite identificarea versiunii preluate.
83f36ca08a0462dd3b2aa402f874f1f4c4f374087516a0e8d22a8c7af3f2d8d3