NIS2 Country Guide

NIS2 Romania: Compliance, Authorities & Key Requirements

Romania transposed NIS2 through OUG 155/2024, approved with amendments by Law 124/2025 and amended again by Law 123/2026. Fines are set in lei with a statutory minimum on every band, registration runs from the DNSC’s own decision rather than from the law, and supervision is shared with sectoral authorities.

In force: OUG 155/2024 Amended: Law 123/2026, 6 Jul Fines from 1,000 lei Register: 30 days, rolling Last updated: 12 August 2026

Introduction: NIS2 Directive & the Romanian context

Romania implemented NIS2 via Government Emergency Ordinance (OUG) 155/2024, effective early January 2025, subsequently approved and amended by Law 124/2025. The framework replaces Law 362/2018 and brings expanded scope, clearer governance duties, and stronger enforcement.

Two things make the Romanian regime behave differently from most transpositions, and neither is widely reported. The fines are set in lei with a statutory minimum on every band - the EUR 10 million and EUR 7 million ceilings that circulate are the top of one band out of five, and for most contraventions the range that actually applies is 1,000 to 300,000 lei. And your deadlines run from the DNSC’s own decision, not from the date the ordinance came into force, so two comparable companies can be months apart.

Quick link: Read our overview “What is NIS2?” and “NIS vs NIS2” for background before diving into Romania’s specifics.

How Romania transposed NIS2

Romania transposed NIS2 through OUG 155/2024, published in Monitorul Oficial no. 1332 of 31 December 2024. Parliament approved it with substantial amendments through Law 124/2025 (Monitorul Oficial no. 638 of 7 July 2025, in force 10 July 2025), which rewrote the penalty scale among much else. The ordinance was amended again by Law 123/2026 (Monitorul Oficial no. 550 of 3 July 2026, in force 6 July 2026), which added an advisory committee to Article 36 - a comitet consultativ without legal personality, made up of the authorities listed in Articles 11, 12 and 14 to 17 of Law 58/2023, working to a statute drafted by DNSC and endorsed by its members.

Most published summaries of Romanian NIS2 stop at Law 124/2025. If your compliance file cites only the ordinance and the approving law, it is one amendment out of date.

Status

Transposed and in force. Consolidated text current to 6 July 2026 (Law 123/2026), the third version of the framework.

Legal instruments

OUG 155/2024 (framework) + Law 124/2025 (approval and amendments) + Law 123/2026 (advisory committee), plus DNSC Orders 1/2025 and 2/2025.

Operational orders

On 20 Aug 2025 the DNSC issued Order 1/2025 (registration & notification rules) and Order 2/2025 (incident disruption thresholds & risk assessment methodology).

CategoryNotes
Essential sectorsEnergy, transport, banking & FMIs, health, drinking & wastewater, digital infrastructure, public admin, etc.
Important sectorsPostal & courier, waste, food, manufacturing/chemicals, digital providers, research, etc.
Size criteriaGeneral NIS2 baseline: medium-size and above (≥50 employees or ≥€10m). Some providers are in scope regardless of size.
Recent expansionLaw 124/2025 adds categories (e.g., certain pharma distributors/resellers via NACE codes) broadening Annex I/II coverage.

Who is in scope

Romania applies the two-tier model (Essential / Important) with management accountability and detailed reporting mechanics.

Two or more sectors

Article 37(6): where an entity operates in two or more of the Annex 1 or Annex 2 sectors, it must apply the measures of the highest applicable level. You do not get to pick the lighter regime.

Registration & tools

DNSC provides NIS2@RO tools for scoping and notification, plus an onboarding & cooperation platform (Platforma NIS2@RO).

Your filings are not public information

Article 3(3) and (4), added by Law 124/2025: DNSC must protect entities’ security and commercial interests and the confidentiality of what they supply, and that information falls outside Law 544/2001 on free access to public information. A useful answer to the question boards actually ask about incident reports.

Registration & the DNSC decision

Registration is rolling, and the clock that matters afterwards is not the ordinance’s but your own decision letter. Article 18(2): notify DNSC within 30 days of the ordinance entering into force, or within 30 days of the date on which it becomes applicable to you. Growing into scope in 2026 starts your own 30-day clock.

What you notify

Article 18(3): identification and contact details, the relevant Annex sector and subsector, the member states where you provide services, your public IP address ranges, and enough information to show you meet the Article 5 or Article 6 tests.

Then DNSC decides - and the wait differs

Article 18(4)-(5): DNSC issues the decision identifying you and entering you in the register within 60 days of your notification if you are an essential entity, and within 150 days if you are an important one.

Why that matters

Because the obligations that follow are timed from communication of that decision, not from the law. An important entity can wait five months to learn it is one, and only then does its own clock start.

The register and the tooling. DNSC keeps the register of identified essential and important entities (Article 18(1)), and publishes the NIS2@RO self-assessment and notification helper together with the Platforma NIS2@RO. Order 1/2025 of 20 August 2025 standardises the notification content and channels.

Management duties & the security officer

Article 14 puts three separate duties on the management body, and Law 124/2025 tightened all of them.

  • Accredited training, not just training. Article 14(2): members of the management bodies of essential and important entities must take accredited professional training courses (cursuri de formare profesională acreditate) sufficient to identify risks and assess cybersecurity risk-management practices and their impact on the entity’s services. Entities must also train all staff regularly. Most member states require management to be trained and leave the content open; Romania requires the course to be accredited.
  • Permanent contact points and resources. Article 14(3): management establishes permanent means of contact and allocates the resources needed to implement the risk-management measures.
  • A named officer, on a 30-day clock. Within 30 days of communication of the DNSC director’s identification and registration decision, management must designate the responsabil cu securitatea rețelelor și sistemelor informatice - the person who implements and oversees the risk-management measures at entity level.
The 30 days run from the decision, not from the law. This is the same structure as the registration timeline, and it is the single most common misunderstanding in Romanian NIS2 guidance: nothing in this regime is timed from 2 January 2025 except the first notification window.

DNSC & the sectoral authorities

Supervision in Romania is not centralised. DNSC is the national competent authority, the single point of contact and the national CSIRT - but the ordinance also provides for autorități competente sectorial with their own powers to supervise, control and sanction.

RoleWhoWhat the ordinance says
National competent authority and single point of contactDirectoratul Național de Securitate Cibernetică (DNSC)Keeps the register, issues the implementing orders, supervises and sanctions.
National CSIRTDNSCReceives the reports and owes a reply within 24 hours of an early warning.
Sectoral competent authoritiesTo be designated by the line ministries, by Government decision (Article 37(5))Empowered to supervise, control and sanction in their sector, alongside DNSC.
Sectoral CSIRTsOptional, set up by the sectoral authorities (Article 37(7))May also buy CSIRT services from providers authorised by DNSC.
Financial sectorBNR and ASF (Article 37(3))Exchange DORA incident information with DNSC in both directions.
We do not name the sectoral authorities, because the law does not. Article 37(5) leaves each designation to a Government decision taken by the relevant ministry. Published guidance that names specific Romanian sectoral regulators for NIS2 is running ahead of the legal position. What the ordinance does settle is what they may do once designated: Article 37(10) empowers them to supervise, control and sanction where EU regulations have not assigned those powers elsewhere; Article 37(11) has that control carried out together with DNSC control or specialist staff where appropriate; and Article 37(12) lets them act at the reasoned request of CNCPIC for entities identified as critical under the critical-entity resilience rules.

Incident reporting: 24h / 72h / one month

Article 15(7). Both of the first two clocks run from the moment you become aware of the significant incident, and reports go to the national CSIRT at DNSC.

24 hoursavertizare timpurie, an early warning, indicating where applicable whether the incident is suspected to be caused by unlawful or malicious acts, or could have cross-border impact.
72 hours — the incident report, updating the early warning with an initial assessment of severity and impact and, where available, indicators of compromise.
Intermediate report — on status, where required.
Final report — covering a detailed description and severity, the threat type or root cause, mitigation applied and ongoing, and any cross-border impact.
Still ongoing? Article 15(7)(e): submit a progress report at that point, and the final report within one month of the incident being handled.

Trust services report in 24 hours

Article 15(8): a trust service provider reports significant incidents affecting its trust services within 24 hours of becoming aware, not 72.

DNSC owes you a reply

Article 15(9): the national CSIRT must respond within 24 hours of the early warning where possible, with initial feedback and, on request, operational guidance on mitigation. Article 15(10) allows further technical support on request.

What counts as significant

Article 15(6), as amended by Law 124/2025: severe operational disruption of services or financial loss to the entity, or considerable material or non-material harm to others. Either limb is enough.

The annual self-assessment

Romania imposes a recurring, self-funded duty that most transpositions do not, and failing to do it is itself sanctionable.

Essential and important entities must carry out and submit to DNSC - and, where one exists, to the sectoral competent authority - an annual self-assessment of the maturity of their cybersecurity risk-management measures, in the form set by the implementing order, and endorsed by the entity’s management.

Essential entities then have 30 days. Within 30 days of completing the self-assessment, they must draw up and submit a plan of measures to remedy the deficiencies identified, again endorsed by management. Failing to notify DNSC that the plan has been implemented, or to supply the supporting evidence within the deadline undertaken, is a listed contravention in its own right.

An entity can be secure and still be sanctioned for missing the cycle. Croatia runs a biennial audit at the entity’s own cost; Latvia a self-assessment report; Romania an annual self-assessment plus a dated remediation plan. Put it in the compliance calendar, not the project plan.

Timeline & key dates

27 Dec 2022 — NIS2 published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline for Member States.
2 Jan 2025 — OUG 155/2024 enters into force (national NIS2 framework).
10 Jul 2025 — Law 124/2025 approves OUG 155/2024 with amendments (scope clarified/expanded).
20 Aug 2025 — DNSC Order 1/2025 (registration and notification) and Order 2/2025 (disruption thresholds and risk methodology) enter into force.
6 Jul 2026Law 123/2026 (Monitorul Oficial no. 550 of 3 July 2026) completes Article 36, creating the DNSC comitet consultativ.
Rolling — there is no further national cut-off. Registration is due 30 days from the date the ordinance becomes applicable to you, and every later deadline runs from the DNSC decision that follows.

Sector-specific notes

  • Health & pharma: Law 124/2025 expands the scope to include certain distributors and resellers, identifies through specific NACE codes.
  • Finance/energy/digital infrastructure: NIS2 applies alongside parallel EU regimes (e.g., DORA) and relevant sector-specific supervisory guidance.
  • Public administration: generally covered, with exclusions for entities operating in defence, law enforcement and national security.

Penalties: the five fine bands

The EUR 10 million and EUR 7 million figures that circulate are the ceiling of one band out of five. Article 60(2) sets a scale in lei, and every band has a statutory minimum. For most of the listed contraventions the range that actually applies to a Romanian entity is 1,000 to 300,000 lei.

BandEntityRange
a)ImportantFrom 5,000 lei to at most EUR 7,000,000 in lei equivalent or 1.4% of worldwide annual turnover, whichever is higher
b)EssentialFrom 10,000 lei to at most EUR 10,000,000 in lei equivalent or 2% of worldwide annual turnover, whichever is higher
c)Important1,000 to 300,000 lei
d)Essential1,500 to 500,000 lei
e)Any entity1,000 to 100,000 lei

Which band applies depends on which lettered contravention in Article 60(1) you have committed: bands a) and b) cover the risk-management and reporting failures, bands c) and d) a second group of obligations, and band e) a third. Article 60(3): the worldwide turnover used is that of the last financial year.

Two features worth being precise about. First, Romania sets a statutory minimum on every band - so unlike a regime with ceilings only, there is a floor beneath which a fine cannot fall. Second, the top two bands run from a minimum in lei to a maximum expressed in euro, converted into lei equivalent. Quoting a flat "up to EUR 10 million" therefore misses both the floor and the currency mechanism.

Serious breaches & repeat offences

Law 124/2025 added Article 60(2¹), a separate band for încălcări grave - serious breaches - carrying a fine of 3,000 to 600,000 lei.

Article 50(2) defines what counts as serious:

  • repeated breaches;
  • obstructing audits, monitoring ordered by DNSC following its findings, or control activity carried out by DNSC or the sectoral competent authority;
  • providing false or misleading information.
Repeat offending increases the band by half, not double. Article 60(4): the amount is individualised using the Article 50(1) criteria, and in the case of repeated breaches under Article 50(2)(a) the limits in Article 60(2¹) are increased by half - se majoră cu jumătate - taking the band to 4,500 to 900,000 lei. It applies to this band, not across the whole scale.

Who imposes it depends on the letter. Article 61(2): contraventions under Article 60(1) a)-n), ee), ff) and jj)-qq) may be found by DNSC or by the control staff of a sectoral competent authority, and where a sectoral authority acts the sanction is applied by decision of its leadership. Contraventions under Article 60(1) o)-dd), gg)-ii) and the serious-breach band are found by DNSC alone, and the sanction is applied by decision of the DNSC director.

How Romania differs

If you are running NIS2 across several member states, these are the points where Romania will not behave like your other jurisdictions.

  • Fines are in lei, with a floor on every band. The euro ceilings apply to two bands out of five and are converted to lei equivalent.
  • Your clock starts with a decision, not a statute. Registration is 30 days from applicability; everything after that runs from communication of the DNSC decision - which itself takes up to 60 days for essential entities and 150 days for important ones.
  • Repeat offending adds half, not double.
  • Management training must be accredited, not merely provided.
  • A named security officer is mandatory, designated within 30 days of the DNSC decision.
  • An annual maturity self-assessment, with a 30-day remediation plan for essential entities - a recurring duty with its own sanctions.
  • Sectoral authorities are provided for but not yet named, and they may create their own CSIRTs or buy CSIRT services from DNSC-authorised providers.
  • What you file is exempt from freedom-of-information access under Article 3(4).
  • The ordinance has been amended twice, most recently on 6 July 2026.

Romanian terms you will meet

DNSC publishes and corresponds in Romanian. These are the terms that appear in the orders, the register and the platform.

RomanianEnglish
Directoratul Național de Securitate Cibernetică (DNSC)the national competent authority, SPOC and CSIRT
entitate esențială / entitate importantăessential entity / important entity
registrul entitățilorthe register of identified entities (Article 18)
Platforma NIS2@ROthe DNSC notification and cooperation platform
responsabil cu securitatea rețelelor și sistemelor informaticethe network and information systems security officer
incident semnificativsignificant incident
avertizare timpurieearly warning, due in 24 hours
autoritate competentă sectorialăsectoral competent authority
încălcări graveserious breaches (Article 50(2))
contravenție / amendăadministrative offence / fine
se majoră cu jumătateincreased by half - the repeat-offence rule
comitet consultativthe DNSC advisory committee added by Law 123/2026

How to prepare

  1. Establish your date, not the ordinance’s. If you came into scope after January 2025, your notification was due 30 days from that moment. The 2 January 2025 date in most guidance is only the first cohort’s.
  2. Notify DNSC through NIS2@RO in the form set by Order 1/2025, and have your public IP ranges ready - it is the item organisations most often cannot produce quickly.
  3. Diarise the decision, then count from it. Expect it within 60 days if you are essential, up to 150 if you are important. Your security-officer deadline and the rest run from its communication.
  4. Designate the responsabil cu securitatea within 30 days of that decision, and record the designation.
  5. Book accredited training for the management body - Article 14(2) requires the course to be accredited, so an internal briefing will not discharge it.
  6. Put the annual self-assessment in the compliance calendar, with the 30-day remediation plan behind it if you are an essential entity.
  7. Build the reporting chain to run from awareness: 24 hours, 72 hours, then one month from handling the incident. Decide in advance who declares an incident significant.
  8. Check whether a sectoral authority has been designated for you by Government decision - if one has, it can supervise, control and sanction alongside DNSC.
  9. Read the fine scale by band, not by headline. For most contraventions your exposure is the 1,000-300,000 lei range, and repeat breaches move you into the serious-breach band increased by half.

Official links & resources

OUG 155/2024, consolidated text on Portal Legislativ — the authoritative current version, including Law 124/2025 and Law 123/2026
Law 124/2025 — the approving law that rewrote the penalty scale (Monitorul Oficial no. 638 of 7 July 2025)
DNSC Orders 1/2025 and 2/2025 (Portal Legislativ) — registration and notification rules; disruption thresholds and risk methodology

FAQ: NIS2 in Romania

When did NIS2 enter into force in Romania?
Through OUG 155/2024, published in Monitorul Oficial no. 1332 of 31 December 2024. It was approved with amendments by Law 124/2025 (in force 10 July 2025) and amended again by Law 123/2026 (in force 6 July 2026).
What are the fines, really?
Article 60(2) sets five bands, each with a minimum in lei. The EUR 10 million / 2% and EUR 7 million / 1.4% ceilings apply to two of them and are expressed in lei equivalent, with floors of 10,000 and 5,000 lei. The other three bands are 1,000-300,000 lei (important), 1,500-500,000 lei (essential) and 1,000-100,000 lei. See the table.
What happens if we breach the rules more than once?
Repeated breaches are a serious breach under Article 50(2)(a), which carries 3,000-600,000 lei under Article 60(2¹) - and Article 60(4) increases those limits by half, to 4,500-900,000 lei. It is an increase by half, not a doubling, and it applies to that band only.
Have we missed the registration deadline?
Probably not. Article 18(2) gives 30 days from the ordinance becoming applicable to you, so an organisation that came into scope later has its own window. Registration is rolling; there is no single closed national deadline.
How do we register?
Notify DNSC in the form set by Order 1/2025, using the NIS2@RO tool and platform. You will need identification and contact details, your Annex sector and subsector, the member states you serve, and your public IP address ranges.
How long until DNSC confirms our status?
60 days from your notification for essential entities and 150 days for important entities (Article 18(4)-(5)). This matters because your later obligations are timed from communication of that decision, not from the ordinance.
Do we need to appoint anyone?
Yes. Within 30 days of the DNSC decision, management must designate the responsabil cu securitatea rețelelor și sistemelor informatice, who implements and oversees the risk-management measures (Article 14(3)).
Who supervises us - DNSC or a sectoral regulator?
Possibly both. DNSC is the national authority, but Article 37 provides for sectoral competent authorities with their own powers to supervise, control and sanction. They are designated by the line ministries through Government decisions, so check whether one has been designated for your sector.
Is there a recurring obligation we should diarise?
Yes - an annual self-assessment of the maturity of your risk-management measures, submitted to DNSC and endorsed by management. Essential entities must then file a remediation plan within 30 days of completing it.
Will what we report to DNSC become public?
No. Article 3(3) and (4) require DNSC to protect entities’ security and commercial interests and the confidentiality of what they supply, and place that information outside Law 544/2001 on free access to public information.
Is a specific certification required?
No. Alignment with ISO/IEC 27001:2023, NIST CSF 2.0 and sector standards such as IEC 62443 is good practice, but no certification is mandated by name.
Information provided for general guidance; consult official Romanian sources (DNSC / Portal Legislativ) for updates. Last updated: 12 August 2026