NIS2 Romania: Compliance, Authorities & Key Requirements
Romania transposed NIS2 through OUG 155/2024, approved with amendments by Law 124/2025 and amended again by Law 123/2026. Fines are set in lei with a statutory minimum on every band, registration runs from the DNSC’s own decision rather than from the law, and supervision is shared with sectoral authorities.
Introduction: NIS2 Directive & the Romanian context
Romania implemented NIS2 via Government Emergency Ordinance (OUG) 155/2024, effective early January 2025, subsequently approved and amended by Law 124/2025. The framework replaces Law 362/2018 and brings expanded scope, clearer governance duties, and stronger enforcement.
Two things make the Romanian regime behave differently from most transpositions, and neither is widely reported. The fines are set in lei with a statutory minimum on every band - the EUR 10 million and EUR 7 million ceilings that circulate are the top of one band out of five, and for most contraventions the range that actually applies is 1,000 to 300,000 lei. And your deadlines run from the DNSC’s own decision, not from the date the ordinance came into force, so two comparable companies can be months apart.
How Romania transposed NIS2
Romania transposed NIS2 through OUG 155/2024, published in Monitorul Oficial no. 1332 of 31 December 2024. Parliament approved it with substantial amendments through Law 124/2025 (Monitorul Oficial no. 638 of 7 July 2025, in force 10 July 2025), which rewrote the penalty scale among much else. The ordinance was amended again by Law 123/2026 (Monitorul Oficial no. 550 of 3 July 2026, in force 6 July 2026), which added an advisory committee to Article 36 - a comitet consultativ without legal personality, made up of the authorities listed in Articles 11, 12 and 14 to 17 of Law 58/2023, working to a statute drafted by DNSC and endorsed by its members.
Most published summaries of Romanian NIS2 stop at Law 124/2025. If your compliance file cites only the ordinance and the approving law, it is one amendment out of date.
Status
Transposed and in force. Consolidated text current to 6 July 2026 (Law 123/2026), the third version of the framework.
Legal instruments
OUG 155/2024 (framework) + Law 124/2025 (approval and amendments) + Law 123/2026 (advisory committee), plus DNSC Orders 1/2025 and 2/2025.
Operational orders
On 20 Aug 2025 the DNSC issued Order 1/2025 (registration & notification rules) and Order 2/2025 (incident disruption thresholds & risk assessment methodology).
| Category | Notes |
|---|---|
| Essential sectors | Energy, transport, banking & FMIs, health, drinking & wastewater, digital infrastructure, public admin, etc. |
| Important sectors | Postal & courier, waste, food, manufacturing/chemicals, digital providers, research, etc. |
| Size criteria | General NIS2 baseline: medium-size and above (≥50 employees or ≥€10m). Some providers are in scope regardless of size. |
| Recent expansion | Law 124/2025 adds categories (e.g., certain pharma distributors/resellers via NACE codes) broadening Annex I/II coverage. |
Who is in scope
Romania applies the two-tier model (Essential / Important) with management accountability and detailed reporting mechanics.
Two or more sectors
Article 37(6): where an entity operates in two or more of the Annex 1 or Annex 2 sectors, it must apply the measures of the highest applicable level. You do not get to pick the lighter regime.
Registration & tools
DNSC provides NIS2@RO tools for scoping and notification, plus an onboarding & cooperation platform (Platforma NIS2@RO).
Your filings are not public information
Article 3(3) and (4), added by Law 124/2025: DNSC must protect entities’ security and commercial interests and the confidentiality of what they supply, and that information falls outside Law 544/2001 on free access to public information. A useful answer to the question boards actually ask about incident reports.
Registration & the DNSC decision
Registration is rolling, and the clock that matters afterwards is not the ordinance’s but your own decision letter. Article 18(2): notify DNSC within 30 days of the ordinance entering into force, or within 30 days of the date on which it becomes applicable to you. Growing into scope in 2026 starts your own 30-day clock.
What you notify
Article 18(3): identification and contact details, the relevant Annex sector and subsector, the member states where you provide services, your public IP address ranges, and enough information to show you meet the Article 5 or Article 6 tests.
Then DNSC decides - and the wait differs
Article 18(4)-(5): DNSC issues the decision identifying you and entering you in the register within 60 days of your notification if you are an essential entity, and within 150 days if you are an important one.
Why that matters
Because the obligations that follow are timed from communication of that decision, not from the law. An important entity can wait five months to learn it is one, and only then does its own clock start.
Management duties & the security officer
Article 14 puts three separate duties on the management body, and Law 124/2025 tightened all of them.
- Accredited training, not just training. Article 14(2): members of the management bodies of essential and important entities must take accredited professional training courses (cursuri de formare profesională acreditate) sufficient to identify risks and assess cybersecurity risk-management practices and their impact on the entity’s services. Entities must also train all staff regularly. Most member states require management to be trained and leave the content open; Romania requires the course to be accredited.
- Permanent contact points and resources. Article 14(3): management establishes permanent means of contact and allocates the resources needed to implement the risk-management measures.
- A named officer, on a 30-day clock. Within 30 days of communication of the DNSC director’s identification and registration decision, management must designate the responsabil cu securitatea rețelelor și sistemelor informatice - the person who implements and oversees the risk-management measures at entity level.
Incident reporting: 24h / 72h / one month
Article 15(7). Both of the first two clocks run from the moment you become aware of the significant incident, and reports go to the national CSIRT at DNSC.
Trust services report in 24 hours
Article 15(8): a trust service provider reports significant incidents affecting its trust services within 24 hours of becoming aware, not 72.
DNSC owes you a reply
Article 15(9): the national CSIRT must respond within 24 hours of the early warning where possible, with initial feedback and, on request, operational guidance on mitigation. Article 15(10) allows further technical support on request.
What counts as significant
Article 15(6), as amended by Law 124/2025: severe operational disruption of services or financial loss to the entity, or considerable material or non-material harm to others. Either limb is enough.
The annual self-assessment
Romania imposes a recurring, self-funded duty that most transpositions do not, and failing to do it is itself sanctionable.
Essential and important entities must carry out and submit to DNSC - and, where one exists, to the sectoral competent authority - an annual self-assessment of the maturity of their cybersecurity risk-management measures, in the form set by the implementing order, and endorsed by the entity’s management.
Essential entities then have 30 days. Within 30 days of completing the self-assessment, they must draw up and submit a plan of measures to remedy the deficiencies identified, again endorsed by management. Failing to notify DNSC that the plan has been implemented, or to supply the supporting evidence within the deadline undertaken, is a listed contravention in its own right.
Timeline & key dates
Sector-specific notes
- Health & pharma: Law 124/2025 expands the scope to include certain distributors and resellers, identifies through specific NACE codes.
- Finance/energy/digital infrastructure: NIS2 applies alongside parallel EU regimes (e.g., DORA) and relevant sector-specific supervisory guidance.
- Public administration: generally covered, with exclusions for entities operating in defence, law enforcement and national security.
Penalties: the five fine bands
The EUR 10 million and EUR 7 million figures that circulate are the ceiling of one band out of five. Article 60(2) sets a scale in lei, and every band has a statutory minimum. For most of the listed contraventions the range that actually applies to a Romanian entity is 1,000 to 300,000 lei.
| Band | Entity | Range |
|---|---|---|
| a) | Important | From 5,000 lei to at most EUR 7,000,000 in lei equivalent or 1.4% of worldwide annual turnover, whichever is higher |
| b) | Essential | From 10,000 lei to at most EUR 10,000,000 in lei equivalent or 2% of worldwide annual turnover, whichever is higher |
| c) | Important | 1,000 to 300,000 lei |
| d) | Essential | 1,500 to 500,000 lei |
| e) | Any entity | 1,000 to 100,000 lei |
Which band applies depends on which lettered contravention in Article 60(1) you have committed: bands a) and b) cover the risk-management and reporting failures, bands c) and d) a second group of obligations, and band e) a third. Article 60(3): the worldwide turnover used is that of the last financial year.
Serious breaches & repeat offences
Law 124/2025 added Article 60(2¹), a separate band for încălcări grave - serious breaches - carrying a fine of 3,000 to 600,000 lei.
Article 50(2) defines what counts as serious:
- repeated breaches;
- obstructing audits, monitoring ordered by DNSC following its findings, or control activity carried out by DNSC or the sectoral competent authority;
- providing false or misleading information.
Who imposes it depends on the letter. Article 61(2): contraventions under Article 60(1) a)-n), ee), ff) and jj)-qq) may be found by DNSC or by the control staff of a sectoral competent authority, and where a sectoral authority acts the sanction is applied by decision of its leadership. Contraventions under Article 60(1) o)-dd), gg)-ii) and the serious-breach band are found by DNSC alone, and the sanction is applied by decision of the DNSC director.
How Romania differs
If you are running NIS2 across several member states, these are the points where Romania will not behave like your other jurisdictions.
- Fines are in lei, with a floor on every band. The euro ceilings apply to two bands out of five and are converted to lei equivalent.
- Your clock starts with a decision, not a statute. Registration is 30 days from applicability; everything after that runs from communication of the DNSC decision - which itself takes up to 60 days for essential entities and 150 days for important ones.
- Repeat offending adds half, not double.
- Management training must be accredited, not merely provided.
- A named security officer is mandatory, designated within 30 days of the DNSC decision.
- An annual maturity self-assessment, with a 30-day remediation plan for essential entities - a recurring duty with its own sanctions.
- Sectoral authorities are provided for but not yet named, and they may create their own CSIRTs or buy CSIRT services from DNSC-authorised providers.
- What you file is exempt from freedom-of-information access under Article 3(4).
- The ordinance has been amended twice, most recently on 6 July 2026.
Romanian terms you will meet
DNSC publishes and corresponds in Romanian. These are the terms that appear in the orders, the register and the platform.
| Romanian | English |
|---|---|
| Directoratul Național de Securitate Cibernetică (DNSC) | the national competent authority, SPOC and CSIRT |
| entitate esențială / entitate importantă | essential entity / important entity |
| registrul entităților | the register of identified entities (Article 18) |
| Platforma NIS2@RO | the DNSC notification and cooperation platform |
| responsabil cu securitatea rețelelor și sistemelor informatice | the network and information systems security officer |
| incident semnificativ | significant incident |
| avertizare timpurie | early warning, due in 24 hours |
| autoritate competentă sectorială | sectoral competent authority |
| încălcări grave | serious breaches (Article 50(2)) |
| contravenție / amendă | administrative offence / fine |
| se majoră cu jumătate | increased by half - the repeat-offence rule |
| comitet consultativ | the DNSC advisory committee added by Law 123/2026 |
How to prepare
- Establish your date, not the ordinance’s. If you came into scope after January 2025, your notification was due 30 days from that moment. The 2 January 2025 date in most guidance is only the first cohort’s.
- Notify DNSC through NIS2@RO in the form set by Order 1/2025, and have your public IP ranges ready - it is the item organisations most often cannot produce quickly.
- Diarise the decision, then count from it. Expect it within 60 days if you are essential, up to 150 if you are important. Your security-officer deadline and the rest run from its communication.
- Designate the responsabil cu securitatea within 30 days of that decision, and record the designation.
- Book accredited training for the management body - Article 14(2) requires the course to be accredited, so an internal briefing will not discharge it.
- Put the annual self-assessment in the compliance calendar, with the 30-day remediation plan behind it if you are an essential entity.
- Build the reporting chain to run from awareness: 24 hours, 72 hours, then one month from handling the incident. Decide in advance who declares an incident significant.
- Check whether a sectoral authority has been designated for you by Government decision - if one has, it can supervise, control and sanction alongside DNSC.
- Read the fine scale by band, not by headline. For most contraventions your exposure is the 1,000-300,000 lei range, and repeat breaches move you into the serious-breach band increased by half.
