NIS2 in Romania: who it covers and what they must do
by Claudiu Hulea · IT Management Consultant
NIS2 is the European directive that raises the cybersecurity bar for thousands of companies. In Romania it has become law, with an authority, deadlines and concrete penalties. Below are the facts — short and structured. This guide is informational, not legal advice: for your specific situation, check with DNSC and a consultant.
What is NIS2 and how is it transposed in Romania?
NIS2 (EU Directive 2022/2555) is the European cybersecurity framework for operators of important and essential services. In Romania it was transposed through Emergency Ordinance (OUG) 155/2024, approved and amended by Law 124/2025. The competent authority is DNSC (the National Cybersecurity Directorate), which detailed the procedures through Orders no. 1 and 2/2025.
Who it covers: essential vs. important entities
The law splits covered organisations into two categories, by sector and size:
- Essential entities — critical sectors (energy, transport, health, water, digital infrastructure, public administration, etc.), under stricter supervision.
- Important entities — other relevant sectors (postal services, waste management, manufacturing, digital providers, etc.).
Many companies that didn’t consider themselves “critical infrastructure” are now covered — directly, or as suppliers in someone else’s chain. If you’re not sure which category you fall into, that’s the first question to settle.
What your obligations are
Under the legislation, the main obligations include:
- Cybersecurity risk-management measures (technical and organisational, proportionate to the risk).
- Appointing a person responsible for cybersecurity / NIS2.
- Reporting significant incidents to DNSC, within the set deadlines.
- Ongoing training of staff and accountability of management.
Deadlines and registration
- Essential and important entities were required to register with DNSC (the deadline stated in the law: 19 September 2025).
- After notification/registration, DNSC issues the identification decision and registry entry — indicatively 60 days for essential entities and 150 days for important ones.
The exact deadlines that apply to your situation are confirmed with DNSC — the calendar was detailed gradually through orders.
What penalties non-compliance carries
Under Law 124/2025, the fines are significant:
- Important entities — up to €7,000,000 or 1.4% of worldwide annual turnover (whichever is higher).
- Essential entities — up to €10,000,000 or 2% of worldwide annual turnover.
Beyond the fine, a badly handled incident means downtime, and loss of data and trust.
What to do now
- Determine whether you’re covered and in which category (essential / important).
- Register with DNSC if applicable and appoint a responsible person.
- Assess your security posture against the requirements — here an IT security audit shows you exactly where you stand and what to remediate.
- Implement the prioritised measures and prepare your incident-reporting process.
Sources
Frequently asked questions
Is my small company covered by NIS2?
It depends on sector and size — and on the fact that you can be covered as a supplier in another entity's chain. Settle your classification first.
Who is the NIS2 authority in Romania?
DNSC (the National Cybersecurity Directorate), which detailed the procedures through Orders no. 1 and 2/2025.
What is the risk if I ignore NIS2?
Fines up to €7 million or 1.4% of worldwide annual turnover (important entities) and up to €10 million or 2% (essential entities), plus the operational risk of a badly handled incident.
Where do I start, concretely, with NIS2 compliance?
By settling your classification (essential or important) and registering with DNSC, then assessing your current state against the requirements (an audit) and a prioritised remediation plan.