1. Why NIS2 matters for foreign-owned operations in Romania
Romania transposed NIS2 through OUG 155/2024, in force since December 2024. The transposition is largely faithful to the Directive but introduces a single national authority — DNSC (Directoratul Național de Securitate Cibernetică) — and a mandatory national registration platform, ENIRE@RO v2. For multinational groups this creates three frictions that ISO 27001 or a global SOC alone do not solve:
- Local legal personality matters. A Romanian SRL or SA subsidiary is a separate regulated entity. Group certifications travel, but registrations, contact points, and sanctions do not.
- Language and timing. Incident notifications to DNSC are filed in Romanian, within hours of detection. Translating an English playbook at 3 AM is not a strategy.
- Personal accountability. Article 20 of the Directive — preserved in OUG 155/2024 — places the management body on the hook. For local directors in Romania, that is a personal exposure your foreign HQ cannot underwrite.
2. Jurisdiction: where exactly does your group register?
NIS2 uses two different jurisdiction rules depending on the sector.
2.1 General rule — main establishment
Most essential and important entities (energy, transport, banking, health, water, manufacturing, postal, waste, food, chemicals, etc.) are regulated in the Member State of their main establishment. The main establishment is the Member State where cybersecurity risk-management decisions are predominantly taken. If those decisions cannot be located, it falls back to where cybersecurity operations are carried out or, failing that, where the entity has the largest workforce.
What this means for groups: a Romanian subsidiary of a German manufacturer typically registers in Romania for itself, while the German parent registers in Germany. There is no group-wide single registration; each EU legal entity that meets the thresholds registers locally.
2.2 Special rule — digital infrastructure & DSPs
DNS providers, TLD registries, cloud providers, data center providers, CDNs, MSPs, MSSPs, online marketplaces, online search engines and social networking platforms register either:
- in the Member State of their main establishment (within the EU), or
- where their designated representative is established, if the provider itself is outside the EU but offers services in the EU.
A US-headquartered MSP without an EU office that serves Romanian clients must designate an EU representative. If that representative sits in Romania, DNSC becomes the lead regulator.
2.3 Decision matrix
| Your situation | Where to register | Local rep needed? |
|---|---|---|
| Romanian SRL/SA subsidiary (any covered sector) | Romania (DNSC / ENIRE@RO) | No — the SRL/SA is the EU establishment |
| Branch (sucursală) of EU parent, no separate legal personality | Member State of parent's main establishment | No |
| Non-EU cloud/MSP/marketplace serving Romanian users, no EU office | Where the designated representative sits | Yes — Article 26 representative |
| Group with Romanian-based cybersecurity decisioning | Romania, even if HQ is elsewhere | No |
3. Scope test: is the Romanian entity actually in?
An entity is in scope when it satisfies both of the following:
- It operates in one of the 18 sectors listed in Annex I (high criticality) or Annex II (other critical) of NIS2 — see our full sector list.
- It is a medium enterprise (50+ headcount or >10M EUR turnover) or large (250+ headcount or >50M EUR turnover) under EU Recommendation 2003/361/EC.
Medium = important; large in Annex I = essential; large in Annex II = important. There are size-independent exceptions: DNS, TLD, qualified trust service providers, public electronic communications, and entities providing sole services to a Member State are always in scope, regardless of size.
Group thresholds: under OUG 155/2024 and Romanian SME methodology, autonomy is assessed on consolidated headcount and turnover when there is a linked enterprise relationship. A 40-person Romanian subsidiary of a 5 000-person multinational is treated as a large enterprise — not a micro/small entity. Run the free classification tool to remove ambiguity.
4. ENIRE@RO registration: what foreign owners need to know
ENIRE@RO is DNSC's national registry for essential and important entities. Version 2 (active since 2025) requires:
- Legal identification of the Romanian entity (CUI, ONRC registration, legal representative).
- Primary and secondary CAEN codes mapped strictly to the 4-digit list — this drives sector classification (see our deadline timeline).
- NIS2 contact point — a person reachable in Romanian during business hours.
- Network and information systems scope — services delivered, geographical reach, dependencies.
- Designated representative data for non-EU DSPs.
Deadlines
- Essential entities — 60 days from becoming applicable.
- Important entities — 150 days from becoming applicable.
- Updates within 14 days for material changes (sector, services, contact, representative).
For freshly acquired Romanian subsidiaries, "becoming applicable" is normally the closing date of the transaction — not the parent's original registration date.
5. Article 21 measures: what your local entity must actually do
OUG 155/2024 mirrors the ten technical and organisational measures of NIS2 Article 21. Foreign-owned entities almost always have a head start because group policies cover most of the ground, but a Romanian regulator expects to see local applicability and evidence:
- Risk analysis & ISMS — mapped to the Romanian entity's services, not just the global ISMS scope statement.
- Incident handling — runbook in Romanian, on-call rotation, DNSC notification template ready.
- Business continuity, backup, crisis management — RTO/RPO per critical service; backups tested locally.
- Supply chain security — vendor register including intra-group services; contractual NIS2 clauses with parent and sister companies.
- Security in acquisition, development, maintenance — secure SDLC and vulnerability handling, including for products imported from HQ.
- Policies for assessing effectiveness — local KPIs and periodic review.
- Cyber hygiene & training — annual training documented for Romanian staff, in Romanian.
- Cryptography — key management policy applicable to local data flows.
- HR security, access control, asset management — joiner/mover/leaver tied to the Romanian payroll.
- MFA, secured communications, secure emergency comms — applied to all admin and remote access.
The Romanian-specific addition: a documented management body decision approving the Article 21 framework and a yearly review minute. Without this artefact, DNSC inspections start at a deficit.
6. Incident reporting clock
The clock is identical to the Directive but enforcement is Romanian:
- 6 hours — pre-notification for cross-border or systemic impact.
- 24 hours — early warning to DNSC: nature of incident, suspected malicious cause, cross-border impact.
- 72 hours — incident notification: initial assessment, severity, IoCs.
- 1 month — final report: root cause, mitigations, lessons learned.
- Progress reports on request for incidents still ongoing.
Notifications are filed in Romanian through ENIRE@RO. Practically, foreign-owned groups should pre-translate notification templates and pre-assign the Romanian-speaking person who has authority to file without HQ sign-off in the first 24 hours.
7. Sanctions and personal liability
| Entity type | Maximum administrative fine | Alternative cap |
|---|---|---|
| Essential | 10 000 000 EUR | 2% of worldwide annual turnover (whichever is higher) |
| Important | 7 000 000 EUR | 1.4% of worldwide annual turnover (whichever is higher) |
"Worldwide annual turnover" in the Directive is interpreted at the level of the undertaking — i.e., the consolidated group. A 5 M EUR Romanian subsidiary of a 4 bn EUR parent therefore faces a fine ceiling computed on the 4 bn, not the 5 M.
For repeated infringements DNSC may, subject to judicial review, suspend a certification or authorisation and prohibit any natural person discharging managerial responsibilities from doing so within the entity. Group HQ cannot indemnify away an Article 20 obligation that EU law assigns personally.
8. 90-day roadmap for a foreign-owned Romanian entity
Days 1–15 — Establish the local programme
- Confirm scope and tier with the classification tool.
- Appoint a NIS2 contact person and a deputy (Romanian-speaking).
- Map global policies to OUG 155/2024 Article 21 measures; flag gaps.
- Open the ENIRE@RO account and lock the registration deadline in the calendar (60 or 150 days).
Days 16–45 — Register and localise
- Submit ENIRE@RO registration with correct CAEN codes.
- Translate and localise the incident response runbook; pre-fill the DNSC notification template.
- Document management body approval of the Article 21 framework.
- Sign supply chain NIS2 addenda with intra-group providers.
Days 46–75 — Build evidence
- Run a tabletop incident exercise with a simulated 24h/72h DNSC clock.
- Complete annual cybersecurity training for Romanian staff (Romanian-language deck).
- Inventory critical assets and dependencies; tag intra-group services in the supplier register.
- Configure MFA and privileged access reviews on local admin paths.
Days 76–90 — Assure and report
- Independent gap assessment vs OUG 155/2024 and ENISA NIS2 reference framework.
- Management body review meeting; minute the approval and KPIs.
- Update ENIRE@RO with any material change.
- Schedule the first annual audit and the next tabletop.
9. Frequent mistakes we see in multinationals
- Assuming group ISO 27001 = compliance. It covers controls, not registration, language, or local governance.
- Filing in English. DNSC accepts only Romanian for official notifications.
- Confusing branch and subsidiary. A sucursală follows the parent's jurisdiction; an SRL/SA is its own regulated entity.
- Missing the size aggregation. Linked-enterprise rules can pull a small Romanian entity into "large" classification.
- Designating a representative who cannot act. The Article 26 representative must be empowered to receive enforcement on behalf of the non-EU provider.
- Treating the management body decision as a formality. It is the single most-checked artefact in early DNSC inspections.
10. How CysNis helps foreign-owned entities
CysNis is the Romanian-built NIS2 implementation platform: classification, ENIRE@RO-aligned registration packs, Article 21 evidence, incident notification templates in Romanian, risk register on the 5×5 NIS2 matrix, and audit-ready DOCX/PDF exports. The platform is bilingual (EN/RO) so HQ teams operate in English while output documents are produced in Romanian for DNSC.
Start free with the classification tool or review the pricing.
Frequently asked questions
Does NIS2 apply to a foreign company with a Romanian subsidiary?
Yes, when the Romanian subsidiary independently meets sector and size thresholds, it is a regulated entity in Romania regardless of group-level compliance abroad.
Where does a multi-country EU group register?
Generally in the Member State of main establishment — where cybersecurity decisions are predominantly taken. Digital service providers follow the Article 26 special rule.
Does a non-EU parent need a representative in Romania?
Only certain DSPs without an EU establishment. A Romanian-incorporated subsidiary is itself an EU establishment.
Can a foreign entity rely on its global ISMS?
Partially. Global ISMS covers most Article 21 controls but cannot satisfy ENIRE@RO registration, Romanian-language reporting, local contact, supply chain register, and local management-body governance.
What is the deadline to register a Romanian subsidiary?
60 days (essential) or 150 days (important) from becoming applicable, including from a closing date for new acquisitions.
What are the fines?
Up to 10 M EUR or 2% of worldwide group turnover for essential entities; 7 M EUR or 1.4% for important. Plus personal accountability for the management body.
What is the incident reporting timeline?
6h pre-notification (cross-border), 24h early warning, 72h notification, 1 month final report — all in Romanian via ENIRE@RO.
