Flagship guide · 2026 edition

NIS2 in Romania: complete guide for foreign entities & subsidiaries

If your group operates a Romanian subsidiary, a branch, or sells regulated digital services into Romania, NIS2 compliance is now a local obligation — not a corporate-headquarters checkbox. This guide explains exactly how the Directive (EU) 2022/2555 was transposed via OUG 155/2024, who is in scope, how jurisdiction works for multi-country groups, what the ENIRE@RO registration looks like, the 24h/72h/1-month reporting clock, fines, and a 90-day roadmap your local team can execute.

Updated: June 2026 · Authoritative sources: Directive (EU) 2022/2555, OUG 155/2024, DNSC guidance, ENISA NIS2 reference framework

1. Why NIS2 matters for foreign-owned operations in Romania

Romania transposed NIS2 through OUG 155/2024, in force since December 2024. The transposition is largely faithful to the Directive but introduces a single national authority — DNSC (Directoratul Național de Securitate Cibernetică) — and a mandatory national registration platform, ENIRE@RO v2. For multinational groups this creates three frictions that ISO 27001 or a global SOC alone do not solve:

2. Jurisdiction: where exactly does your group register?

NIS2 uses two different jurisdiction rules depending on the sector.

2.1 General rule — main establishment

Most essential and important entities (energy, transport, banking, health, water, manufacturing, postal, waste, food, chemicals, etc.) are regulated in the Member State of their main establishment. The main establishment is the Member State where cybersecurity risk-management decisions are predominantly taken. If those decisions cannot be located, it falls back to where cybersecurity operations are carried out or, failing that, where the entity has the largest workforce.

What this means for groups: a Romanian subsidiary of a German manufacturer typically registers in Romania for itself, while the German parent registers in Germany. There is no group-wide single registration; each EU legal entity that meets the thresholds registers locally.

2.2 Special rule — digital infrastructure & DSPs

DNS providers, TLD registries, cloud providers, data center providers, CDNs, MSPs, MSSPs, online marketplaces, online search engines and social networking platforms register either:

A US-headquartered MSP without an EU office that serves Romanian clients must designate an EU representative. If that representative sits in Romania, DNSC becomes the lead regulator.

2.3 Decision matrix

Your situationWhere to registerLocal rep needed?
Romanian SRL/SA subsidiary (any covered sector)Romania (DNSC / ENIRE@RO)No — the SRL/SA is the EU establishment
Branch (sucursală) of EU parent, no separate legal personalityMember State of parent's main establishmentNo
Non-EU cloud/MSP/marketplace serving Romanian users, no EU officeWhere the designated representative sitsYes — Article 26 representative
Group with Romanian-based cybersecurity decisioningRomania, even if HQ is elsewhereNo

3. Scope test: is the Romanian entity actually in?

An entity is in scope when it satisfies both of the following:

  1. It operates in one of the 18 sectors listed in Annex I (high criticality) or Annex II (other critical) of NIS2 — see our full sector list.
  2. It is a medium enterprise (50+ headcount or >10M EUR turnover) or large (250+ headcount or >50M EUR turnover) under EU Recommendation 2003/361/EC.

Medium = important; large in Annex I = essential; large in Annex II = important. There are size-independent exceptions: DNS, TLD, qualified trust service providers, public electronic communications, and entities providing sole services to a Member State are always in scope, regardless of size.

Group thresholds: under OUG 155/2024 and Romanian SME methodology, autonomy is assessed on consolidated headcount and turnover when there is a linked enterprise relationship. A 40-person Romanian subsidiary of a 5 000-person multinational is treated as a large enterprise — not a micro/small entity. Run the free classification tool to remove ambiguity.

4. ENIRE@RO registration: what foreign owners need to know

ENIRE@RO is DNSC's national registry for essential and important entities. Version 2 (active since 2025) requires:

Deadlines

For freshly acquired Romanian subsidiaries, "becoming applicable" is normally the closing date of the transaction — not the parent's original registration date.

5. Article 21 measures: what your local entity must actually do

OUG 155/2024 mirrors the ten technical and organisational measures of NIS2 Article 21. Foreign-owned entities almost always have a head start because group policies cover most of the ground, but a Romanian regulator expects to see local applicability and evidence:

  1. Risk analysis & ISMS — mapped to the Romanian entity's services, not just the global ISMS scope statement.
  2. Incident handling — runbook in Romanian, on-call rotation, DNSC notification template ready.
  3. Business continuity, backup, crisis management — RTO/RPO per critical service; backups tested locally.
  4. Supply chain security — vendor register including intra-group services; contractual NIS2 clauses with parent and sister companies.
  5. Security in acquisition, development, maintenance — secure SDLC and vulnerability handling, including for products imported from HQ.
  6. Policies for assessing effectiveness — local KPIs and periodic review.
  7. Cyber hygiene & training — annual training documented for Romanian staff, in Romanian.
  8. Cryptography — key management policy applicable to local data flows.
  9. HR security, access control, asset management — joiner/mover/leaver tied to the Romanian payroll.
  10. MFA, secured communications, secure emergency comms — applied to all admin and remote access.

The Romanian-specific addition: a documented management body decision approving the Article 21 framework and a yearly review minute. Without this artefact, DNSC inspections start at a deficit.

6. Incident reporting clock

The clock is identical to the Directive but enforcement is Romanian:

Notifications are filed in Romanian through ENIRE@RO. Practically, foreign-owned groups should pre-translate notification templates and pre-assign the Romanian-speaking person who has authority to file without HQ sign-off in the first 24 hours.

7. Sanctions and personal liability

Entity typeMaximum administrative fineAlternative cap
Essential10 000 000 EUR2% of worldwide annual turnover (whichever is higher)
Important7 000 000 EUR1.4% of worldwide annual turnover (whichever is higher)

"Worldwide annual turnover" in the Directive is interpreted at the level of the undertaking — i.e., the consolidated group. A 5 M EUR Romanian subsidiary of a 4 bn EUR parent therefore faces a fine ceiling computed on the 4 bn, not the 5 M.

For repeated infringements DNSC may, subject to judicial review, suspend a certification or authorisation and prohibit any natural person discharging managerial responsibilities from doing so within the entity. Group HQ cannot indemnify away an Article 20 obligation that EU law assigns personally.

8. 90-day roadmap for a foreign-owned Romanian entity

Days 1–15 — Establish the local programme

Days 16–45 — Register and localise

Days 46–75 — Build evidence

Days 76–90 — Assure and report

9. Frequent mistakes we see in multinationals

10. How CysNis helps foreign-owned entities

CysNis is the Romanian-built NIS2 implementation platform: classification, ENIRE@RO-aligned registration packs, Article 21 evidence, incident notification templates in Romanian, risk register on the 5×5 NIS2 matrix, and audit-ready DOCX/PDF exports. The platform is bilingual (EN/RO) so HQ teams operate in English while output documents are produced in Romanian for DNSC.

Start free with the classification tool or review the pricing.

Frequently asked questions

Does NIS2 apply to a foreign company with a Romanian subsidiary?

Yes, when the Romanian subsidiary independently meets sector and size thresholds, it is a regulated entity in Romania regardless of group-level compliance abroad.

Where does a multi-country EU group register?

Generally in the Member State of main establishment — where cybersecurity decisions are predominantly taken. Digital service providers follow the Article 26 special rule.

Does a non-EU parent need a representative in Romania?

Only certain DSPs without an EU establishment. A Romanian-incorporated subsidiary is itself an EU establishment.

Can a foreign entity rely on its global ISMS?

Partially. Global ISMS covers most Article 21 controls but cannot satisfy ENIRE@RO registration, Romanian-language reporting, local contact, supply chain register, and local management-body governance.

What is the deadline to register a Romanian subsidiary?

60 days (essential) or 150 days (important) from becoming applicable, including from a closing date for new acquisitions.

What are the fines?

Up to 10 M EUR or 2% of worldwide group turnover for essential entities; 7 M EUR or 1.4% for important. Plus personal accountability for the management body.

What is the incident reporting timeline?

6h pre-notification (cross-border), 24h early warning, 72h notification, 1 month final report — all in Romanian via ENIRE@RO.

Related resources