Romanian law · NIS2 transposition

OUG 155/2024 explained: NIS2 transposition in Romania

OUG 155/2024 is the Romanian Government Emergency Ordinance that transposes EU Directive 2022/2555 (NIS2) into national law. It designates DNSC as the competent authority, mandates registration through ENIRE@RO v2, sets the 60/150-day registration windows, the 24h/72h/1 month incident reporting regime and fines up to 10M EUR or 2% of global turnover.

Updated: June 2026 · Source: Romanian Official Journal, OUG 155/2024

Scope

OUG 155/2024 applies to essential and important entities in 18 sectors (Annexes I & II of the NIS2 Directive). Size thresholds: 50 employees and/or 10M EUR turnover. Size-agnostic exceptions apply to operators with unique critical roles (DNS, TLDs, qualified trust services, public electronic communications, public administration).

DNSC — competent authority

The Directoratul Național de Securitate Cibernetică (DNSC) is the single national competent authority for NIS2. DNSC operates the ENIRE@RO v2 registration platform, receives incident notifications, performs ex-ante supervision of essential entities and ex-post supervision of important entities, and applies sanctions.

Key obligations

  1. Registration with DNSC via ENIRE@RO within 60 days (essential) or 150 days (important).
  2. Implementation of Art. 21 measures (17 pillars including 4 CyFun® 2025 domains).
  3. Incident reporting — 24h early warning, 72h notification, 1 month final report (plus 6h for cross-border impact).
  4. Management body accountability — formal cybersecurity governance.
  5. Periodic audit and effectiveness assessment.

Sanctions

EntityMax fine% turnover
Essential10M EUR2%
Important7M EUR1.4%

Whichever is higher. Plus administrative measures: warnings, suspension, ban on management duties.

FAQ

What is OUG 155/2024?

The Romanian Government Emergency Ordinance transposing the NIS2 Directive — in force since December 2024.

What is DNSC's role?

Single competent authority — runs ENIRE@RO v2, receives incident reports, supervises and sanctions.

How does it differ from NIS2?

Adds national specifics: DNSC governance, ENIRE@RO platform, sector codes (§101–§207), CyFun® 2025 reference framework, strict 4-digit NACE classification.

Related resources