Scope
OUG 155/2024 applies to essential and important entities in 18 sectors (Annexes I & II of the NIS2 Directive). Size thresholds: 50 employees and/or 10M EUR turnover. Size-agnostic exceptions apply to operators with unique critical roles (DNS, TLDs, qualified trust services, public electronic communications, public administration).
DNSC — competent authority
The Directoratul Național de Securitate Cibernetică (DNSC) is the single national competent authority for NIS2. DNSC operates the ENIRE@RO v2 registration platform, receives incident notifications, performs ex-ante supervision of essential entities and ex-post supervision of important entities, and applies sanctions.
Key obligations
- Registration with DNSC via ENIRE@RO within 60 days (essential) or 150 days (important).
- Implementation of Art. 21 measures (17 pillars including 4 CyFun® 2025 domains).
- Incident reporting — 24h early warning, 72h notification, 1 month final report (plus 6h for cross-border impact).
- Management body accountability — formal cybersecurity governance.
- Periodic audit and effectiveness assessment.
Sanctions
| Entity | Max fine | % turnover |
|---|---|---|
| Essential | 10M EUR | 2% |
| Important | 7M EUR | 1.4% |
Whichever is higher. Plus administrative measures: warnings, suspension, ban on management duties.
FAQ
What is OUG 155/2024?
The Romanian Government Emergency Ordinance transposing the NIS2 Directive — in force since December 2024.
What is DNSC's role?
Single competent authority — runs ENIRE@RO v2, receives incident reports, supervises and sanctions.
How does it differ from NIS2?
Adds national specifics: DNSC governance, ENIRE@RO platform, sector codes (§101–§207), CyFun® 2025 reference framework, strict 4-digit NACE classification.
