In brief
- Legal basis: EU Directive 2022/2555 + Romanian OUG 155/2024.
- Scope: 18 sectors, essential & important entities above size thresholds.
- Key obligations: DNSC registration, Art. 21 measures, incident reporting, governance.
- Sanctions: up to 10M EUR or 2% of global turnover.
What NIS2 changes vs NIS1
NIS2 significantly broadens the previous regime: sectors expand from 7 to 18, the essential/important entity classification replaces operator-of-essential-services, the management body becomes directly accountable, and a structured three-tier incident reporting regime is introduced (early warning within 24 hours, full notification within 72 hours, final report within 1 month).
Who must comply
Essential and important entities across 18 sectors (Annex I & II) above size thresholds: 50 employees and/or 10 million EUR turnover. Specific exceptions apply regardless of size for critical operators (DNS providers, TLD registries, qualified trust services, public electronic communications, public administration).
Check your status with the free NIS2 classification tool.
The 17 Art. 21 pillars
Article 21 of OUG 155/2024 lists 13 explicit pillars (risk policies, incident management, BCM, supply chain security, network security, effectiveness evaluation, training, cryptography, HR security, access control, asset management, MFA, vulnerability management) plus 4 complementary CyFun® 2025 domains (governance, monitoring, logging, recovery) recognised by DNSC.
See NIS2 implementation guide for details.
Deadlines and reporting
- DNSC registration: 60 days (essential) / 150 days (important) from becoming applicable, via ENIRE@RO.
- Incident reporting: 24h early warning, 72h notification, 1 month final report.
- Audit & evidence: ongoing; periodic assessment of measure effectiveness.
FAQ
What is the NIS2 Directive?
Directive (EU) 2022/2555, transposed in Romania through OUG 155/2024 — sets cybersecurity, governance and incident-reporting obligations for essential and important entities in 18 sectors.
Who must comply with NIS2 in Romania?
Essential entities (Annex I, >250 employees or >50M EUR turnover) and important entities (Annex I/II, >50 employees or >10M EUR turnover), with size-agnostic exceptions for unique critical roles.
What are the deadlines?
60 days for essential, 150 days for important entities to register with DNSC via ENIRE@RO. Incidents: 24h / 72h / 1 month.
What sanctions apply?
Up to 10M EUR or 2% global turnover (essential); 7M EUR or 1.4% (important). Personal liability for management on repeated non-compliance.
