NIS2 explained · Romania

What is NIS2? Directive (EU) 2022/2555 explained

NIS2 is the European cybersecurity directive that replaces NIS1, expanding scope from 7 to 18 sectors, introducing strict incident reporting (24h/72h/1 month), holding the management body personally accountable and imposing fines up to 10 million EUR or 2% of global turnover. In Romania it is transposed through OUG 155/2024, with DNSC as the competent authority.

Updated: June 2026 · Applicable to essential and important entities

In brief

What NIS2 changes vs NIS1

NIS2 significantly broadens the previous regime: sectors expand from 7 to 18, the essential/important entity classification replaces operator-of-essential-services, the management body becomes directly accountable, and a structured three-tier incident reporting regime is introduced (early warning within 24 hours, full notification within 72 hours, final report within 1 month).

Who must comply

Essential and important entities across 18 sectors (Annex I & II) above size thresholds: 50 employees and/or 10 million EUR turnover. Specific exceptions apply regardless of size for critical operators (DNS providers, TLD registries, qualified trust services, public electronic communications, public administration).

Check your status with the free NIS2 classification tool.

The 17 Art. 21 pillars

Article 21 of OUG 155/2024 lists 13 explicit pillars (risk policies, incident management, BCM, supply chain security, network security, effectiveness evaluation, training, cryptography, HR security, access control, asset management, MFA, vulnerability management) plus 4 complementary CyFun® 2025 domains (governance, monitoring, logging, recovery) recognised by DNSC.

See NIS2 implementation guide for details.

Deadlines and reporting

FAQ

What is the NIS2 Directive?

Directive (EU) 2022/2555, transposed in Romania through OUG 155/2024 — sets cybersecurity, governance and incident-reporting obligations for essential and important entities in 18 sectors.

Who must comply with NIS2 in Romania?

Essential entities (Annex I, >250 employees or >50M EUR turnover) and important entities (Annex I/II, >50 employees or >10M EUR turnover), with size-agnostic exceptions for unique critical roles.

What are the deadlines?

60 days for essential, 150 days for important entities to register with DNSC via ENIRE@RO. Incidents: 24h / 72h / 1 month.

What sanctions apply?

Up to 10M EUR or 2% global turnover (essential); 7M EUR or 1.4% (important). Personal liability for management on repeated non-compliance.

Related resources