NIS2 officer in Romania: important entities must appoint one too, not only essential entities
The question comes up in almost every scoping discussion: “we are an important entity, do we still have to appoint a NIS officer?” The answer is yes, and the legal basis requires no interpretation at all. The confusion comes from a single word missing from one paragraph, and this article shows exactly where it comes from and why it changes nothing.
In short
- Art. 14 para. (3) of Romania’s GEO no. 155/2024 requires the appointment of the officer responsible for the security of networks and information systems at both essential and important entities, expressly.
- Para. (4) does not create the obligation. It sets the minimum profile criteria for that person, in a subset: essential entities, excluding public administration entities, micro and small enterprises.
- The difference between the two categories lies in sanction levels and supervision mode, not in the scope of obligations.
- The 30 day deadline runs from communication of the DNSC director’s decision on identification and entry in the register, not from the entry into force of the law.
What the text says, literally
Art. 14 para. (3) of Government Emergency Ordinance no. 155/2024, as amended by Law no. 124/2025:
“The management bodies of essential entities and of important entities establish permanent means of contact, ensure the allocation of the resources needed to implement cybersecurity risk management measures and appoint, within 30 days from communication of the DNSC director’s decision on identification and entry in the register, the officers responsible for the security of networks and information systems whose role is to implement and supervise cybersecurity risk management measures at the level of the entity.”
Both categories are named. The verb is “appoint”, not “may appoint”. There is no grey area here. Anyone claiming that important entities are exempt has to explain how they read this paragraph, and there is no way to do it.
Where the confusion actually comes from
From the next paragraph. Para. (4) sets the conditions the appointed person must meet, but limits them to part of the entities:
“The person responsible for the security of networks and information systems, provided for in para. (3), appointed within essential entities, with the exception of public administration entities, as well as micro and small enterprises … must cumulatively meet at least the following: a) has managerial authority; b) reports directly to the management bodies of the entity; c) operates independently of the IT and operational technology structures; d) has access to the resources needed …; e) has obtained an accredited specialist course, recognised by DNSC, in the field of cybersecurity, within 12 months of appointment.”
Because only essential entities appear here, people quickly reach the wrong conclusion that important entities have no obligation. That is the exact opposite of what the text says.
Three reasons why para. (4) confirms the obligation rather than narrowing it
First, and decisive: para. (4) refers back to para. (3). The wording is “The person responsible … provided for in para. (3)”. Para. (4) does not establish a new appointment; it qualifies a person whose appointment is already imposed elsewhere. For that cross-reference to make sense, the appointment must exist in both categories. A paragraph describing a person’s profile cannot abolish the paragraph that requires that person to exist.
Second, where the law does not distinguish, neither should we. Para. (3) makes no difference between essential and important. The interpretive rule is classic, ubi lex non distinguit, nec nos distinguere debemus, and applies without difficulty to a text that expressly lists both categories.
Third, the legislator knew how to distinguish and did so where it wanted to. Para. (4) does not exclude only important entities. It also excludes public administration entities, micro enterprises and small enterprises, with an express reference to art. 4 para. (1) letters a) and b) of Law no. 346/2004. That is a deliberate proportionality pattern, not a drafting slip. And if the legislator distinguished that precisely in para. (4), the absence of any distinction in para. (3) is equally deliberate.
The practical conclusion: the difference between the two categories is not whether you appoint, but whom you may appoint.
What actually differs between essential and important
| Requirement | Essential entity (excluding public administration, micro and small) | Important entity |
|---|---|---|
| Appointment of the officer, para. (3) | Mandatory | Mandatory |
| 30 day deadline from communication of the DNSC decision | Yes | Yes |
| Role: implementing and supervising the measures | Yes | Yes |
| Managerial authority | Required by law | Not required |
| Direct reporting to the management body | Required | Not required |
| Independence from IT and OT structures | Required | Not required |
| Access to the necessary resources | Required | Not required |
| Accredited course recognised by DNSC, within 12 months of appointment | Required | Not required |
An important entity therefore has freedom in choosing the person. It may appoint someone from the IT function, without managerial authority and without an accredited course. It may, but it is worth thinking twice, for the reason set out further down.
The trap: two different training obligations, for two different people
This is the most common reasoning error on both sides of the argument, and it deserves a clear separation.
- Para. (2) requires accredited professional training for the members of the management body, at essential and important entities. That means the director, the CEO, the board.
- Para. (4) letter e) requires an accredited specialist course recognised by DNSC, within 12 months of appointment, for the appointed person, only in the subset of essential entities described above.
Two distinct people, two distinct obligations. The board of an important entity takes training because para. (2) requires it, independently of anything in para. (4). Confusing the two leads either to believing that para. (4) “forgot” important entities, or that para. (2) applies to the appointed officer. Neither reading survives contact with the text.
The same distinction produces the split that matters in practice: execution responsibility belongs to the appointed person, while accountability stays with the management body under para. (1). The function can be delegated; the accountability cannot.
How the authority itself reads art. 14
DNSC has drafted a decision approving the training standard for members of management bodies and the list of recognised certifications. It is a draft, watermarked DRAFT, and not a legal act in force, so it cannot be cited as a legal basis. It is, however, the clearest public indication of how the authority itself reads art. 14, and that reading confirms everything above.
The declared scope of the standard covers both categories: the title speaks of “the training standard for the members of the management bodies of essential and important entities”, and the qualification level is defined as “Strategic / Executive Management, essential and important entities”. There is no separate, lighter version for important entities.
One of the six competence units is the appointment duty itself. Unit 3, “Organisation, Delegation and Resource Allocation”, declares its source as “GEO 155 Art. 14(3)” and is described as follows: “This unit details how the manager fulfils the legal obligation to ‘appoint’ responsible persons and to ‘supervise’ their activity.” Its first competence element requires the manager to use “the European ENISA ECSF ‘CISO’ profile and the provisions of paragraphs (3) and (4) of GEO 155/2024″ to define the job description, objectives and KPIs, to establish “reporting lines that ensure the CISO’s independence from the IT department”, and to issue “the formal appointment decision in accordance with legal requirements”.
In other words, the authority teaches the appointment as an executive duty of the management of any entity within the scope of the ordinance, and the independence criterion, which in the law appears only in para. (4), is presented as a competence element for the management of both categories. Legally that does not turn the criterion into an obligation for important entities. Practically, it shows plainly what the authority expects.
The draft also states for itself what the difference between the two categories consists of. Under the “Range of Variables” of the first competence unit: “Type of entity: Essential (critical sectors, maximum sanctions) vs. Important (slightly reduced sanctions, ex post supervision).” The difference is one of sanction level and supervision mode, not of the scope of obligations.
The same draft is what names the art. 14 (3) and (4) officer “CISO”, taking the role profile from the European ENISA ECSF framework. If it is adopted, this will become the authority’s de facto terminology, although the legal designation remains “officer responsible for the security of networks and information systems”. The standard is analysed in detail in the article on the DNSC draft training standard for management bodies, which we publish on 29 September.
The 30 day deadline: when it actually starts
This deserves to be said plainly, because it is the only real argument available to those who are waiting. The 30 day deadline does not run from the entry into force of the ordinance, but from communication of the DNSC director’s decision on identification and entry in the register. An entity that has not yet received that decision does not have the clock running.
That is not an exemption, though, it is a deferral of a procedural deadline. The substantive obligation stands, and 30 calendar days are enough to sign a decision, not to find the right person, build their job description, establish the reporting line and secure their independence from IT. Organisations that start only after receiving the decision predictably end up with a formal appointment made in haste, exactly the kind of evidence that collapses at the first inspection.
What an important entity actually risks by waiting
Failure to comply with the obligations in art. 14 is sanctionable in both categories. The maximum caps are higher for essential entities than for important ones under the ordinance’s sanctions regime, but a lower cap is not an exemption from the obligation.
The difference in mechanism matters more. Essential entities are subject to ex ante supervision, meaning they can be checked proactively. Important entities are subject to ex post supervision, which means the check usually comes after an incident or a complaint. The moment at which an important entity has to show who the appointed officer was, what duties they had and what they did is, statistically, the worst possible moment: mid investigation, with the service degraded and the press on the story.
And here is the argument that should weigh more than the letter of the law. At important entities the para. (4) criteria are not mandatory. But an officer reporting to the very structure they are supposed to control, with no managerial authority and no budget, is the first observation any auditor writes and the first weakness any post incident analysis exploits. The law permits it; risk management does not recommend it.
What to do in practice, in the right order
- Confirm your classification. Essential or important, on what criterion, in which sector. Everything else follows, including which profile criteria apply to you.
- Choose the person before the DNSC decision arrives. The 30 days are for formalisation, not for recruitment.
- Issue the appointment decision, with duties, reporting line, indicators and a firm date.
- Document the independence, even as an important entity for which the law does not require it. It costs one line in the org chart and it saves your file.
- Connect the appointment to the rest of the file: the approved security policy, the signed risk register, the incident reporting procedure with its 24 hour and 72 hour deadlines, and the minutes of a risk review meeting.
For the first step, the CysNis platform walks through the classification criteria step by step and separates legal obligations from technical recommendations, so the board discussion starts from a clear status rather than an assumption.
For steps three to five, the documents do not have to be invented from scratch. The NIS2 documentation packages contain editable templates for appointment decisions, job descriptions, policies, registers and procedures. If you would rather first know how far you are from the requirements, the starting point is a NIS2 compliance assessment with a remediation plan, carried out on evidence rather than declarations. ProDefence is a NIS auditor accredited by DNSC.
Where no internal person can cover the role, and especially where the only candidate would be the head of IT, which is precisely the situation the independence criterion is designed to avoid, the role can be covered through an outsourced NIS2 officer, accountable for deadlines, documentation and the relationship with the authority. Which approach fits the organisation, in-house, consultant or outsourced role, is compared in the article on implementing NIS2 requirements in Romania, three routes.
Frequently asked questions
Do important entities have to appoint a NIS2 officer?
Yes. Art. 14 para. (3) of GEO no. 155/2024, as amended by Law no. 124/2025, requires the appointment by the management bodies of essential entities and of important entities alike. The text lists both expressly.
Then why does para. (4) mention only essential entities?
Because para. (4) does not govern the duty to appoint, but the minimum conditions the appointed person must meet. It refers expressly back to para. (3), so it presupposes that the appointment already exists in both categories. The limitation applies the proportionality principle, in the same way as the exclusion of public administration entities, micro and small enterprises in the same paragraph.
At an important entity, can the officer be the head of IT?
The law does not forbid it, because the independence requirement from IT and OT structures sits in para. (4), which applies to essential entities. From a risk management perspective it is a weak choice: the person controlling the measures ends up reporting to the structure they control, and that conflict of interest is the first observation in an audit or a post incident analysis.
When does the 30 day appointment deadline start?
From communication of the DNSC director’s decision on identification and entry in the register, not from the entry into force of the ordinance. The substantive obligation exists independently of that procedural deadline, and 30 days are not enough to recruit and prepare the right person.
Does the appointed officer need a certification?
An accredited specialist course recognised by DNSC, obtained within 12 months of appointment, is required by para. (4) letter e), so in essential entities, with the exceptions stated in the text. The law does not impose this condition on important entities.
Can the role be outsourced?
The law speaks of appointing a responsible person and, at essential entities, of criteria on authority, reporting, independence and access to resources. Covering the role through an external provider is widely practised, provided the duties, the reporting line and the contractual accountability are documented. The management body’s own accountability under para. (1) stays with the entity in any case.
What is the real difference between an essential and an important entity?
The level of the sanction caps and the supervision mode. Essential entities are subject to ex ante supervision, important entities to ex post supervision, usually triggered by an incident or a complaint. The risk management and governance obligations in art. 11 to 14 apply to both.
The analysis above is a technical reading of the text of GEO no. 155/2024, approved with amendments by Law no. 124/2025. It is informative and does not constitute legal advice. The DNSC draft decision cited is watermarked DRAFT and is not a legal act in force.


