Romania’s NIS2 law: where to find the official text of GEO 155/2024

Where to find the official text of Romania's NIS2 law

Romania transposed NIS2 through Government Emergency Ordinance no. 155/2024. Anyone trying to read the actual law runs into three problems: the official PDF of the Official Gazette is not free, most copies circulating online are the initial version without the 2025 and 2026 amendments, and there is no official English translation.

Below are the exact acts, where the consolidated text can be read for free, what changed, and how to cite it correctly.

The acts, precisely identified

ActSubjectOfficial Gazette
GEO no. 155 of 30 December 2024framework for the cyber security of networks and information systems in the national civil cyberspaceno. 1332 of 31 December 2024
Law no. 124 of 7 July 2025approval of GEO no. 155/2024, with amendments and additionsno. 638 of 7 July 2025
Law no. 123 of 3 July 2026addition to art. 36 of GEO no. 155/2024 and to the Criminal Codeno. 550 of 3 July 2026

The ordinance entered into force on 31 December 2024, with one exception set out in art. 64 para. (4): art. 60 and 61, the offences and their establishment, entered into force 30 days after publication, on 30 January 2025. The amendments brought by Law no. 124/2025 take effect from 10 July 2025.

The correct citation today is „GEO no. 155/2024, approved with amendments and additions by Law no. 124/2025, as subsequently supplemented”. A document that cites only the ordinance was written before July 2025, or written in a hurry.

Where to read the text, free and up to date

The free official source is the Legislative Portal of the Romanian Ministry of Justice, which publishes the consolidated form, meaning the text with amendments incorporated and marked:

Each page carries a „Forma printabilă” button, the printable form, which renders the whole act on a single page that a browser can save as PDF. It is the closest thing to the free PDF people are looking for, with the advantage of being the version in force rather than the original one.

There is no official English translation of the ordinance. For cross-border work, the practical approach is to read the Romanian consolidated text against the English text of Directive (EU) 2022/2555, keeping in mind that the national text adds obligations the directive does not contain.

A map of the ordinance

The ordinance has 11 chapters and 68 articles.

ChapterContentArticles
IGeneral provisions, definitions1 to 4
IIScope, essential and important entities, thresholds5 to 10
IIIRisk management measures and reporting obligations11 to 17
IVRegistration, register of entities18 to 20
VRoles and responsibilities21 to 36
VICooperation37 to 45
VIISupervision, verification and control46 to 56
VIIICyber security audit57 to 59
IXPenalties60 to 63
XTransitional and final provisions64 to 68

The articles people reach for most often: art. 5 and 6 for classification as essential or important, art. 8 for thresholds, art. 9 for entering scope regardless of size, art. 11 to 14 for measures, audit and management obligations, art. 15 for incident reporting, art. 18 for registration, art. 58 for auditors, art. 60 for fines.

What Law no. 124/2025 changed

The law has a single article with 23 amending points. The ones with direct practical effect:

  • Art. 14 para. (2) and (3). Members of management bodies attend accredited professional training. Entities provide regular training for all staff. Management establishes permanent contact points, allocates resources, and appoints the officers responsible for the security of networks and information systems within 30 days of DNSC communicating the registration decision.
  • Art. 15 para. (6). The introductory definition of a significant incident was rewritten.
  • Art. 18 para. (3) letter g) and para. (10). Information on the member states where the entity provides services, and its transmission to ENISA.
  • Art. 50 para. (2) and (4). Serious breaches redefined.
  • Art. 60. Letters n), bb) and cc) amended, letters pp) and qq) added, the fine regime in para. (2) rewritten, and a new para. (2^1): serious breaches under art. 50 para. (2) are penalised with fines from 3,000 to 600,000 lei.
  • Art. 60 para. (3) and (4). The turnover of reference for percentage based fines is that of the last financial year.
  • Art. 61 para. (2). Competences to establish offences are split between DNSC and the sectoral competent authorities. For letters o) to dd), DNSC establishes the offence and the penalty is applied by decision of its director.
  • The annexes. Sector 5, health, and sector 8, digital infrastructure, were rewritten in Annex no. 1. In Annex no. 2, sector 4 became „Production, processing and/or distribution of food”, which widens scope: a company no longer has to do all three.

That last point is the most underestimated. A company that only distributes food, without producing or processing it, came into the conversation through that „and/or”.

Law no. 123/2026, the amendment nobody talks about

In July 2026 the ordinance was supplemented again. Law no. 123/2026 inserts art. 36 para. (1^1) into GEO no. 155/2024 and, more importantly, art. 365^1 into the Criminal Code, a ground removing the criminal character of the act. In practice, vulnerability research conducted in cumulative compliance with the reporting conditions in art. 36 para. (5) and (6) no longer constitutes an offence under art. 360 para. (1) and (3), art. 361 and art. 364 of the Criminal Code.

This is the first safe harbour for security researchers in Romanian law. For entities it means that a coordinated vulnerability disclosure policy is no longer merely good practice, it now has a counterpart in statute.

What the ordinance does not contain

  • The size threshold figures. Art. 8 contains no numbers. It refers to art. 4 para. (1) letter c) of Law no. 346/2004, without applying art. 4^5. That detail matters: classification is done per entity, without aggregating figures from linked or partner undertakings.
  • The concrete technical measures. Art. 13 gives the minimum list. The actual control catalogue is in Order of the DNSC director no. 1/2026.
  • The audit interval. Art. 11 para. (5) defers it to the order under art. 12 para. (1). Order no. 1/2026 sets no interval, so as at the date of this article the periodicity is not regulated.
  • The notification form. It is annexed to the Requirements approved by Order of the DNSC director no. 1/2025.

The DNSC orders, in brief

ActSubjectOfficial Gazette
Order no. 1/2025how you register: notification requirements, the form, the NIS2@RO platformno. 776 of 20 August 2025
Order no. 2/2025how your risk level and assurance level are calculatedno. 776 of 20 August 2025
Order no. 3/2025how DNSC supervises, verifies and controlsno. 1149 of 11 December 2025
Order no. 1/2026risk management measures and the maturity self-assessment methodologyno. 712 of 27 August 2026, annexes in 712 bis
Order no. 2/2026supplement to Order no. 1/2026, reference to the rules for groupsno. 792 of 18 September 2026
Decision no. 3/2026applicability rules for entities in a group of undertakingsno. 798 of 21 September 2026

Where we can help

If the real question behind the search is „does this apply to us”, the answer is not in the PDF, it is in the scoping exercise. The CysNis platform walks through the criteria step by step.

If you are already in scope, the distance between the text and practice is measured through a NIS2 compliance analysis with a remediation plan. ProDefence is a cyber security auditor accredited by DNSC, and the role of the responsible officer can be covered through an outsourced NIS2 officer.

Sources

This material is informative and does not constitute legal advice. Article titles and quotations are working translations of the Romanian text. Consolidated forms change; check the last update date on each act’s page.

Frequently asked questions

Where can I find a PDF of Romania’s NIS2 law?

There is no free official PDF. The consolidated text, meaning the version in force with all amendments, is available free of charge on the Legislative Portal of the Ministry of Justice, document 293121, and the „Forma printabilă” button lets a browser save it as PDF. The authentic Official Gazette issue is available for a fee.

What did Law no. 124/2025 change?

It has a single article with 23 amending points. The most important concern accredited training for management bodies and the appointment of responsible officers, the definition of a significant incident, serious breaches, the fine regime in art. 60, the competences in art. 61, and the rewriting of sectors 5 and 8 in Annex no. 1. In Annex no. 2, the food sector became „production, processing and/or distribution”.

How should Romanian NIS2 legislation be cited today?

„GEO no. 155/2024, approved with amendments and additions by Law no. 124/2025, as subsequently supplemented”. The subsequent supplement is Law no. 123/2026, which added art. 36 para. (1^1) and art. 365^1 of the Criminal Code.

Where are the size thresholds for essential and important entities?

Not in the ordinance. Art. 8 refers to art. 4 para. (1) letter c) of Law no. 346/2004, without applying art. 4^5. Classification is therefore done per entity, without aggregating figures from linked or partner undertakings.

Is there an official English translation of GEO 155/2024?

No. For cross-border work the practical approach is to read the Romanian consolidated text alongside the English text of Directive (EU) 2022/2555, bearing in mind that the national act adds obligations the directive does not contain.

Which DNSC orders must be read together with the ordinance?

Order no. 1/2025 for registration, Order no. 2/2025 for the risk level, Order no. 3/2025 for supervision and control, Order no. 1/2026 for risk management measures and maturity self-assessment, and Order no. 2/2026 together with Decision no. 3/2026 for entities in a group of undertakings.

Skip to content