The DNSC notification form and the NIS2@RO platform: how registration is done correctly

The DNSC registration form and the NIS2@RO platform

„Romania NIS2 registration” hides a common confusion. Many people assume there is a single, all purpose DNSC form. In fact, as at the date of this article there is one form regulated by a normative act: the notification form for registration in the register of entities. It is annexed to the Requirements approved by Order of the DNSC director no. 1 of 11 August 2025, published in the Official Gazette no. 776 of 20 August 2025.

The first fine issued by DNSC under GEO no. 155/2024, on 29 September 2026, concerns exactly this notification. It is worth getting right the first time.

The NIS2@RO tool and the NIS2@RO platform are not the same thing

The Requirements describe two distinct mechanisms, and confusing them is the most frequent source of delay:

NIS2@RO toolNIS2@RO platform
What it isa digital tool for assessment and for generating the notification dataan enrolment, information and cooperation platform
Where it runslocally, downloadedonline, at platformanis2.ro, with an account
When it is usedonly when the platform is unavailablethe primary method

The rule is simple: once an entity has enrolled on the platform, all subsequent interaction happens exclusively through it. The local tool is a fallback, not a permanent alternative.

The six sections of the form

  1. General data. Name, unique registration code, registered office, primary and secondary activity codes.
  2. Specific data. Average headcount, net turnover, total assets, sector, subsector and entity type, public IP address ranges, presence in other member states, and the details of the person responsible for cyber security where one has already been appointed: name, position, e-mail address and mobile number.
  3. Specific situations. Among others, the self-assessment against art. 9, meaning entry into scope regardless of size, and whether the entity is a critical entity under the legislation on the resilience of critical entities.
  4. Attached documents.
  5. Preliminary assessment.
  6. Entity representation.

Two fields cause most of the delay. Public IP address ranges assume an inventory many organisations do not keep current, especially those that have partly migrated to cloud. And the subsector is not chosen intuitively: the annexes have a structure of their own that does not map onto national activity codes.

Signature, and who signs

The form is saved as a PDF and signed by the legal representative of the entity, with a qualified electronic signature. On paper filing, the signature is handwritten. This is not a document the network administrator sends in their own name.

The three channels

  • the NIS2@RO platform, at platformanis2.ro, after authentication;
  • by e-mail, to the DNSC records address given in the Requirements;
  • by filing at the DNSC office, Str. Italiană nr. 22, Bucharest, sector 2.

Acknowledgement matters. Under art. 11 of the Requirements, the notification is deemed received on the date DNSC confirms receipt, and no later than 5 working days, for submissions through the platform or by e-mail. For physical filing, the date is the date of filing. Keep the evidence. It is the only thing that counts if the deadline is ever questioned.

What happens next

  • Enrolment on the platform. An entity that notified by e-mail or on paper because the platform was unavailable must create an account within 20 days of the platform becoming available. DNSC validates and confirms the data within 10 working days.
  • The registration decision. Its communication starts the 30 day period for appointing the officer responsible for the security of networks and information systems, under art. 14 para. (3) of the ordinance.
  • Updates. Changes to identification information must be communicated to DNSC within two weeks of the change, under art. 18 para. (8) letter a). A change of registered office, of legal representative or of IP ranges falls here.

What this form is not

It is not the incident notification form. Incident reporting is governed by art. 15 of the ordinance, with deadlines of 24 hours, 72 hours and one month, and art. 15 para. (17) provides that the methodological rules for incident reporting are to be set by order of the DNSC director. As at the date of this article we have not identified such an order published in the Official Gazette.

Nor is it an officer appointment form. No separate form of that kind exists: the details of the responsible person are declared inside the registration form, in the „Specific data” section, and changes are communicated through an update.

The mistakes that keep repeating

  • The form is completed, saved, and never sent. Without an acknowledgement, there is no notification.
  • It is signed by someone who is neither the legal representative nor formally empowered.
  • Only the primary activity code is declared, although the activity that brings the entity into scope sits on a secondary one.
  • Public IP ranges are left blank, because „the provider knows them”.
  • The entity notifies once and never updates anything, although the office, the representative or the infrastructure have changed since.
  • Silence from DNSC is read as confirmation of being out of scope. Silence is not a decision.

Where we can help

Scoping comes before the form, because half of the fields depend on it. The CysNis platform walks through the criteria step by step.

If you want the notification, the appointment of the responsible officer and the supporting documents done once and done correctly, the starting point is a NIS2 compliance analysis with a remediation plan. The role itself can be covered through an outsourced NIS2 officer.

Sources

This material is informative and does not constitute legal advice. Quotations from the Romanian acts are working translations. Addresses and procedures may change; check dnsc.ro and platformanis2.ro before filing.

Frequently asked questions

Is there a DNSC form for NIS2?

Yes, one form regulated by a normative act: the notification form for registration in the register of entities, annexed to the Requirements approved by Order of the DNSC director no. 1/2025. There is no published incident notification form approved by order, and no separate form for appointing the responsible officer.

What is the difference between the NIS2@RO tool and the NIS2@RO platform?

The tool is a downloadable application used locally for assessment and for generating the notification data, and it is used only when the platform is unavailable. The platform, at platformanis2.ro, is the primary mechanism: enrolment, information and cooperation, with an account. After enrolment, interaction happens exclusively through the platform.

Who signs the registration form?

The legal representative of the entity, with a qualified electronic signature on the PDF, or by hand on paper filing. It is not a document the network administrator can send in their own name.

How is the notification filed and when is it deemed received?

Through the NIS2@RO platform after authentication, by e-mail to the DNSC records address, or by filing at the DNSC office in Str. Italiană nr. 22, Bucharest, sector 2. It is deemed received on the date DNSC confirms receipt, and no later than 5 working days for the first two channels.

What data does the form require?

Name, registration code, registered office, activity codes, average headcount, net turnover, total assets, sector, subsector and entity type, public IP address ranges, presence in other member states, the details of the person responsible for cyber security if appointed, plus specific situations and attached documents.

We notified by e-mail. Do we still need a platform account?

Yes. An entity that notified by e-mail or on paper because the platform was unavailable must create an account within 20 days of the platform becoming available, and DNSC validates the data within 10 working days.

Skip to content