The NIS officer in Romania: duties, appointment, training and what DNSC does not certify
„NIS officer” is not a legal title in Romania. In GEO no. 155/2024 the role is called the officer responsible for the security of networks and information systems, and DNSC orders also use „the person responsible for cyber security”. The short name caught on through the training market. Around it, three false claims circulate: that a dedicated occupational code exists, that the officer is licensed by the authority, and that the role is solved by attending a course.
What the law actually says
The basis is art. 14 para. (3), as amended by Law no. 124/2025. The management bodies of essential and important entities establish permanent means of contact, allocate the necessary resources and appoint, within 30 days of the communication of the DNSC director’s decision on identification and entry in the register, the officers responsible for the security of networks and information systems.
Two things to keep in mind. The deadline does not run from a fixed calendar date, it runs from the communication of the DNSC decision. And the obligation covers both categories of entity, not only essential ones, a point we covered separately in the article on the appointment obligation for important entities.
The conditions in para. (4), and who they apply to
Art. 14 para. (4) adds five cumulative conditions, but only for the person appointed in essential entities, excluding public administration entities, micro enterprises and small enterprises:
- holds managerial authority;
- reports directly to the management bodies of the entity;
- operates independently of the IT and operational technology functions;
- has access to the resources needed to supervise and implement the measures effectively;
- has completed an accredited specialist course in cyber security, recognised by DNSC, within 12 months of appointment.
Independence from IT is the condition most often breached in practice. Appointing the head of IT as the responsible officer, in an essential entity that does not fall within the exceptions, does not satisfy para. (4) letter c). Not because the person is unsuitable, but because nobody supervises themselves.
Occupational code: there is no dedicated one
The Romanian Classification of Occupations contains no occupation called „NIS officer” or „officer responsible for the security of networks and information systems”. What is used in practice are occupations in base group 2529, specialists in databases and networks:
| Code | Occupation |
|---|---|
| 252904 | Cyber security expert |
| 252906 | Cyber security auditor |
| 252907 | Cyber security consultant |
| 252908 | ICT security administrator |
| 252910 | Information systems security manager |
| 252913 | Specialist in information systems security procedures and tools |
| 133048 | Information security manager (CISO), group 1330 |
Job descriptions circulating online give „code 252913, cyber security specialist”. The title is wrong: 252913 is „specialist in information systems security procedures and tools”. If the wrong title reaches the personnel file, correcting it later costs more.
The practical conclusion: pick the code by the real content of the position, not by the „NIS” label. The law requires no particular code.
There is no „DNSC licensed NIS officer”
This is the most frequent and most misunderstood question. DNSC does not license, attest or register the responsible person. The arguments are in the text of the ordinance:
- Art. 25 lists the tasks of DNSC. Letter j) covers issuing, revoking and renewing attestations for cyber security auditors. Letter k) covers authorising training service providers for auditors and CSIRT teams. The officer responsible for network security does not appear.
- Art. 58 regulates the attestation of auditors only.
- Art. 65 para. (1) lists the orders the DNSC director must issue. None concerns attestation of the responsible officer.
The closest reference is art. 26 para. (2), under which DNSC ensures the evaluation of the training and specialisation process for auditors, CSIRT team members, cyber security officers and training providers. That is a task about the training process, not an attestation of the person.
What did exist is something else: a Responsabil NIS training programme, delivered by providers authorised under DNSC Order no. 106/2022, with a certificate recognised by DNSC. That programme has been discontinued. According to the DNSC announcement, from 1 March 2026 no completion certificates are issued for programmes organised after that date.
The regulatory gap, stated plainly
Art. 14 para. (4) letter e) requires an „accredited specialist course, recognised by DNSC”. Order no. 106/2022 was issued under Law no. 362/2018, repealed by GEO no. 155/2024, and under the new law the authorisation of training providers covers only auditors and CSIRT teams. The programme dedicated to the responsible officer has been discontinued, and no act defining which course is „recognised by DNSC” for this role had been published as at the date of this article.
The result: the obligation exists, the mechanism to satisfy it does not. For an entity inside the 12 month window, the reasonable course is to document what training the appointed person completed, from whom, with what content and with what certificate, and to keep the evidence. In an inspection, serious documented training is a better position than none, and the impossibility of obtaining a certificate that does not exist is not attributable to the entity.
Be careful with offers that still use the „DNSC authorised” label for NIS officer courses. Ask the provider, in writing, for the authorisation number, the programme it covers and its validity date.
Can the role be outsourced?
The law says nothing about outsourcing, neither permitting nor prohibiting it. Art. 14 para. (3) uses the verb „appoints”, without requiring employee status. The real constraints come from the five conditions in para. (4): managerial authority, direct reporting to management, independence from IT and OT, access to resources, training.
An external provider can meet those conditions only through a formal mandate, with access and authority written into the appointment decision, not through an ordinary consultancy contract. And whatever the arrangement, accountability stays with the management bodies: art. 14 para. (1) makes them responsible for breaches. There is no transfer of liability to the appointed person or to the provider.
What is penalised
| Letter of art. 60 para. (1) | Conduct |
|---|---|
| h) | members of management bodies do not attend the training required by art. 14 para. (2) |
| i) | failure to establish permanent means of contact |
| j) | failure to allocate resources |
| k) | failure to appoint the officers responsible for the security of networks and information systems |
All four sit in the upper fine range of art. 60 para. (2) letters a) and b): from 5,000 lei up to 7,000,000 euro or 1.4 per cent of total worldwide annual turnover for important entities, and from 10,000 lei up to 10,000,000 euro or 2 per cent for essential ones, whichever is higher. By comparison, failure to register with DNSC, for which the first fine was issued, sits on the lower tier.
The checklist
- Is there a written appointment decision, dated and signed by the management body?
- Does it fall within 30 days of the communication of the DNSC registration decision?
- For essential entities outside the exceptions, are all five conditions in para. (4) met, including independence from IT?
- Have the person’s details been communicated to DNSC, through the registration form or an update within two weeks of a change?
- Is there a job description with real duties, not just a line on an organisation chart?
- Is there evidence of training and a plan for the 12 month deadline?
- Does the person have unfiltered access to management, and a budget?
Where we can help
For organisations with nobody to appoint internally without breaching the independence condition, the role can be covered through an outsourced NIS2 officer, with a formal mandate, access to management and documented reporting.
If you are not yet sure whether you are in scope, the CysNis platform walks through the scoping criteria step by step. If you are, a NIS2 compliance analysis with a remediation plan shows exactly what is missing. ProDefence is a cyber security auditor accredited by DNSC.
Sources
- GEO no. 155/2024, consolidated form. Art. 14, 25, 26, 58, 60 and 65.
- Law no. 124/2025, Official Gazette no. 638 of 7 July 2025, point 4 of the single article.
- Requirements approved by Order of the DNSC director no. 1/2025, art. 5 para. (2) letter c), the details of the responsible person.
- Rules on the authorisation of cyber security training providers, approved by DNSC Order no. 106/2022, Official Gazette no. 1076 of 8 November 2022.
- Romanian Classification of Occupations, base group 2529 and group 1330.
This material is informative and does not constitute legal advice. Quotations from the Romanian acts are working translations. The status of training programmes may change through later normative acts; check dnsc.ro before contracting a course.
Frequently asked questions
What does NIS officer mean in Romania?
It is the market name for the officer responsible for the security of networks and information systems, a role set out in art. 14 para. (3) of GEO no. 155/2024. The person implements and supervises the cyber security risk management measures at entity level and is appointed by decision of the management bodies.
Is there an occupational code for the NIS officer?
No. The Romanian Classification of Occupations contains no occupation with that name. In practice, occupations in base group 2529 are used, such as 252904 cyber security expert, 252906 cyber security auditor, 252910 information systems security manager, or 133048 information security manager. The law requires no particular code.
Does DNSC license the NIS officer?
No. DNSC attests cyber security auditors and authorises training providers for auditors and CSIRT teams, under art. 25 and 58. There is no licensing, attestation or registration of the officer responsible for the security of networks and information systems.
What training must the NIS officer complete?
For a person appointed in an essential entity outside the exceptions, art. 14 para. (4) letter e) requires an accredited specialist course recognised by DNSC, completed within 12 months of appointment. The Responsabil NIS training programme has been discontinued, with no completion certificates issued for programmes organised after 1 March 2026, and no act defining an alternative recognised course had been published as at the date of this article.
How soon must the officer be appointed?
Within 30 days of the communication of the DNSC director’s decision on identification and entry in the register, under art. 14 para. (3). The deadline does not run from a fixed calendar date.
Can the head of IT be the NIS officer?
In essential entities outside the exceptions in art. 14 para. (4), no. The text requires the person to operate independently of the IT and operational technology functions and to report directly to the management bodies. For important entities, public administration, micro and small enterprises, those conditions do not apply.
Can the NIS officer role be outsourced?
The law neither prohibits nor expressly regulates it. Outsourcing works if the formal mandate secures the five conditions in art. 14 para. (4). Accountability nevertheless stays with the management bodies under art. 14 para. (1) and does not transfer to the provider.


