Romania’s first NIS2 fine: 50,000 lei for failing to register, not for incidents
On 29 September 2026, Romania’s National Cyber Security Directorate (DNSC) issued the first ever penalty under GEO no. 155/2024, the national transposition of NIS2. The fine is 50,000 lei, roughly 10,000 euro, and it went to a legal person described as a specialised body of the central public administration, covered by sector 10, Public administration, in Annex no. 1 to the ordinance. The legal basis cited by DNSC is art. 60 para. (1) letter o).
The press release, published on 30 September and carried by the national news agency, says the entity „failed to observe the notification obligation within the legal deadline”. Part of the press rendered that as a failure to report incidents. The text of the law says something else, and the difference matters for every entity in scope.
What letter o) actually says
„failure by entities in the sectors listed in Annexes no. 1 and 2 to comply with the notification obligation under art. 18 para. (2) within the indicated deadline”
The cross-reference is to art. 18 para. (2), which sits in Chapter IV, titled „Registration”. That article requires entities in the Annex 1 and Annex 2 sectors to notify DNSC for the purpose of registration in the register of entities, within 30 days of the ordinance entering into force, or of the date on which its provisions become applicable to them.
Incident reporting lives in a different chapter and a different article: art. 15, with 24 hours for the early warning, 72 hours for the incident notification and one month for the final report. Failing those obligations is penalised under other letters of art. 60 para. (1), not under letter o).
Romania’s first NIS2 fine is therefore not a fine for an undeclared incident. It is a fine because an entity did not register with the authority in time.
The two notifications people confuse
| Criterion | Registration notification | Incident notification |
|---|---|---|
| Legal basis | art. 18 para. (2) | art. 15 |
| When | once, on entering scope, plus updates | for every incident with significant impact |
| Deadline | 30 days | 24 hours, 72 hours, final report at one month |
| Where | the NIS2@RO platform, or e-mail or filing at the DNSC office | DNSC, through the incident reporting channels |
| Offence | art. 60 para. (1) letter o) | other letters of art. 60 para. (1) |
Why 50,000 lei
The amount is neither arbitrary nor maximal. Art. 60 para. (2) sets different ranges depending on the letter breached and on the status of the entity. For letter o), the ranges are:
- important entities: from 1,000 to 300,000 lei;
- essential entities: from 1,500 to 500,000 lei.
The sanctioned entity is a central public administration institution. Under art. 5 para. (1) letter a), central public administration entities listed in Annex no. 1 are essential entities regardless of size. The applicable range is therefore 1,500 to 500,000 lei, and 50,000 lei is about one tenth of the ceiling.
The contrast with the other ranges in the same article is worth keeping in mind. For breaches treated as serious, art. 60 para. (2) letters a) and b) reach up to 7,000,000 euro or 1.4 per cent of total worldwide annual turnover for important entities, and 10,000,000 euro or 2 per cent for essential ones, whichever is higher. Failure to register sits on the lower tier. That is not where the real financial exposure is.
Who establishes the offence
Art. 61 para. (2), as amended by Law no. 124/2025, splits the competences. For offences under letters o) to dd), the offence is established by DNSC and the penalty is applied by decision of the DNSC director. For other letters, control staff of the sectoral competent authorities may also establish the offence.
That explains the wording in the press release, a „decision establishing the offence and applying the penalty”. It is not an inspection report drawn up by a sectoral inspector, it is an act of the head of the authority.
What this means for everyone else
The ordinance entered into force on 31 December 2024. For entities already in scope at that date, the 30 day deadline expired on 30 January 2025. For an entity entering scope later, because it crosses a size threshold, changes its activity or is identified under art. 9, the deadline runs from the date on which the provisions become applicable to it.
Two practical consequences, frequently ignored:
- The obligation does not lapse when the deadline passes. An entity that failed to notify in January 2025 has not escaped the obligation. It still has it, and the delay remains punishable.
- The authority does not come looking for you first. Scope is self-assessed. The law provides for no list that the authority sends out to companies, and until the registration decision arrives, the entity is the one that has to know its own status.
The first fine went to a public institution. That is not a sign that the private sector is less exposed. It is, most likely, a sign of where the authority has immediate visibility.
What to check this week
- Whether your organisation operates in one of the sectors in Annex no. 1 or no. 2 to GEO no. 155/2024.
- Whether the registration notification was actually sent, and whether you hold the acknowledgement from DNSC. Do not assume: ask for the document.
- Whether the data submitted is still current. Changes to identification information must be communicated within two weeks of the change.
- Whether the entity has enrolled on the NIS2@RO platform, if the initial notification was made by e-mail or on paper.
- Whether the officer responsible for the security of networks and information systems has been appointed, within 30 days of DNSC communicating the registration decision.
- Whether an internal incident reporting procedure exists, and whether someone can trigger it within 24 hours, including at night and at weekends.
Where we can help
If you are not certain whether you fall within the scope of the ordinance, the CysNis platform walks through the scoping criteria step by step and separates legal obligations from technical recommendations.
If you are in scope and want to know how far you are from the requirements, the starting point is a NIS2 compliance analysis with a remediation plan, built on evidence rather than statements. ProDefence is a cyber security auditor accredited by DNSC. For organisations with no one to appoint internally, the role can be covered through an outsourced NIS2 officer.
Sources
- GEO no. 155/2024, published in the Official Gazette no. 1332 of 31 December 2024, consolidated text on the Romanian Legislative Portal. Art. 5, 15, 18, 60 and 61.
- Law no. 124/2025 approving GEO no. 155/2024, published in the Official Gazette no. 638 of 7 July 2025, text on the Legislative Portal.
- DNSC, press release of 30 September 2026 on the first penalty for failure to comply with the notification obligation, dnsc.ro.
- Agerpres, carried by G4Media, 30 September 2026.
- Order of the DNSC director no. 1/2025 on the requirements for the registration notification, Official Gazette no. 776 of 20 August 2025, the requirements.
This material is informative and does not constitute legal advice. The amount of the fine and the status of the sanctioned entity come from the DNSC press release as carried by the national news agency. DNSC did not publish the name of the entity. Quotations from the ordinance are working translations of the Romanian text.
Frequently asked questions
What was Romania’s first NIS2 fine issued for?
For failing to comply with the notification obligation for registration in the register of entities, set out in art. 18 para. (2). The penalty is grounded in art. 60 para. (1) letter o), which refers expressly to that article. The fine is 50,000 lei and was applied on 29 September 2026 to a specialised body of the central public administration.
Is the fine about an unreported incident?
No. Incident reporting is governed by art. 15, with deadlines of 24 hours, 72 hours and one month, and breaches of it are penalised under other letters of art. 60 para. (1). Letter o), cited by DNSC, concerns only the registration notification.
How large can the fine be for failing to register with DNSC?
Under art. 60 para. (2), from 1,000 to 300,000 lei for important entities and from 1,500 to 500,000 lei for essential entities. The 50,000 lei fine falls in the second range, because central public administration entities listed in Annex no. 1 are essential entities regardless of size under art. 5 para. (1) letter a).
We missed the 30 day registration deadline. What now?
The obligation does not lapse when the deadline passes. The notification should still be filed, through the NIS2@RO platform or, if the platform is unavailable, through the other channels set out in Order of the DNSC director no. 1/2025. The delay remains punishable, but a notification filed on your own initiative is a better position than one established during an inspection.
Who establishes the offence and how is it challenged?
For offences under letters o) to dd), the offence is established by DNSC and the penalty applied by decision of the DNSC director, under art. 61 para. (2). Challenges follow the general regime for administrative offences; the remedy, the deadline and the competent court are stated in the decision itself.
How do I know whether my organisation has to register?
Scope is self-assessed, based on the sector listed in Annexes no. 1 and 2 and the size thresholds in art. 8, which refer to Law no. 346/2004. Some entities are in scope regardless of size, under art. 9. The authority does not send out a list of the companies concerned.


