The NIS officer in Romania: duties, appointment, training and what DNSC does not certify

The NIS officer under Romanian law, duties and training

„NIS officer” is not a legal title in Romania. In GEO no. 155/2024 the role is called the officer responsible for the security of networks and information systems, and DNSC orders also use „the person responsible for cyber security”. The short name caught on through the training market. Around it, three false claims circulate: that a dedicated occupational code exists, that the officer is licensed by the authority, and that the role is solved by attending a course.

What the law actually says

The basis is art. 14 para. (3), as amended by Law no. 124/2025. The management bodies of essential and important entities establish permanent means of contact, allocate the necessary resources and appoint, within 30 days of the communication of the DNSC director’s decision on identification and entry in the register, the officers responsible for the security of networks and information systems.

Two things to keep in mind. The deadline does not run from a fixed calendar date, it runs from the communication of the DNSC decision. And the obligation covers both categories of entity, not only essential ones, a point we covered separately in the article on the appointment obligation for important entities.

The conditions in para. (4), and who they apply to

Art. 14 para. (4) adds five cumulative conditions, but only for the person appointed in essential entities, excluding public administration entities, micro enterprises and small enterprises:

  • holds managerial authority;
  • reports directly to the management bodies of the entity;
  • operates independently of the IT and operational technology functions;
  • has access to the resources needed to supervise and implement the measures effectively;
  • has completed an accredited specialist course in cyber security, recognised by DNSC, within 12 months of appointment.

Independence from IT is the condition most often breached in practice. Appointing the head of IT as the responsible officer, in an essential entity that does not fall within the exceptions, does not satisfy para. (4) letter c). Not because the person is unsuitable, but because nobody supervises themselves.

Occupational code: there is no dedicated one

The Romanian Classification of Occupations contains no occupation called „NIS officer” or „officer responsible for the security of networks and information systems”. What is used in practice are occupations in base group 2529, specialists in databases and networks:

CodeOccupation
252904Cyber security expert
252906Cyber security auditor
252907Cyber security consultant
252908ICT security administrator
252910Information systems security manager
252913Specialist in information systems security procedures and tools
133048Information security manager (CISO), group 1330

Job descriptions circulating online give „code 252913, cyber security specialist”. The title is wrong: 252913 is „specialist in information systems security procedures and tools”. If the wrong title reaches the personnel file, correcting it later costs more.

The practical conclusion: pick the code by the real content of the position, not by the „NIS” label. The law requires no particular code.

There is no „DNSC licensed NIS officer”

This is the most frequent and most misunderstood question. DNSC does not license, attest or register the responsible person. The arguments are in the text of the ordinance:

  • Art. 25 lists the tasks of DNSC. Letter j) covers issuing, revoking and renewing attestations for cyber security auditors. Letter k) covers authorising training service providers for auditors and CSIRT teams. The officer responsible for network security does not appear.
  • Art. 58 regulates the attestation of auditors only.
  • Art. 65 para. (1) lists the orders the DNSC director must issue. None concerns attestation of the responsible officer.

The closest reference is art. 26 para. (2), under which DNSC ensures the evaluation of the training and specialisation process for auditors, CSIRT team members, cyber security officers and training providers. That is a task about the training process, not an attestation of the person.

What did exist is something else: a Responsabil NIS training programme, delivered by providers authorised under DNSC Order no. 106/2022, with a certificate recognised by DNSC. That programme has been discontinued. According to the DNSC announcement, from 1 March 2026 no completion certificates are issued for programmes organised after that date.

The regulatory gap, stated plainly

Art. 14 para. (4) letter e) requires an „accredited specialist course, recognised by DNSC”. Order no. 106/2022 was issued under Law no. 362/2018, repealed by GEO no. 155/2024, and under the new law the authorisation of training providers covers only auditors and CSIRT teams. The programme dedicated to the responsible officer has been discontinued, and no act defining which course is „recognised by DNSC” for this role had been published as at the date of this article.

The result: the obligation exists, the mechanism to satisfy it does not. For an entity inside the 12 month window, the reasonable course is to document what training the appointed person completed, from whom, with what content and with what certificate, and to keep the evidence. In an inspection, serious documented training is a better position than none, and the impossibility of obtaining a certificate that does not exist is not attributable to the entity.

Be careful with offers that still use the „DNSC authorised” label for NIS officer courses. Ask the provider, in writing, for the authorisation number, the programme it covers and its validity date.

Can the role be outsourced?

The law says nothing about outsourcing, neither permitting nor prohibiting it. Art. 14 para. (3) uses the verb „appoints”, without requiring employee status. The real constraints come from the five conditions in para. (4): managerial authority, direct reporting to management, independence from IT and OT, access to resources, training.

An external provider can meet those conditions only through a formal mandate, with access and authority written into the appointment decision, not through an ordinary consultancy contract. And whatever the arrangement, accountability stays with the management bodies: art. 14 para. (1) makes them responsible for breaches. There is no transfer of liability to the appointed person or to the provider.

What is penalised

Letter of art. 60 para. (1)Conduct
h)members of management bodies do not attend the training required by art. 14 para. (2)
i)failure to establish permanent means of contact
j)failure to allocate resources
k)failure to appoint the officers responsible for the security of networks and information systems

All four sit in the upper fine range of art. 60 para. (2) letters a) and b): from 5,000 lei up to 7,000,000 euro or 1.4 per cent of total worldwide annual turnover for important entities, and from 10,000 lei up to 10,000,000 euro or 2 per cent for essential ones, whichever is higher. By comparison, failure to register with DNSC, for which the first fine was issued, sits on the lower tier.

The checklist

  1. Is there a written appointment decision, dated and signed by the management body?
  2. Does it fall within 30 days of the communication of the DNSC registration decision?
  3. For essential entities outside the exceptions, are all five conditions in para. (4) met, including independence from IT?
  4. Have the person’s details been communicated to DNSC, through the registration form or an update within two weeks of a change?
  5. Is there a job description with real duties, not just a line on an organisation chart?
  6. Is there evidence of training and a plan for the 12 month deadline?
  7. Does the person have unfiltered access to management, and a budget?

Where we can help

For organisations with nobody to appoint internally without breaching the independence condition, the role can be covered through an outsourced NIS2 officer, with a formal mandate, access to management and documented reporting.

If you are not yet sure whether you are in scope, the CysNis platform walks through the scoping criteria step by step. If you are, a NIS2 compliance analysis with a remediation plan shows exactly what is missing. ProDefence is a cyber security auditor accredited by DNSC.

Sources

This material is informative and does not constitute legal advice. Quotations from the Romanian acts are working translations. The status of training programmes may change through later normative acts; check dnsc.ro before contracting a course.

Frequently asked questions

What does NIS officer mean in Romania?

It is the market name for the officer responsible for the security of networks and information systems, a role set out in art. 14 para. (3) of GEO no. 155/2024. The person implements and supervises the cyber security risk management measures at entity level and is appointed by decision of the management bodies.

Is there an occupational code for the NIS officer?

No. The Romanian Classification of Occupations contains no occupation with that name. In practice, occupations in base group 2529 are used, such as 252904 cyber security expert, 252906 cyber security auditor, 252910 information systems security manager, or 133048 information security manager. The law requires no particular code.

Does DNSC license the NIS officer?

No. DNSC attests cyber security auditors and authorises training providers for auditors and CSIRT teams, under art. 25 and 58. There is no licensing, attestation or registration of the officer responsible for the security of networks and information systems.

What training must the NIS officer complete?

For a person appointed in an essential entity outside the exceptions, art. 14 para. (4) letter e) requires an accredited specialist course recognised by DNSC, completed within 12 months of appointment. The Responsabil NIS training programme has been discontinued, with no completion certificates issued for programmes organised after 1 March 2026, and no act defining an alternative recognised course had been published as at the date of this article.

How soon must the officer be appointed?

Within 30 days of the communication of the DNSC director’s decision on identification and entry in the register, under art. 14 para. (3). The deadline does not run from a fixed calendar date.

Can the head of IT be the NIS officer?

In essential entities outside the exceptions in art. 14 para. (4), no. The text requires the person to operate independently of the IT and operational technology functions and to report directly to the management bodies. For important entities, public administration, micro and small enterprises, those conditions do not apply.

Can the NIS officer role be outsourced?

The law neither prohibits nor expressly regulates it. Outsourcing works if the formal mandate secures the five conditions in art. 14 para. (4). Accountability nevertheless stays with the management bodies under art. 14 para. (1) and does not transfer to the provider.

Skip to content