NIS and NIS2 legislation hub

NIS2 Directive in Romania: the complete legislation

Every legal act on the security of networks and information systems in Romania, from the first NIS Directive to the latest DNSC orders and decisions. Each act links directly to its official text on the Ministry of Justice legislative portal.

Romanian acts indexed82
EU acts11
Competent authorityDNSC
Last checked8 October 2026

How to read this page. Romanian legal acts are published only in Romanian; the English titles and summaries here are our working translations and have no official value. Each card also shows the Romanian title, for citing and searching.

“Consolidated version” includes all later amendments and is the working text. “Original version” is the initial text as published in the Official Gazette (Monitorul Oficial). Abbreviations: GEO = Government Emergency Ordinance (OUG), GO = Government Ordinance (OG), GD = Government Decision (HG), DNSC = National Cyber Security Directorate.

Search by number, year, issuer or topic (e.g. “order 1 2026”, “auditors”, “ANCOM”).

00Timeline

The main milestones, from the NIS Directive to the implementing acts of GEO 155/2024.

  1. Directive (EU) 2016/1148 (NIS)First common EU framework
  2. Law No. 362/2018NIS transposed in Romania
  3. GEO No. 104/2021DNSC established
  4. Directive (EU) 2022/2555 (NIS2)The new EU framework
  5. GEO No. 155/2024NIS2 transposed
  6. Law No. 124/2025GEO 155/2024 approved
  7. DNSC Orders 1 and 2/2025Registration, thresholds, risk
  8. DNSC Order 3/2025Supervision and control
  9. DNSC Order 1/2026Measures and self-assessment
  10. Order 2/2026, Decision 3/2026Supplements, groups

01Obligations: where they are written

For each obligation of essential and important entities, the article of GEO 155/2024 and the DNSC act that details it. The table summarises the legal text; for compliance, refer to the full act.

ObligationWhat it requiresGEO 155/2024Implementing act
Scope checkEssential entity (art. 5) or important entity (art. 6), by sector (Annexes 1 and 2) and size (art. 7-9).art. 5-9, Annexes 1-2DNSC Order No. 2/2025
DNSC Decision No. 3/2026 (groups)
Notification for registrationWithin 30 days of the date the ordinance becomes applicable to the entity, through the NIS2@RO Platform or, if it is unavailable, with the NIS2@RO Tool.art. 18(2), (3), (9)DNSC Order No. 1/2025
Updating the dataChanges are communicated within 2 weeks (identification, contact and sector data) or 3 months (other information).art. 18(8)DNSC Order No. 1/2025
Risk-level assessmentSent to DNSC within 60 days of notification of the registration decision.art. 10(2), art. 18(6)DNSC Order No. 2/2025
Risk-management measuresProportionate technical, operational and organisational measures, at least those listed in art. 13.art. 11-13DNSC Order No. 1/2026
DNSC Order No. 2/2026
Maturity self-assessmentThe first within 60 days of sending the risk assessment, then yearly. Essential entities submit a remediation plan within 30 days.art. 12(4)-(5), art. 18(7)DNSC Order No. 1/2026
Role of managementManagement bodies approve the measures, oversee their implementation, are liable for infringements and attend accredited training.art. 14(1)-(2)Draft DNSC decision (in progress)
Security officerAppointed by management within 30 days of notification of the registration decision.art. 14(3)-(4)no dedicated implementing act
Incident reportingEarly warning within 24 hours, notification within 72 hours, final report within one month, through PNRISC.art. 15DNSC Order No. 100/2024 (PNRISC)
Security auditPeriodic, under the conditions and frequency set by DNSC order, according to the risk level; ad hoc at DNSC's request. The auditor must be certified by DNSC.art. 11(5), art. 57-58SGG Order No. 559/2021 (earlier regulation on auditors)
Supervision and controlDNSC may request information, carry out inspections and order measures, including an ad hoc audit.art. 46-50DNSC Order No. 3/2025
PenaltiesFines that differ by type of entity and by infringement; DNSC establishes the infringement.art. 60-61no dedicated implementing act

Fines (art. 60(2))

InfringementsEssential entitiesImportant entities
First-tier infringements (art. 60(2)(a) and (b))from RON 10,000 to EUR 10 million or 2% of worldwide turnoverfrom RON 5,000 to EUR 7 million or 1.4% of worldwide turnover
Second tier, including notification for registration (art. 60(2)(c) and (d))from RON 1,500 to RON 500,000from RON 1,000 to RON 300,000

For fines expressed in euro, the higher of the fixed amount and the percentage of total worldwide annual turnover in the preceding financial year applies (art. 60(2)-(3)). Other infringements carry a fine from RON 1,000 to RON 100,000 (point (e)).

02Deadline chain for each entity

The steps an entity goes through once it falls under GEO 155/2024, with the deadline for each and the moment from which it runs.

  1. 30 days
    Notification for registrationfrom the date the ordinance becomes applicable to the entity (art. 18(2))
  2. 60 / 150 days
    DNSC decision on registration60 days for essential entities, 150 for important ones, from notification (art. 18(4)-(5))
  3. 30 days
    Appointing the security officerfrom notification of the DNSC decision (art. 14(3))
  4. 60 days
    Risk-level assessmentfrom notification of the DNSC decision (art. 18(6))
  5. 60 days
    First maturity self-assessmentfrom sending the risk assessment (art. 18(7)), then yearly (art. 12(4))
  6. 30 days
    Remediation planessential entities only, from completing the self-assessment (art. 12(5))

Register data is updated within 2 weeks or 3 months of a change (art. 18(8)), and significant incidents are reported within 24 hours, 72 hours and one month (art. 15(7)).

03Incident reporting: DNSC and ANSPDCP

A security incident can trigger two reporting obligations, under the NIS2 regime and under the GDPR. The comparison below shows the differences.

One incident, two obligations. A significant incident that also affects personal data is reported separately to DNSC and to ANSPDCP, the Romanian data protection authority. DNSC in turn informs ANSPDCP when it finds aspects affecting data protection (art. 62 of GEO 155/2024).

NIS2: GEO 155/2024, art. 15GDPR: Regulation (EU) 2016/679, art. 33-34
What is reportedIncidents with a significant impact on services (art. 15(1) and (6))Personal data breaches (art. 33)
To whomThe national incident response team (DNSC), through PNRISCANSPDCP, the supervisory authority
Deadlines24 hours early warning, 72 hours notification, final report within one month; 6 hours for information on cross-border impact; 24 hours for trust service providers72 hours after becoming aware, where the breach is likely to result in a risk to individuals
Who else must be informedRecipients of the services, where the incident may affect them (art. 15(1) and (5))Data subjects, where the risk is high (art. 34)
Who is responsibleThe essential or important entityThe data controller

on the protection of natural persons with regard to the processing of personal data; art. 33 (notification to the supervisory authority) and art. 34 (communication to the data subject)

European Parliament and CouncilOJ L 119 of 4 May 2016

Law

Law No. 190/2018

Personal data

on measures implementing Regulation (EU) 2016/679

Romanian title: Legea nr. 190/2018 privind măsuri de punere în aplicare a Regulamentului (UE) 2016/679

Parliament of RomaniaOfficial Gazette No. 651 of 26 July 2018

The national framework implementing the GDPR; the supervisory authority is ANSPDCP.

04EU framework

The EU acts on which national legislation is based, including sectoral rules for electricity and aviation. Under art. 4 of the NIS2 Directive, where a sector-specific Union act imposes requirements at least equivalent in effect, the corresponding NIS2 provisions do not apply. The links point to the English version on EUR-Lex.

EU

Directive (EU) 2022/2555 (NIS2)

Transposed by GEO 155/2024

on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148

European Parliament and CouncilOJ L 333 of 27 December 2022

laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered significant, for digital service and digital infrastructure providers

European CommissionOJ L of 18 October 2024

05NIS2 in Romania: the core act

The emergency ordinance transposing the NIS2 Directive and the laws that approved and supplemented it. For the text applicable today, use the consolidated version.

GEO

GEO No. 155/2024

NIS2 transposition act

on establishing a framework for the cybersecurity of networks and information systems in the national civilian cyberspace

Romanian title: OUG nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil

Government of RomaniaOfficial Gazette No. 1332 of 31 December 2024

The act transposing the NIS2 Directive. It defines essential and important entities, the obligations on registration, risk management and incident reporting, supervision and penalties. It repealed Law No. 362/2018 (art. 66).

Law

Law No. 124/2025

Approval with amendments

approving Government Emergency Ordinance No. 155/2024

Romanian title: Legea nr. 124/2025 pentru aprobarea Ordonanței de urgență a Guvernului nr. 155/2024

Parliament of RomaniaOfficial Gazette No. 638 of 7 July 2025

Approves GEO 155/2024 with amendments (art. 2, 3, 4, 14, 15, 18, 20, 23, 36, 37, 47, 50, 60, 61, 67 and Annexes 1 and 2).

Law

Law No. 123/2026

Supplement

supplementing art. 36 of GEO No. 155/2024 and supplementing Law No. 286/2009 on the Criminal Code

Romanian title: Legea nr. 123/2026 pentru completarea art. 36 din OUG nr. 155/2024, precum și pentru completarea Legii nr. 286/2009 privind Codul penal

Parliament of RomaniaOfficial Gazette No. 550 of 3 July 2026

Introduces the framework for good-faith vulnerability research: art. 36(1^1) of GEO 155/2024 and art. 365^1 of the Criminal Code.

06Implementing acts issued by DNSC

Orders and decisions of the DNSC Director issued under GEO 155/2024, in chronological order, with the annexes each approves.

Order

DNSC Order No. 1/2025

Registration

approving the Requirements on the notification process for registration and the method of transmitting information

Romanian title: Ordinul DNSC nr. 1/2025 pentru aprobarea Cerințelor privind procesul de notificare în vederea înregistrării și metoda de transmitere a informațiilor

National Cyber Security Directorate (DNSC)Official Gazette No. 776 of 20 August 2025

Issued under art. 18(9) of GEO 155/2024.

Order

DNSC Order No. 2/2025

Classification and risk

approving the Criteria and thresholds for determining the degree of disruption of a service and the Methodology for assessing the risk level of entities

Romanian title: Ordinul DNSC nr. 2/2025 pentru aprobarea Criteriilor și pragurilor de determinare a gradului de perturbare a unui serviciu și a Metodologiei privind evaluarea nivelului de risc al entităților

National Cyber Security Directorate (DNSC)Official Gazette No. 776 of 20 August 2025

Issued under art. 10(2) of GEO 155/2024. The Methodology was amended by DNSC Order No. 1/2026.

Order

DNSC Order No. 3/2025

Supervision and control

approving the Implementing Rules on supervision, verification and control of compliance with GEO No. 155/2024 and the Methodology for risk-based prioritisation of supervision, verification and control activities

Romanian title: Ordinul DNSC nr. 3/2025 pentru aprobarea Normelor de aplicare a dispozițiilor privind supravegherea, verificarea și controlul respectării prevederilor OUG nr. 155/2024 și a Metodologiei de prioritizare pe bază de risc a activităților de supraveghere, verificare și control

National Cyber Security Directorate (DNSC)Official Gazette No. 1149 of 11 December 2025

Issued under art. 47(8) of GEO 155/2024.

Order

DNSC Order No. 1/2026

Security measures

approving the Cybersecurity risk-management measures for the networks and information systems used by essential and important entities and the Methodology for self-assessing the maturity of cybersecurity risk-management measures, and amending the Methodology for assessing the risk level of entities

Romanian title: Ordinul DNSC nr. 1/2026 pentru aprobarea Măsurilor de gestionare a riscurilor de securitate cibernetică aferente rețelelor și sistemelor informatice utilizate de entitățile esențiale și importante și a Metodologiei de autoevaluare a maturității măsurilor de gestionare a riscurilor de securitate cibernetică și pentru modificarea Metodologiei privind evaluarea nivelului de risc al entităților

National Cyber Security Directorate (DNSC)Official Gazette No. 712 and 712 bis of 27 August 2026

Issued under art. 12 of GEO 155/2024. The annexes were published in Official Gazette No. 712 bis. Supplemented by DNSC Order No. 2/2026.

Order

DNSC Order No. 2/2026

Supplement

supplementing DNSC Director's Order No. 1/2026

Romanian title: Ordinul DNSC nr. 2/2026 privind completarea Ordinului directorului DNSC nr. 1/2026

National Cyber Security Directorate (DNSC)Official Gazette No. 792 of 18 September 2026

Supplements Order No. 1/2026; the change is included in its consolidated version.

Decision

DNSC Decision No. 3/2026

Groups of undertakings

approving the Rules on the applicability of cybersecurity requirements to entities that are part of a group of undertakings

Romanian title: Decizia DNSC nr. 3/2026 pentru aprobarea Normelor de aplicabilitate a cerințelor de securitate cibernetică pentru entitățile care fac parte dintr-un grup de întreprinderi

National Cyber Security Directorate (DNSC)Official Gazette No. 798 of 21 September 2026

Clarifies how the requirements apply to each entity within a group.

07Status of the acts required by art. 65

Article 65 of GEO 155/2024 lists the acts DNSC must issue. The table shows what has been published in the Official Gazette, what exists only as a draft on dnsc.ro and what is still missing.

4 of 14 acts published
Art. 65What is approvedLegal basisStatus
para. (1)(a)Criteria and thresholds for the degree of disruption and the risk-level assessment methodologyart. 10(2)DNSC Order No. 2/2025
para. (1)(b)Risk-management measuresart. 12(1)DNSC Order No. 1/2026
para. (1)(c)Methodological rules on incident reportingart. 15(17)Not published; no draft on dnsc.ro
para. (1)(d)Requirements on notification for registration and the method of transmitting informationart. 18(9)DNSC Order No. 1/2025
para. (1)(e)National peacetime cybersecurity crisis management planart. 28(2)Not published; no draft on dnsc.ro
para. (1)(f)Technical rules on CSIRT compatibility and interoperability and criteria for qualified staffart. 31(2)Not published; no draft on dnsc.ro
para. (1)(g)Minimum package of CSIRT servicesart. 32(5)Not published; no draft on dnsc.ro
para. (1)(h)Regulation on the authorisation and verification of CSIRTs and staff training curriculaart. 34(2)(a)Not published; no draft on dnsc.ro
para. (1)(i)Implementing rules and risk-based prioritisation methodology for supervision, verification and controlart. 47(8)DNSC Order No. 3/2025
para. (1)(j)Regulation on the authorisation of training providers for auditors and CSIRTsart. 54(3)Draft published by DNSC, not adopted
para. (1)(k)Rules on the supervision and control of CSIRTs, CSIRT service providers and auditorsart. 56(2)Not published; no draft on dnsc.ro
para. (1)(l)Regulation on the certification and verification of cybersecurity auditorsart. 58(2)(b)Not published; no draft on dnsc.ro
para. (2)(a)Specialisation curricula for auditors seeking certification (DNSC decision)art. 58(2)(e)Not published; no draft on dnsc.ro
para. (2)(b)Specialisation curricula for CSIRT staff seeking authorisation (DNSC decision)art. 31(3)Not published; no draft on dnsc.ro

08In progress: DNSC drafts and bills in Parliament

Acts not yet adopted or published in the Official Gazette, identified on the DNSC decision-making transparency page and in the Chamber of Deputies legislative tracking system. The final text may differ from the draft.

Draft

Draft DNSC order: training providers

Draft, not adopted

approving the Regulation on the authorisation, verification and revocation of cybersecurity training providers and the validity conditions of their authorisations

Romanian title: Proiect de ordin DNSC: furnizorii de formare

National Cyber Security Directorate (DNSC)DNSC decision-making transparency page, document of June 2026

Corresponds to art. 65(1)(j) of GEO 155/2024. The authorisation of training providers was previously regulated by DNSC Order No. 106/2022.

Draft

Draft DNSC decision: management training

Draft, not adopted

approving the training standard for members of the management bodies of essential and important entities and the list of cybersecurity certifications

Romanian title: Proiect de decizie DNSC: pregătirea conducerii

National Cyber Security Directorate (DNSC)DNSC decision-making transparency page, document of December 2025

Concerns the training of management bodies required by GEO 155/2024. Not found in the Official Gazette.

Bill

PL-x 20/2026: DNSC membership fees for FIRST and TF-CSIRT

Favourable report, plenary next

Bill approving the payment of DNSC's membership fees to the Forum of Incident Response and Security Teams (FIRST) and to the TF-CSIRT Trusted Introducer (TI)

Romanian title: PL-x 20/2026: cotizațiile DNSC la FIRST și TF-CSIRT

Parliament of RomaniaSenate L558/2025, Chamber of Deputies PL-x 20/2026 (deciding chamber)

Adopted by the Senate; in the Chamber of Deputies it received a favourable report on 24 September 2026. Law No. 146/2014, which authorised the CERT-RO fees, was repealed by art. 66 of GEO 155/2024.

Bill

PL-x 409/2026: CSIRT for the energy sector

In Chamber committees

Bill on establishing and operationalising the Cybersecurity Incident Response Centre for Energy and amending and supplementing certain legal acts

Romanian title: PL-x 409/2026: CSIRT pentru sectorul energetic

Parliament of RomaniaSenate L214/2026, Chamber of Deputies PL-x 409/2026

Adopted by the Senate; in the Chamber of Deputies, the deciding chamber, it is in committee (latest opinion received on 15 September 2026).

Legislative proposal supplementing Government Emergency Ordinance No. 155/2024 on establishing a framework for the cybersecurity of networks and information systems in the national civilian cyberspace

Romanian title: BP 610/2026: completarea OUG 155/2024

Parliament of Romania (9 deputies)Registered on 29 July 2026

Sent to the Senate, as first chamber, on 1 September 2026; the Chamber of Deputies is the deciding chamber.

09Related acts linked to NIS2

Sectoral or parallel rules that refer to GEO 155/2024 or apply to the same entities: electronic communications, critical entities, the financial sector, trust services.

Decision

ANCOM Decision No. 70/2024

Electronic communications

on the security of public electronic communications networks and publicly available electronic communications services

Romanian title: Decizia ANCOM nr. 70/2024 privind securitatea rețelelor publice de comunicații electronice și a serviciilor de comunicații electronice destinate publicului

National Authority for Management and Regulation in Communications (ANCOM)Official Gazette No. 117 of 9 February 2024

Under art. 64(1) of GEO 155/2024, the measures adopted by this decision remain in force until they are reviewed.

Law

Law No. 294/2024

Critical entities (CER)

on the resilience of critical entities and amending certain legal acts

Romanian title: Legea nr. 294/2024 privind reziliența entităților critice, precum și pentru modificarea unor acte normative

Parliament of RomaniaOfficial Gazette No. 1189 of 29 November 2024

Transposes Directive (EU) 2022/2557. The NIS2 Directive (art. 3(1)(f)) treats critical entities identified under CER as essential entities.

GD

GD No. 1115/2025

Critical entities (CER)

approving the rules, procedures and measures provided for in art. 1(3) of Law No. 294/2024

Romanian title: HG nr. 1115/2025 pentru aprobarea normelor, procedurilor și măsurilor prevăzute la art. 1 alin. (3) din Legea nr. 294/2024

Government of RomaniaOfficial Gazette No. 1214 of 30 December 2025

Decision

Prime Minister's Decision No. 266/2026

Critical entities (CER)

approving the List of critical entities identified under art. 6(1) of Law No. 294/2024

Romanian title: Decizia prim-ministrului nr. 266/2026 pentru aprobarea Listei entităților critice identificate în temeiul art. 6 alin. (1) din Legea nr. 294/2024

Prime MinisterOfficial Gazette No. 603 of 23 July 2026

GEO

GEO No. 14/2026

Financial sector (DORA)

establishing measures implementing Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)

Romanian title: OUG nr. 14/2026 privind stabilirea unor măsuri de punere în aplicare a Regulamentului (UE) 2022/2554 privind reziliența operațională digitală a sectorului financiar (DORA)

Government of RomaniaOfficial Gazette No. 188 of 11 March 2026

Law

Law No. 119/2026

Public digital infrastructure

on the records and management of public digital infrastructure and the creation of the National Public Digital Infrastructure Platform

Romanian title: Legea nr. 119/2026 privind evidența și administrarea infrastructurii digitale publice, precum și crearea Platformei naționale a infrastructurii digitale publice

Parliament of RomaniaOfficial Gazette No. 550 of 3 July 2026

Refers to GEO 155/2024.

Decision

ADR Decision No. 162/2026

Trust services

on the procedures for notification, granting of status, entry in and removal from the register, and supervision of trust service providers (eIDAS Regulation)

Romanian title: Decizia ADR nr. 162/2026 privind procedurile de notificare, acordare a statutului, înscriere, radiere și supraveghere a prestatorilor de servicii de încredere (Regulamentul eIDAS)

Romanian Digitalisation Authority (ADR)Official Gazette No. 246 and 246 bis of 30 March 2026

Trust service providers fall within the scope of NIS2 (digital infrastructure sector).

10DNSC and the national cybersecurity framework

The founding act of the competent authority, the national strategy and the Cybersecurity and Cyber Defence Law.

GEO

GEO No. 104/2021

DNSC founding act

establishing the National Cyber Security Directorate

Romanian title: OUG nr. 104/2021 privind înființarea Directoratului Național de Securitate Cibernetică

Government of RomaniaOfficial Gazette No. 918 of 24 September 2021

DNSC is the national competent authority and single point of contact for NIS2.

Law

Law No. 11/2022

Approval

approving GEO No. 104/2021

Romanian title: Legea nr. 11/2022 pentru aprobarea OUG nr. 104/2021

Parliament of RomaniaOfficial Gazette No. 25 of 7 January 2022

Law

Law No. 366/2022

Amendment

amending GEO No. 104/2021 and supplementing Annex VIII to Framework Law No. 153/2017

Romanian title: Legea nr. 366/2022 pentru modificarea OUG nr. 104/2021, precum și pentru completarea anexei nr. VIII la Legea-cadru nr. 153/2017

Parliament of RomaniaOfficial Gazette No. 1231 of 21 December 2022

Law

Law No. 58/2023

Cybersecurity and cyber defence

on Romania's cybersecurity and cyber defence and amending and supplementing certain legal acts

Romanian title: Legea nr. 58/2023 privind securitatea și apărarea cibernetică a României, precum și pentru modificarea și completarea unor acte normative

Parliament of RomaniaOfficial Gazette No. 214 of 15 March 2023

The general national framework for cybersecurity and cyber defence, separate from GEO 155/2024.

GD

GD No. 62/2024

Law 58/2023

approving the Methodological rules on requesting and communicating the data and information provided for in art. 25(1) of Law No. 58/2023

Romanian title: HG nr. 62/2024 pentru aprobarea Normelor metodologice privind solicitarea și comunicarea datelor și informațiilor prevăzute la art. 25 alin. (1) din Legea nr. 58/2023

Government of RomaniaOfficial Gazette No. 97 of 1 February 2024

Annexes and approved acts
GD

GD No. 831/2024

Law 58/2023

establishing the categories of persons provided for in art. 3(1)(c) of Law No. 58/2023

Romanian title: HG nr. 831/2024 pentru stabilirea categoriilor de persoane prevăzute la art. 3 alin. (1) lit. c) din Legea nr. 58/2023

Government of RomaniaOfficial Gazette No. 711 of 22 July 2024

11DNSC acts issued before GEO 155/2024

Orders and decisions issued by DNSC before NIS2 was transposed, under GEO 104/2021 and Law 362/2018. We keep them for context; whether each still applies must be checked against GEO 155/2024 and later DNSC acts.

Decision

DNSC Decision No. 301/2021

Before GEO 155/2024

approving the List of fees for services under the activities provided for by Law No. 362/2018

Romanian title: Decizia DNSC nr. 301/2021 privind aprobarea Listei cuantumului tarifelor pentru serviciile din activitățile prevăzute de Legea nr. 362/2018

National Cyber Security Directorate (DNSC)Official Gazette No. 2 of 3 January 2022

Order

DNSC Order No. 105/2022

Before GEO 155/2024

approving the Implementing Rules on the verification and control of compliance with cybersecurity obligations in the national civilian cyberspace

Romanian title: Ordinul DNSC nr. 105/2022 pentru aprobarea Normelor de aplicare a dispozițiilor privind verificarea și controlul îndeplinirii obligațiilor de securitate cibernetică pentru spațiul cibernetic național civil

National Cyber Security Directorate (DNSC)Official Gazette No. 1062 of 2 November 2022

Annexes and approved acts
Order

DNSC Order No. 106/2022

Before GEO 155/2024

approving the Rules on the authorisation and verification of cybersecurity training providers

Romanian title: Ordinul DNSC nr. 106/2022 pentru aprobarea Normelor privind autorizarea și verificarea furnizorilor de servicii de formare pentru securitate cibernetică

National Cyber Security Directorate (DNSC)Official Gazette No. 1076 of 8 November 2022

Decision

DNSC Decision No. 107/2022

Before GEO 155/2024

approving the curricula for training cybersecurity auditors, CSIRT team members and network and information system security officers

Romanian title: Decizia DNSC nr. 107/2022 privind aprobarea tematicilor pentru formarea auditorilor de securitate cibernetică, a membrilor echipelor CSIRT și a responsabililor cu securitatea rețelelor și sistemelor informatice

National Cyber Security Directorate (DNSC)Official Gazette No. 1146 of 29 November 2022

Order

DNSC Order No. 100/2024

Before GEO 155/2024

approving the confidentiality and transparency policies of the National Platform for Reporting Cybersecurity Incidents (PNRISC)

Romanian title: Ordinul DNSC nr. 100/2024 privind aprobarea politicilor de confidențialitate și transparență ale Platformei Naționale pentru Raportarea Incidentelor de Securitate Cibernetică

National Cyber Security Directorate (DNSC)Official Gazette No. 120 of 12 February 2024

Order

DNSC Order No. 180/2024

Before GEO 155/2024

approving the Methodology on cyber alert levels and courses of action in cyber alert situations

Romanian title: Ordinul DNSC nr. 180/2024 pentru aprobarea Metodologiei privind nivelurile de alertă cibernetică și modalitățile de acțiune în situații de alertă cibernetică

National Cyber Security Directorate (DNSC)Official Gazette No. 197 of 11 March 2024

Annexes and approved acts

12NIS1: Law 362/2018 and its implementing acts (historical)

The framework that transposed the first NIS Directive. Law 362/2018 was repealed by GEO 155/2024; measures adopted under Chapters IV and V remain in force until they are reviewed (art. 66(1)(a)).

Law

Law No. 362/2018

Repealed by GEO 155/2024

on ensuring a high common level of security of networks and information systems

Romanian title: Legea nr. 362/2018 privind asigurarea unui nivel comun ridicat de securitate a rețelelor și sistemelor informatice

Parliament of RomaniaOfficial Gazette No. 21 of 9 January 2019

The law transposing the NIS Directive. Repealed when GEO 155/2024 entered into force, except for the measures adopted under Chapters IV and V, which remain in force until reviewed (art. 66(1)(a)). References to Law 362/2018 are deemed to be made to GEO 155/2024.

GEO

GEO No. 76/2019

Deadline extension

extending certain deadlines provided for by Law No. 362/2018 and GO No. 2/2019

Romanian title: OUG nr. 76/2019 pentru prorogarea unor termene prevăzute de Legea nr. 362/2018 și de OG nr. 2/2019

Government of RomaniaOfficial Gazette No. 1023 of 19 December 2019

Order

MCSI Order No. 599/2019

OES identification

approving the Methodological rules for identifying operators of essential services and digital service providers

Romanian title: Ordinul MCSI nr. 599/2019 privind aprobarea Normelor metodologice de identificare a operatorilor de servicii esențiale și furnizorilor de servicii digitale

Ministry of Communications and Information SocietyOfficial Gazette No. 584 of 17 July 2019

Annexes and approved acts
Order

MCSI Order No. 600/2019

OES register

approving the Methodological rules on the organisation and operation of the Register of operators of essential services

Romanian title: Ordinul MCSI nr. 600/2019 privind aprobarea Normelor metodologice de organizare și funcționare a Registrului operatorilor de servicii esențiale

Ministry of Communications and Information SocietyOfficial Gazette No. 542 of 2 July 2019

Annexes and approved acts
Order

MCSI Order No. 601/2019

Disruptive effect

approving the Methodology for determining the significant disruptive effect of incidents affecting the networks and information systems of operators of essential services

Romanian title: Ordinul MCSI nr. 601/2019 pentru aprobarea Metodologiei de stabilire a efectului perturbator semnificativ al incidentelor la nivelul rețelelor și sistemelor informatice ale operatorilor de servicii esențiale

Ministry of Communications and Information SocietyOfficial Gazette No. 590 of 18 July 2019

Decision

CERT-RO Decision No. 88/2020

Standards

approving the List of European and international standards and specifications

Romanian title: Decizia CERT-RO nr. 88/2020 privind aprobarea Listei standardelor și specificațiilor europene și internaționale

CERT-ROOfficial Gazette No. 465 of 2 June 2020

GD

GD No. 963/2020

Essential services

approving the List of essential services

Romanian title: HG nr. 963/2020 pentru aprobarea Listei serviciilor esențiale

Government of RomaniaOfficial Gazette No. 1086 of 16 November 2020

GD

GD No. 976/2020

Thresholds

approving the threshold values for determining the significant disruptive effect of incidents affecting the networks and information systems of operators of essential services

Romanian title: HG nr. 976/2020 privind aprobarea valorilor de prag pentru stabilirea efectului perturbator semnificativ al incidentelor la nivelul rețelelor și sistemelor informatice ale operatorilor de servicii esențiale

Government of RomaniaOfficial Gazette No. 1089 of 17 November 2020

Order

SGG Order No. 1323/2020

Minimum requirements

approving the Technical rules on the minimum security requirements for networks and information systems applicable to operators of essential services

Romanian title: Ordinul SGG nr. 1323/2020 pentru aprobarea Normelor tehnice privind cerințele minime de asigurare a securității rețelelor și sistemelor informatice aplicabile operatorilor de servicii esențiale

General Secretariat of the GovernmentOfficial Gazette No. 1142 of 26 November 2020

GD

GD No. 1003/2020

Incident impact

approving the Technical rules for determining the impact of incidents for the categories of operators of essential services and digital service providers

Romanian title: HG nr. 1003/2020 pentru aprobarea Normelor tehnice de stabilire a impactului incidentelor pentru categoriile de operatori de servicii esențiale și furnizori de servicii digitale

Government of RomaniaOfficial Gazette No. 1223 of 14 December 2020

GD

GD No. 494/2011

Institutional, historical

establishing the National Computer Security Incident Response Centre (CERT-RO)

Romanian title: HG nr. 494/2011 privind înființarea Centrului Național de Răspuns la Incidente de Securitate Cibernetică (CERT-RO)

Government of RomaniaOfficial Gazette No. 388 of 2 June 2011

CERT-RO was replaced by DNSC through GEO 104/2021.

13Official DNSC resources

DNSC platforms, downloadable tools and official pages used in applying NIS2 legislation.

The enrolment, information and cooperation platform used for notification for registration and later interaction with DNSC (DNSC Order No. 1/2025).

The resources above are not legal acts. DNSC provides them for applying the acts on this page. The DNSC pages are in Romanian.

Downloadable tools

StageToolVersion
Notification for registrationNIS2@RO Tool, version 2.3
Generates the notification form when the NIS2@RO Platform is unavailable (art. 18 GEO 155/2024, DNSC Order No. 1/2025). Romanian interface.
RODownload
Notification for registrationNIS2@RO tool, version 2.1
English version of the tool, for people who do not speak Romanian. The form is still submitted in Romanian.
ENDownload
IdentificationGuide to the disruptive effect analysis, version 1.0
Supports the entity's self-assessment of the disruptive effect of an incident, at the identification stage. In Romanian.
GuideDownload
Risk-level assessmentENIRE@RO Tool, version 2
Generates the entity's risk-level assessment report until the platform is operational. The report is signed by the legal representative (art. 18(6)). In Romanian.
RODownload
Maturity self-assessmentEVAL_MMS_B, basic level
Self-assessment tool for the maturity of risk-management measures at the basic security level (art. 18(7)). In Romanian.
v1Download
Maturity self-assessmentEVAL_MMS_I, important level
Self-assessment tool for the important security level. The applicable level follows from the overall score obtained with ENIRE@RO and validated by DNSC.
v3Download
Maturity self-assessmentEVAL_MMS_E, essential level
Self-assessment tool for the essential security level.
v3Download

The links point directly to the files published by DNSC on dnsc.ro, checked on 8 October 2026. DNSC regularly publishes new versions; the current version is the one on the Registration of entities and Obligations of registered entities pages.

14Frequently asked questions

Short answers, with references to the legal text.

Where can I find the official text of GEO 155/2024?

The consolidated version, which includes the amendments made by Law No. 124/2025 and Law No. 123/2026, is on the Ministry of Justice legislative portal at legislatie.just.ro/Public/DetaliiDocumentAfis/311690, in Romanian. The portal also has a printable version. The text with official value is the one published in Official Gazette No. 1332 of 31 December 2024. There is no official English translation.

What did Law No. 124/2025 change?

It approved GEO 155/2024 with amendments, applicable from 10 July 2025. The amendments cover, among others, management training (art. 14), incident reporting (art. 15), notification for registration (art. 18) and penalties (art. 60-61), as well as Annexes 1 and 2.

What is the deadline for registering with DNSC?

Entities in the sectors listed in Annexes 1 and 2 that qualify as essential or important notify DNSC within 30 days of the entry into force of the ordinance or of the date it becomes applicable to them (art. 18(2)). Notification is made through the NIS2@RO Platform, under DNSC Order No. 1/2025.

What fines does GEO 155/2024 provide for?

For serious infringements, up to EUR 10 million or 2% of worldwide turnover for essential entities and up to EUR 7 million or 1.4% for important entities. For other obligations, including notification for registration, between RON 1,500 and RON 500,000, and between RON 1,000 and RON 300,000 respectively (art. 60(2)).

How often must the security audit be carried out?

GEO 155/2024 provides that the frequency is set by order of the DNSC Director, according to the risk level (art. 11(5)). As of 8 October 2026 we have not identified a published order setting it. DNSC may order an ad hoc audit at any time (art. 57).

Must an incident be reported to both DNSC and ANSPDCP?

Yes, if the significant incident also affects personal data. Reporting to DNSC follows art. 15 of GEO 155/2024, and notification to ANSPDCP follows art. 33 GDPR. They are two separate obligations, with different recipients and content.

Does NIS2 apply to every company in a group?

Obligations are assessed at the level of each entity. How they apply within groups of undertakings is explained in the Rules approved by DNSC Decision No. 3/2026.

15Changelog

What has been added or changed on this page.

  • Page published: 80 Romanian acts and 7 European acts, with the status of the acts required by art. 65.
  • Added DNSC drafts under consultation, bills in Parliament and supporting documents (explanatory notes, statements of reasons, approval reports).
  • Added the obligations table, the deadline chain, the comparison between reporting to DNSC and to ANSPDCP, sectoral EU acts, official DNSC resources and frequently asked questions.
  • Added direct download links for the DNSC tools: NIS2@RO (RO and EN), ENIRE@RO, the guide on disruptive effect and the EVAL_MMS self-assessment tools for the three levels.
  • English version published.

No act matches your search. Try the act number or the year.

Need help applying these acts?

We check whether you qualify as an essential or important entity, prepare the notification to DNSC, implement the measures in DNSC Order 1/2026 and act as your NIS2 officer.

This page is for information only. The texts with official value are those published in the Official Gazette of Romania, Part I, and in the Official Journal of the European Union.

The list was checked on 8 October 2026 on legislatie.just.ro (which reproduces the Official Gazette, Part I), on the DNSC decision-making transparency page and on cdep.ro, and is updated when new acts are published. Spotted a missing act? Write to us at [email protected].

Skip to content