NIS and NIS2 legislation hub
NIS2 Directive in Romania: the complete legislation
Every legal act on the security of networks and information systems in Romania, from the first NIS Directive to the latest DNSC orders and decisions. Each act links directly to its official text on the Ministry of Justice legislative portal.
How to read this page. Romanian legal acts are published only in Romanian; the English titles and summaries here are our working translations and have no official value. Each card also shows the Romanian title, for citing and searching.
“Consolidated version” includes all later amendments and is the working text. “Original version” is the initial text as published in the Official Gazette (Monitorul Oficial). Abbreviations: GEO = Government Emergency Ordinance (OUG), GO = Government Ordinance (OG), GD = Government Decision (HG), DNSC = National Cyber Security Directorate.
00Timeline
The main milestones, from the NIS Directive to the implementing acts of GEO 155/2024.
- Directive (EU) 2016/1148 (NIS)First common EU framework
- Law No. 362/2018NIS transposed in Romania
- GEO No. 104/2021DNSC established
- Directive (EU) 2022/2555 (NIS2)The new EU framework
- GEO No. 155/2024NIS2 transposed
- Law No. 124/2025GEO 155/2024 approved
- DNSC Orders 1 and 2/2025Registration, thresholds, risk
- DNSC Order 3/2025Supervision and control
- DNSC Order 1/2026Measures and self-assessment
- Order 2/2026, Decision 3/2026Supplements, groups
01Obligations: where they are written
For each obligation of essential and important entities, the article of GEO 155/2024 and the DNSC act that details it. The table summarises the legal text; for compliance, refer to the full act.
| Obligation | What it requires | GEO 155/2024 | Implementing act |
|---|---|---|---|
| Scope check | Essential entity (art. 5) or important entity (art. 6), by sector (Annexes 1 and 2) and size (art. 7-9). | art. 5-9, Annexes 1-2 | DNSC Order No. 2/2025 DNSC Decision No. 3/2026 (groups) |
| Notification for registration | Within 30 days of the date the ordinance becomes applicable to the entity, through the NIS2@RO Platform or, if it is unavailable, with the NIS2@RO Tool. | art. 18(2), (3), (9) | DNSC Order No. 1/2025 |
| Updating the data | Changes are communicated within 2 weeks (identification, contact and sector data) or 3 months (other information). | art. 18(8) | DNSC Order No. 1/2025 |
| Risk-level assessment | Sent to DNSC within 60 days of notification of the registration decision. | art. 10(2), art. 18(6) | DNSC Order No. 2/2025 |
| Risk-management measures | Proportionate technical, operational and organisational measures, at least those listed in art. 13. | art. 11-13 | DNSC Order No. 1/2026 DNSC Order No. 2/2026 |
| Maturity self-assessment | The first within 60 days of sending the risk assessment, then yearly. Essential entities submit a remediation plan within 30 days. | art. 12(4)-(5), art. 18(7) | DNSC Order No. 1/2026 |
| Role of management | Management bodies approve the measures, oversee their implementation, are liable for infringements and attend accredited training. | art. 14(1)-(2) | Draft DNSC decision (in progress) |
| Security officer | Appointed by management within 30 days of notification of the registration decision. | art. 14(3)-(4) | no dedicated implementing act |
| Incident reporting | Early warning within 24 hours, notification within 72 hours, final report within one month, through PNRISC. | art. 15 | DNSC Order No. 100/2024 (PNRISC) |
| Security audit | Periodic, under the conditions and frequency set by DNSC order, according to the risk level; ad hoc at DNSC's request. The auditor must be certified by DNSC. | art. 11(5), art. 57-58 | SGG Order No. 559/2021 (earlier regulation on auditors) |
| Supervision and control | DNSC may request information, carry out inspections and order measures, including an ad hoc audit. | art. 46-50 | DNSC Order No. 3/2025 |
| Penalties | Fines that differ by type of entity and by infringement; DNSC establishes the infringement. | art. 60-61 | no dedicated implementing act |
Fines (art. 60(2))
| Infringements | Essential entities | Important entities |
|---|---|---|
| First-tier infringements (art. 60(2)(a) and (b)) | from RON 10,000 to EUR 10 million or 2% of worldwide turnover | from RON 5,000 to EUR 7 million or 1.4% of worldwide turnover |
| Second tier, including notification for registration (art. 60(2)(c) and (d)) | from RON 1,500 to RON 500,000 | from RON 1,000 to RON 300,000 |
For fines expressed in euro, the higher of the fixed amount and the percentage of total worldwide annual turnover in the preceding financial year applies (art. 60(2)-(3)). Other infringements carry a fine from RON 1,000 to RON 100,000 (point (e)).
02Deadline chain for each entity
The steps an entity goes through once it falls under GEO 155/2024, with the deadline for each and the moment from which it runs.
- 30 daysNotification for registrationfrom the date the ordinance becomes applicable to the entity (art. 18(2))
- 60 / 150 daysDNSC decision on registration60 days for essential entities, 150 for important ones, from notification (art. 18(4)-(5))
- 30 daysAppointing the security officerfrom notification of the DNSC decision (art. 14(3))
- 60 daysRisk-level assessmentfrom notification of the DNSC decision (art. 18(6))
- 60 daysFirst maturity self-assessmentfrom sending the risk assessment (art. 18(7)), then yearly (art. 12(4))
- 30 daysRemediation planessential entities only, from completing the self-assessment (art. 12(5))
Register data is updated within 2 weeks or 3 months of a change (art. 18(8)), and significant incidents are reported within 24 hours, 72 hours and one month (art. 15(7)).
03Incident reporting: DNSC and ANSPDCP
A security incident can trigger two reporting obligations, under the NIS2 regime and under the GDPR. The comparison below shows the differences.
One incident, two obligations. A significant incident that also affects personal data is reported separately to DNSC and to ANSPDCP, the Romanian data protection authority. DNSC in turn informs ANSPDCP when it finds aspects affecting data protection (art. 62 of GEO 155/2024).
| NIS2: GEO 155/2024, art. 15 | GDPR: Regulation (EU) 2016/679, art. 33-34 | |
|---|---|---|
| What is reported | Incidents with a significant impact on services (art. 15(1) and (6)) | Personal data breaches (art. 33) |
| To whom | The national incident response team (DNSC), through PNRISC | ANSPDCP, the supervisory authority |
| Deadlines | 24 hours early warning, 72 hours notification, final report within one month; 6 hours for information on cross-border impact; 24 hours for trust service providers | 72 hours after becoming aware, where the breach is likely to result in a risk to individuals |
| Who else must be informed | Recipients of the services, where the incident may affect them (art. 15(1) and (5)) | Data subjects, where the risk is high (art. 34) |
| Who is responsible | The essential or important entity | The data controller |
on the protection of natural persons with regard to the processing of personal data; art. 33 (notification to the supervisory authority) and art. 34 (communication to the data subject)
European Parliament and CouncilOJ L 119 of 4 May 2016
on measures implementing Regulation (EU) 2016/679
Romanian title: Legea nr. 190/2018 privind măsuri de punere în aplicare a Regulamentului (UE) 2016/679
Parliament of RomaniaOfficial Gazette No. 651 of 26 July 2018
The national framework implementing the GDPR; the supervisory authority is ANSPDCP.
04EU framework
The EU acts on which national legislation is based, including sectoral rules for electricity and aviation. Under art. 4 of the NIS2 Directive, where a sector-specific Union act imposes requirements at least equivalent in effect, the corresponding NIS2 provisions do not apply. The links point to the English version on EUR-Lex.
on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148
European Parliament and CouncilOJ L 333 of 27 December 2022
laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered significant, for digital service and digital infrastructure providers
European CommissionOJ L of 18 October 2024
concerning measures for a high common level of security of network and information systems across the Union
European Parliament and CouncilOJ L 194 of 19 July 2016
on ENISA and on information and communications technology cybersecurity certification
European Parliament and CouncilOJ L 151 of 7 June 2019
on digital operational resilience for the financial sector, lex specialis to NIS2 for financial entities
European Parliament and CouncilOJ L 333 of 27 December 2022
on the resilience of critical entities, adopted together with NIS2
European Parliament and CouncilOJ L 333 of 27 December 2022
on horizontal cybersecurity requirements for products with digital elements
European Parliament and CouncilOJ L of 20 November 2024
network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows
European Commission11 March 2024
requirements for the management of information security risks with a potential impact on aviation safety, for organisations in the sector
European Commission14 July 2022
requirements for the management of information security risks with a potential impact on aviation safety, for organisations and competent authorities
European Commission27 October 2022
measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cyber threats and incidents
European Parliament and Council19 December 2024
05NIS2 in Romania: the core act
The emergency ordinance transposing the NIS2 Directive and the laws that approved and supplemented it. For the text applicable today, use the consolidated version.
on establishing a framework for the cybersecurity of networks and information systems in the national civilian cyberspace
Romanian title: OUG nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil
Government of RomaniaOfficial Gazette No. 1332 of 31 December 2024
The act transposing the NIS2 Directive. It defines essential and important entities, the obligations on registration, risk management and incident reporting, supervision and penalties. It repealed Law No. 362/2018 (art. 66).
approving Government Emergency Ordinance No. 155/2024
Romanian title: Legea nr. 124/2025 pentru aprobarea Ordonanței de urgență a Guvernului nr. 155/2024
Parliament of RomaniaOfficial Gazette No. 638 of 7 July 2025
Approves GEO 155/2024 with amendments (art. 2, 3, 4, 14, 15, 18, 20, 23, 36, 37, 47, 50, 60, 61, 67 and Annexes 1 and 2).
supplementing art. 36 of GEO No. 155/2024 and supplementing Law No. 286/2009 on the Criminal Code
Romanian title: Legea nr. 123/2026 pentru completarea art. 36 din OUG nr. 155/2024, precum și pentru completarea Legii nr. 286/2009 privind Codul penal
Parliament of RomaniaOfficial Gazette No. 550 of 3 July 2026
Introduces the framework for good-faith vulnerability research: art. 36(1^1) of GEO 155/2024 and art. 365^1 of the Criminal Code.
06Implementing acts issued by DNSC
Orders and decisions of the DNSC Director issued under GEO 155/2024, in chronological order, with the annexes each approves.
approving the Requirements on the notification process for registration and the method of transmitting information
Romanian title: Ordinul DNSC nr. 1/2025 pentru aprobarea Cerințelor privind procesul de notificare în vederea înregistrării și metoda de transmitere a informațiilor
National Cyber Security Directorate (DNSC)Official Gazette No. 776 of 20 August 2025
Issued under art. 18(9) of GEO 155/2024.
approving the Criteria and thresholds for determining the degree of disruption of a service and the Methodology for assessing the risk level of entities
Romanian title: Ordinul DNSC nr. 2/2025 pentru aprobarea Criteriilor și pragurilor de determinare a gradului de perturbare a unui serviciu și a Metodologiei privind evaluarea nivelului de risc al entităților
National Cyber Security Directorate (DNSC)Official Gazette No. 776 of 20 August 2025
Issued under art. 10(2) of GEO 155/2024. The Methodology was amended by DNSC Order No. 1/2026.
approving the Implementing Rules on supervision, verification and control of compliance with GEO No. 155/2024 and the Methodology for risk-based prioritisation of supervision, verification and control activities
Romanian title: Ordinul DNSC nr. 3/2025 pentru aprobarea Normelor de aplicare a dispozițiilor privind supravegherea, verificarea și controlul respectării prevederilor OUG nr. 155/2024 și a Metodologiei de prioritizare pe bază de risc a activităților de supraveghere, verificare și control
National Cyber Security Directorate (DNSC)Official Gazette No. 1149 of 11 December 2025
Issued under art. 47(8) of GEO 155/2024.
approving the Cybersecurity risk-management measures for the networks and information systems used by essential and important entities and the Methodology for self-assessing the maturity of cybersecurity risk-management measures, and amending the Methodology for assessing the risk level of entities
Romanian title: Ordinul DNSC nr. 1/2026 pentru aprobarea Măsurilor de gestionare a riscurilor de securitate cibernetică aferente rețelelor și sistemelor informatice utilizate de entitățile esențiale și importante și a Metodologiei de autoevaluare a maturității măsurilor de gestionare a riscurilor de securitate cibernetică și pentru modificarea Metodologiei privind evaluarea nivelului de risc al entităților
National Cyber Security Directorate (DNSC)Official Gazette No. 712 and 712 bis of 27 August 2026
Issued under art. 12 of GEO 155/2024. The annexes were published in Official Gazette No. 712 bis. Supplemented by DNSC Order No. 2/2026.
supplementing DNSC Director's Order No. 1/2026
Romanian title: Ordinul DNSC nr. 2/2026 privind completarea Ordinului directorului DNSC nr. 1/2026
National Cyber Security Directorate (DNSC)Official Gazette No. 792 of 18 September 2026
Supplements Order No. 1/2026; the change is included in its consolidated version.
approving the Rules on the applicability of cybersecurity requirements to entities that are part of a group of undertakings
Romanian title: Decizia DNSC nr. 3/2026 pentru aprobarea Normelor de aplicabilitate a cerințelor de securitate cibernetică pentru entitățile care fac parte dintr-un grup de întreprinderi
National Cyber Security Directorate (DNSC)Official Gazette No. 798 of 21 September 2026
Clarifies how the requirements apply to each entity within a group.
07Status of the acts required by art. 65
Article 65 of GEO 155/2024 lists the acts DNSC must issue. The table shows what has been published in the Official Gazette, what exists only as a draft on dnsc.ro and what is still missing.
| Art. 65 | What is approved | Legal basis | Status |
|---|---|---|---|
| para. (1)(a) | Criteria and thresholds for the degree of disruption and the risk-level assessment methodology | art. 10(2) | DNSC Order No. 2/2025 |
| para. (1)(b) | Risk-management measures | art. 12(1) | DNSC Order No. 1/2026 |
| para. (1)(c) | Methodological rules on incident reporting | art. 15(17) | Not published; no draft on dnsc.ro |
| para. (1)(d) | Requirements on notification for registration and the method of transmitting information | art. 18(9) | DNSC Order No. 1/2025 |
| para. (1)(e) | National peacetime cybersecurity crisis management plan | art. 28(2) | Not published; no draft on dnsc.ro |
| para. (1)(f) | Technical rules on CSIRT compatibility and interoperability and criteria for qualified staff | art. 31(2) | Not published; no draft on dnsc.ro |
| para. (1)(g) | Minimum package of CSIRT services | art. 32(5) | Not published; no draft on dnsc.ro |
| para. (1)(h) | Regulation on the authorisation and verification of CSIRTs and staff training curricula | art. 34(2)(a) | Not published; no draft on dnsc.ro |
| para. (1)(i) | Implementing rules and risk-based prioritisation methodology for supervision, verification and control | art. 47(8) | DNSC Order No. 3/2025 |
| para. (1)(j) | Regulation on the authorisation of training providers for auditors and CSIRTs | art. 54(3) | Draft published by DNSC, not adopted |
| para. (1)(k) | Rules on the supervision and control of CSIRTs, CSIRT service providers and auditors | art. 56(2) | Not published; no draft on dnsc.ro |
| para. (1)(l) | Regulation on the certification and verification of cybersecurity auditors | art. 58(2)(b) | Not published; no draft on dnsc.ro |
| para. (2)(a) | Specialisation curricula for auditors seeking certification (DNSC decision) | art. 58(2)(e) | Not published; no draft on dnsc.ro |
| para. (2)(b) | Specialisation curricula for CSIRT staff seeking authorisation (DNSC decision) | art. 31(3) | Not published; no draft on dnsc.ro |
08In progress: DNSC drafts and bills in Parliament
Acts not yet adopted or published in the Official Gazette, identified on the DNSC decision-making transparency page and in the Chamber of Deputies legislative tracking system. The final text may differ from the draft.
approving the Regulation on the authorisation, verification and revocation of cybersecurity training providers and the validity conditions of their authorisations
Romanian title: Proiect de ordin DNSC: furnizorii de formare
National Cyber Security Directorate (DNSC)DNSC decision-making transparency page, document of June 2026
Corresponds to art. 65(1)(j) of GEO 155/2024. The authorisation of training providers was previously regulated by DNSC Order No. 106/2022.
approving the training standard for members of the management bodies of essential and important entities and the list of cybersecurity certifications
Romanian title: Proiect de decizie DNSC: pregătirea conducerii
National Cyber Security Directorate (DNSC)DNSC decision-making transparency page, document of December 2025
Concerns the training of management bodies required by GEO 155/2024. Not found in the Official Gazette.
Bill approving the payment of DNSC's membership fees to the Forum of Incident Response and Security Teams (FIRST) and to the TF-CSIRT Trusted Introducer (TI)
Romanian title: PL-x 20/2026: cotizațiile DNSC la FIRST și TF-CSIRT
Parliament of RomaniaSenate L558/2025, Chamber of Deputies PL-x 20/2026 (deciding chamber)
Adopted by the Senate; in the Chamber of Deputies it received a favourable report on 24 September 2026. Law No. 146/2014, which authorised the CERT-RO fees, was repealed by art. 66 of GEO 155/2024.
Bill on establishing and operationalising the Cybersecurity Incident Response Centre for Energy and amending and supplementing certain legal acts
Romanian title: PL-x 409/2026: CSIRT pentru sectorul energetic
Parliament of RomaniaSenate L214/2026, Chamber of Deputies PL-x 409/2026
Adopted by the Senate; in the Chamber of Deputies, the deciding chamber, it is in committee (latest opinion received on 15 September 2026).
Legislative proposal supplementing Government Emergency Ordinance No. 155/2024 on establishing a framework for the cybersecurity of networks and information systems in the national civilian cyberspace
Romanian title: BP 610/2026: completarea OUG 155/2024
Parliament of Romania (9 deputies)Registered on 29 July 2026
Sent to the Senate, as first chamber, on 1 September 2026; the Chamber of Deputies is the deciding chamber.
09Related acts linked to NIS2
Sectoral or parallel rules that refer to GEO 155/2024 or apply to the same entities: electronic communications, critical entities, the financial sector, trust services.
on the security of public electronic communications networks and publicly available electronic communications services
Romanian title: Decizia ANCOM nr. 70/2024 privind securitatea rețelelor publice de comunicații electronice și a serviciilor de comunicații electronice destinate publicului
National Authority for Management and Regulation in Communications (ANCOM)Official Gazette No. 117 of 9 February 2024
Under art. 64(1) of GEO 155/2024, the measures adopted by this decision remain in force until they are reviewed.
on the resilience of critical entities and amending certain legal acts
Romanian title: Legea nr. 294/2024 privind reziliența entităților critice, precum și pentru modificarea unor acte normative
Parliament of RomaniaOfficial Gazette No. 1189 of 29 November 2024
Transposes Directive (EU) 2022/2557. The NIS2 Directive (art. 3(1)(f)) treats critical entities identified under CER as essential entities.
approving the rules, procedures and measures provided for in art. 1(3) of Law No. 294/2024
Romanian title: HG nr. 1115/2025 pentru aprobarea normelor, procedurilor și măsurilor prevăzute la art. 1 alin. (3) din Legea nr. 294/2024
Government of RomaniaOfficial Gazette No. 1214 of 30 December 2025
approving the List of critical entities identified under art. 6(1) of Law No. 294/2024
Romanian title: Decizia prim-ministrului nr. 266/2026 pentru aprobarea Listei entităților critice identificate în temeiul art. 6 alin. (1) din Legea nr. 294/2024
Prime MinisterOfficial Gazette No. 603 of 23 July 2026
establishing measures implementing Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
Romanian title: OUG nr. 14/2026 privind stabilirea unor măsuri de punere în aplicare a Regulamentului (UE) 2022/2554 privind reziliența operațională digitală a sectorului financiar (DORA)
Government of RomaniaOfficial Gazette No. 188 of 11 March 2026
on the records and management of public digital infrastructure and the creation of the National Public Digital Infrastructure Platform
Romanian title: Legea nr. 119/2026 privind evidența și administrarea infrastructurii digitale publice, precum și crearea Platformei naționale a infrastructurii digitale publice
Parliament of RomaniaOfficial Gazette No. 550 of 3 July 2026
Refers to GEO 155/2024.
on the procedures for notification, granting of status, entry in and removal from the register, and supervision of trust service providers (eIDAS Regulation)
Romanian title: Decizia ADR nr. 162/2026 privind procedurile de notificare, acordare a statutului, înscriere, radiere și supraveghere a prestatorilor de servicii de încredere (Regulamentul eIDAS)
Romanian Digitalisation Authority (ADR)Official Gazette No. 246 and 246 bis of 30 March 2026
Trust service providers fall within the scope of NIS2 (digital infrastructure sector).
10DNSC and the national cybersecurity framework
The founding act of the competent authority, the national strategy and the Cybersecurity and Cyber Defence Law.
establishing the National Cyber Security Directorate
Romanian title: OUG nr. 104/2021 privind înființarea Directoratului Național de Securitate Cibernetică
Government of RomaniaOfficial Gazette No. 918 of 24 September 2021
DNSC is the national competent authority and single point of contact for NIS2.
approving GEO No. 104/2021
Romanian title: Legea nr. 11/2022 pentru aprobarea OUG nr. 104/2021
Parliament of RomaniaOfficial Gazette No. 25 of 7 January 2022
amending GEO No. 104/2021 and supplementing Annex VIII to Framework Law No. 153/2017
Romanian title: Legea nr. 366/2022 pentru modificarea OUG nr. 104/2021, precum și pentru completarea anexei nr. VIII la Legea-cadru nr. 153/2017
Parliament of RomaniaOfficial Gazette No. 1231 of 21 December 2022
approving Romania's Cybersecurity Strategy for 2022-2027 and the Action Plan
Romanian title: HG nr. 1321/2021 privind aprobarea Strategiei de securitate cibernetică a României pentru perioada 2022-2027 și a Planului de acțiune
Government of RomaniaOfficial Gazette No. 2 and 2 bis of 3 January 2022
on Romania's cybersecurity and cyber defence and amending and supplementing certain legal acts
Romanian title: Legea nr. 58/2023 privind securitatea și apărarea cibernetică a României, precum și pentru modificarea și completarea unor acte normative
Parliament of RomaniaOfficial Gazette No. 214 of 15 March 2023
The general national framework for cybersecurity and cyber defence, separate from GEO 155/2024.
approving the Methodological rules on requesting and communicating the data and information provided for in art. 25(1) of Law No. 58/2023
Romanian title: HG nr. 62/2024 pentru aprobarea Normelor metodologice privind solicitarea și comunicarea datelor și informațiilor prevăzute la art. 25 alin. (1) din Legea nr. 58/2023
Government of RomaniaOfficial Gazette No. 97 of 1 February 2024
establishing the categories of persons provided for in art. 3(1)(c) of Law No. 58/2023
Romanian title: HG nr. 831/2024 pentru stabilirea categoriilor de persoane prevăzute la art. 3 alin. (1) lit. c) din Legea nr. 58/2023
Government of RomaniaOfficial Gazette No. 711 of 22 July 2024
11DNSC acts issued before GEO 155/2024
Orders and decisions issued by DNSC before NIS2 was transposed, under GEO 104/2021 and Law 362/2018. We keep them for context; whether each still applies must be checked against GEO 155/2024 and later DNSC acts.
approving the List of fees for services under the activities provided for by Law No. 362/2018
Romanian title: Decizia DNSC nr. 301/2021 privind aprobarea Listei cuantumului tarifelor pentru serviciile din activitățile prevăzute de Legea nr. 362/2018
National Cyber Security Directorate (DNSC)Official Gazette No. 2 of 3 January 2022
approving the Implementing Rules on the verification and control of compliance with cybersecurity obligations in the national civilian cyberspace
Romanian title: Ordinul DNSC nr. 105/2022 pentru aprobarea Normelor de aplicare a dispozițiilor privind verificarea și controlul îndeplinirii obligațiilor de securitate cibernetică pentru spațiul cibernetic național civil
National Cyber Security Directorate (DNSC)Official Gazette No. 1062 of 2 November 2022
approving the Rules on the authorisation and verification of cybersecurity training providers
Romanian title: Ordinul DNSC nr. 106/2022 pentru aprobarea Normelor privind autorizarea și verificarea furnizorilor de servicii de formare pentru securitate cibernetică
National Cyber Security Directorate (DNSC)Official Gazette No. 1076 of 8 November 2022
approving the curricula for training cybersecurity auditors, CSIRT team members and network and information system security officers
Romanian title: Decizia DNSC nr. 107/2022 privind aprobarea tematicilor pentru formarea auditorilor de securitate cibernetică, a membrilor echipelor CSIRT și a responsabililor cu securitatea rețelelor și sistemelor informatice
National Cyber Security Directorate (DNSC)Official Gazette No. 1146 of 29 November 2022
approving the confidentiality and transparency policies of the National Platform for Reporting Cybersecurity Incidents (PNRISC)
Romanian title: Ordinul DNSC nr. 100/2024 privind aprobarea politicilor de confidențialitate și transparență ale Platformei Naționale pentru Raportarea Incidentelor de Securitate Cibernetică
National Cyber Security Directorate (DNSC)Official Gazette No. 120 of 12 February 2024
approving the Methodology on cyber alert levels and courses of action in cyber alert situations
Romanian title: Ordinul DNSC nr. 180/2024 pentru aprobarea Metodologiei privind nivelurile de alertă cibernetică și modalitățile de acțiune în situații de alertă cibernetică
National Cyber Security Directorate (DNSC)Official Gazette No. 197 of 11 March 2024
12NIS1: Law 362/2018 and its implementing acts (historical)
The framework that transposed the first NIS Directive. Law 362/2018 was repealed by GEO 155/2024; measures adopted under Chapters IV and V remain in force until they are reviewed (art. 66(1)(a)).
on ensuring a high common level of security of networks and information systems
Romanian title: Legea nr. 362/2018 privind asigurarea unui nivel comun ridicat de securitate a rețelelor și sistemelor informatice
Parliament of RomaniaOfficial Gazette No. 21 of 9 January 2019
The law transposing the NIS Directive. Repealed when GEO 155/2024 entered into force, except for the measures adopted under Chapters IV and V, which remain in force until reviewed (art. 66(1)(a)). References to Law 362/2018 are deemed to be made to GEO 155/2024.
amending and supplementing Law No. 362/2018
Romanian title: OG nr. 2/2019 pentru modificarea și completarea Legii nr. 362/2018
Government of RomaniaOfficial Gazette No. 80 of 31 January 2019
extending certain deadlines provided for by Law No. 362/2018 and GO No. 2/2019
Romanian title: OUG nr. 76/2019 pentru prorogarea unor termene prevăzute de Legea nr. 362/2018 și de OG nr. 2/2019
Government of RomaniaOfficial Gazette No. 1023 of 19 December 2019
amending and supplementing Law No. 362/2018
Romanian title: OUG nr. 119/2020 pentru modificarea și completarea Legii nr. 362/2018
Government of RomaniaOfficial Gazette No. 658 of 24 July 2020
approving the Methodological rules for identifying operators of essential services and digital service providers
Romanian title: Ordinul MCSI nr. 599/2019 privind aprobarea Normelor metodologice de identificare a operatorilor de servicii esențiale și furnizorilor de servicii digitale
Ministry of Communications and Information SocietyOfficial Gazette No. 584 of 17 July 2019
approving the Methodological rules on the organisation and operation of the Register of operators of essential services
Romanian title: Ordinul MCSI nr. 600/2019 privind aprobarea Normelor metodologice de organizare și funcționare a Registrului operatorilor de servicii esențiale
Ministry of Communications and Information SocietyOfficial Gazette No. 542 of 2 July 2019
approving the Methodology for determining the significant disruptive effect of incidents affecting the networks and information systems of operators of essential services
Romanian title: Ordinul MCSI nr. 601/2019 pentru aprobarea Metodologiei de stabilire a efectului perturbator semnificativ al incidentelor la nivelul rețelelor și sistemelor informatice ale operatorilor de servicii esențiale
Ministry of Communications and Information SocietyOfficial Gazette No. 590 of 18 July 2019
approving the List of European and international standards and specifications
Romanian title: Decizia CERT-RO nr. 88/2020 privind aprobarea Listei standardelor și specificațiilor europene și internaționale
CERT-ROOfficial Gazette No. 465 of 2 June 2020
approving the List of essential services
Romanian title: HG nr. 963/2020 pentru aprobarea Listei serviciilor esențiale
Government of RomaniaOfficial Gazette No. 1086 of 16 November 2020
approving the threshold values for determining the significant disruptive effect of incidents affecting the networks and information systems of operators of essential services
Romanian title: HG nr. 976/2020 privind aprobarea valorilor de prag pentru stabilirea efectului perturbator semnificativ al incidentelor la nivelul rețelelor și sistemelor informatice ale operatorilor de servicii esențiale
Government of RomaniaOfficial Gazette No. 1089 of 17 November 2020
approving the Technical rules on the minimum security requirements for networks and information systems applicable to operators of essential services
Romanian title: Ordinul SGG nr. 1323/2020 pentru aprobarea Normelor tehnice privind cerințele minime de asigurare a securității rețelelor și sistemelor informatice aplicabile operatorilor de servicii esențiale
General Secretariat of the GovernmentOfficial Gazette No. 1142 of 26 November 2020
approving the Technical rules for determining the impact of incidents for the categories of operators of essential services and digital service providers
Romanian title: HG nr. 1003/2020 pentru aprobarea Normelor tehnice de stabilire a impactului incidentelor pentru categoriile de operatori de servicii esențiale și furnizori de servicii digitale
Government of RomaniaOfficial Gazette No. 1223 of 14 December 2020
approving the Regulation on the certification and verification of cybersecurity auditors
Romanian title: Ordinul SGG nr. 559/2021 privind aprobarea Regulamentului pentru atestarea și verificarea auditorilor de securitate cibernetică
General Secretariat of the GovernmentOfficial Gazette No. 387 of 14 April 2021
establishing the National Computer Security Incident Response Centre (CERT-RO)
Romanian title: HG nr. 494/2011 privind înființarea Centrului Național de Răspuns la Incidente de Securitate Cibernetică (CERT-RO)
Government of RomaniaOfficial Gazette No. 388 of 2 June 2011
CERT-RO was replaced by DNSC through GEO 104/2021.
13Official DNSC resources
DNSC platforms, downloadable tools and official pages used in applying NIS2 legislation.
NIS2@RO Platform
The enrolment, information and cooperation platform used for notification for registration and later interaction with DNSC (DNSC Order No. 1/2025).
Registration of entities
DNSC page on the notification process for registration, with the related tools and instructions.
Obligations of registered entities
DNSC page on the obligations that follow entry in the register.
NIS2 legislation on dnsc.ro
The list of legal acts published by DNSC.
DNSC decision-making transparency
Draft legal acts under public consultation, with approval reports and statements of reasons.
Coordinated vulnerability disclosure
DNSC's coordinated vulnerability disclosure process, provided for in art. 36 of GEO 155/2024.
The resources above are not legal acts. DNSC provides them for applying the acts on this page. The DNSC pages are in Romanian.
Downloadable tools
| Stage | Tool | Version | |
|---|---|---|---|
| Notification for registration | NIS2@RO Tool, version 2.3 Generates the notification form when the NIS2@RO Platform is unavailable (art. 18 GEO 155/2024, DNSC Order No. 1/2025). Romanian interface. | RO | Download |
| Notification for registration | NIS2@RO tool, version 2.1 English version of the tool, for people who do not speak Romanian. The form is still submitted in Romanian. | EN | Download |
| Identification | Guide to the disruptive effect analysis, version 1.0 Supports the entity's self-assessment of the disruptive effect of an incident, at the identification stage. In Romanian. | Guide | Download |
| Risk-level assessment | ENIRE@RO Tool, version 2 Generates the entity's risk-level assessment report until the platform is operational. The report is signed by the legal representative (art. 18(6)). In Romanian. | RO | Download |
| Maturity self-assessment | EVAL_MMS_B, basic level Self-assessment tool for the maturity of risk-management measures at the basic security level (art. 18(7)). In Romanian. | v1 | Download |
| Maturity self-assessment | EVAL_MMS_I, important level Self-assessment tool for the important security level. The applicable level follows from the overall score obtained with ENIRE@RO and validated by DNSC. | v3 | Download |
| Maturity self-assessment | EVAL_MMS_E, essential level Self-assessment tool for the essential security level. | v3 | Download |
The links point directly to the files published by DNSC on dnsc.ro, checked on 8 October 2026. DNSC regularly publishes new versions; the current version is the one on the Registration of entities and Obligations of registered entities pages.
14Frequently asked questions
Short answers, with references to the legal text.
Where can I find the official text of GEO 155/2024?
The consolidated version, which includes the amendments made by Law No. 124/2025 and Law No. 123/2026, is on the Ministry of Justice legislative portal at legislatie.just.ro/Public/DetaliiDocumentAfis/311690, in Romanian. The portal also has a printable version. The text with official value is the one published in Official Gazette No. 1332 of 31 December 2024. There is no official English translation.
What did Law No. 124/2025 change?
It approved GEO 155/2024 with amendments, applicable from 10 July 2025. The amendments cover, among others, management training (art. 14), incident reporting (art. 15), notification for registration (art. 18) and penalties (art. 60-61), as well as Annexes 1 and 2.
What is the deadline for registering with DNSC?
Entities in the sectors listed in Annexes 1 and 2 that qualify as essential or important notify DNSC within 30 days of the entry into force of the ordinance or of the date it becomes applicable to them (art. 18(2)). Notification is made through the NIS2@RO Platform, under DNSC Order No. 1/2025.
What fines does GEO 155/2024 provide for?
For serious infringements, up to EUR 10 million or 2% of worldwide turnover for essential entities and up to EUR 7 million or 1.4% for important entities. For other obligations, including notification for registration, between RON 1,500 and RON 500,000, and between RON 1,000 and RON 300,000 respectively (art. 60(2)).
How often must the security audit be carried out?
GEO 155/2024 provides that the frequency is set by order of the DNSC Director, according to the risk level (art. 11(5)). As of 8 October 2026 we have not identified a published order setting it. DNSC may order an ad hoc audit at any time (art. 57).
Must an incident be reported to both DNSC and ANSPDCP?
Yes, if the significant incident also affects personal data. Reporting to DNSC follows art. 15 of GEO 155/2024, and notification to ANSPDCP follows art. 33 GDPR. They are two separate obligations, with different recipients and content.
Does NIS2 apply to every company in a group?
Obligations are assessed at the level of each entity. How they apply within groups of undertakings is explained in the Rules approved by DNSC Decision No. 3/2026.
15Changelog
What has been added or changed on this page.
- Page published: 80 Romanian acts and 7 European acts, with the status of the acts required by art. 65.
- Added DNSC drafts under consultation, bills in Parliament and supporting documents (explanatory notes, statements of reasons, approval reports).
- Added the obligations table, the deadline chain, the comparison between reporting to DNSC and to ANSPDCP, sectoral EU acts, official DNSC resources and frequently asked questions.
- Added direct download links for the DNSC tools: NIS2@RO (RO and EN), ENIRE@RO, the guide on disruptive effect and the EVAL_MMS self-assessment tools for the three levels.
- English version published.
No act matches your search. Try the act number or the year.
Need help applying these acts?
We check whether you qualify as an essential or important entity, prepare the notification to DNSC, implement the measures in DNSC Order 1/2026 and act as your NIS2 officer.
This page is for information only. The texts with official value are those published in the Official Gazette of Romania, Part I, and in the Official Journal of the European Union.
The list was checked on 8 October 2026 on legislatie.just.ro (which reproduces the Official Gazette, Part I), on the DNSC decision-making transparency page and on cdep.ro, and is updated when new acts are published. Spotted a missing act? Write to us at [email protected].
