Checked on September 27, 2026

NIS2 in Romania

How Romania applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.

Transposition status
In force
National law
Government Emergency Ordinance 155/2024 on a cybersecurity framework for networks and information systems in the national civil cyberspace (approved by Law 124/2025) · Ordonanța de urgență nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil
National CSIRT
DNSC (national CSIRT)
Registration
Required · deadline September 19, 2025

Notification for registration to DNSC within 30 days of DNSC Order 1/2025 (in force 20 Aug 2025), via NIS2@RO tool/platform.

Incident reporting
Significant incidents are notified to DNSC; national timelines under GEO 155/2024 and DNSC orders (not independently confirmed here).
National specifics
  • GEO 155/2024 published in Monitorul Oficial no. 1332 of 31 Dec 2024; approved with amendments by Law 124/2025 (in force 10 Jul 2025).
  • DNSC Order 2/2025 sets disruption thresholds and risk-level methodology; risk assessment due 60 days after DNSC notice.
  • Fines up to EUR 10m or 2% of worldwide turnover for essential entities.

Where does your company stand?

The free assessment applies these national rules to your answers and scores every area of the law.

Sources

National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.

NIS2 in other countries

NIS2 in Romania: national law, authority and registration | Parendum