Skip to main content
Avencyx

NIS2 in Romania: what organizations must do now

Understand Romania's NIS2 registration, DNSC assessment, RSSI, annual compliance and incident-reporting deadlines under GEO 155/2024 and Law 124/2025.

Ask when NIS2 compliance is “due” in Romania and you will not get one date. The transposition framework is in force, the initial notification window has expired, and the National Cyber Security Directorate (DNSC) already operates a supervision and control regime – yet most of the deadlines that matter to a given organization are triggered by that organization’s own position in the process, not by the calendar.

Romanian NIS2 compliance is not governed by one final deadline. It operates as a chain of statutory, event-driven and recurring obligations: notification within 30 days of entering scope, DNSC identification, risk and maturity assessments, annual reassessment, immediate incident reporting and continuing evidence-based supervision.

This article sets out that chain – what starts each clock, how long it runs, and what organizations should be doing now.

The NIS2 Directive in brief

Directive (EU) 2022/2555 – NIS2 replaces the original NIS Directive and sets a common, significantly higher baseline for cybersecurity across the EU. It expands the regulated sectors, introduces a size-based scoping rule, makes management bodies explicitly accountable, imposes concrete risk-management measures and standardizes incident reporting. Member states had until 17 October 2024 to transpose it into national law.

Legislative timeline in Romania

Romania’s transposition is now substantially complete and operational:

  • 31 December 2024Government Emergency Ordinance no. 155/2024 on the cybersecurity of networks and information systems enters into force, designating the DNSC as the national competent authority.
  • 10 July 2025Law no. 124/2025, approving and amending GEO 155/2024, enters into force and refines the framework’s scope.
  • 20 August 2025 – DNSC Order no. 1/2025 (notification and registration) and Order no. 2/2025 (service-disruption criteria and the entity risk-assessment methodology) enter into force. The initial notification period for entities already in scope expired in September 2025.
  • DNSC Order no. 3/2025 establishes the rules for supervision, verification and control – inspections, audits, the rights and obligations of inspected entities, and the identification and sanctioning of offences under GEO 155/2024. The supervision framework is not a future development: it is already operational.

There is no single Romanian NIS2 deadline

Obligations under GEO 155/2024 fall into seven distinct categories, each with its own clock: legislative implementation milestones (already passed), a rolling notification obligation, entity-specific deadlines triggered by the DNSC registration decision, annual and periodic assessment obligations, event-driven data-update obligations, immediate incident-reporting deadlines, and active DNSC supervision with remediation requirements.

The table below summarizes the compliance timeline. Each row is examined in the sections that follow.

Trigger or stage Obligation Deadline
Entity becomes subject to GEO no. 155/2024 Notify DNSC Within 30 days
DNSC receives notification for an essential entity DNSC identification and registration decision Up to 60 days
DNSC receives notification for an important entity DNSC identification and registration decision Up to 150 days
DNSC decision is communicated Submit entity risk-level assessment Within 60 days
Risk-level assessment is transmitted Complete maturity self-assessment Within 60 days
Annual maturity self-assessment completed by an essential entity Submit management-approved remediation plan where deficiencies exist Within 30 days
Relevant organizational or registration data changes Update DNSC Two weeks, three months or 30 days, depending on the change
Entity risk score Recalculate At least every three years and when relevant triggers occur

The scope and notification clock

The initial 2025 notification window – 30 days from the entry into force of the DNSC implementing orders – has expired. That does not close the door: the notification obligation is rolling. An organization that subsequently enters scope – through growth, a new activity, an acquisition or a legislative change – must notify the DNSC within 30 days of becoming subject to GEO 155/2024. Organizations that were in scope during the initial window and missed it should address the omission immediately rather than wait for supervisory contact: late notification is a far better position than discovered non-notification.

One point is often misunderstood: the organization performs the applicability analysis and submits the notification, but it does not classify itself definitively. The formal identification as an essential or important entity – and the registration itself – is made by the DNSC through its decision.

The DNSC identification clock

After receiving a notification, the DNSC issues its identification and registration decision within up to 60 days for essential entities and up to 150 days for important entities. This decision matters practically as well as legally: its communication is the trigger that starts the entity-specific assessment deadlines described next. Organizations should use the waiting period to prepare, because the subsequent clocks are short.

The risk-assessment clock

Within 60 days of the communication of the DNSC registration decision, the entity must carry out and submit its risk-level assessment under the methodology in Order no. 2/2025 – an analysis of the entity’s exposure based on the criteria and thresholds set by the DNSC, including the degree of disruption its services could suffer.

Certain regulated entities are excluded from this specific national risk-level assessment procedure under Order no. 2/2025 – typically where sector-specific regimes apply. That exclusion is narrow: it does not necessarily exempt those entities from registration, governance, incident reporting or the other NIS2 obligations.

The maturity-assessment clock

The risk-level assessment and the maturity self-assessment are two separate obligations with two separate deadlines – they are frequently, and wrongly, merged into a single “60-day” requirement. The maturity self-assessment – an evaluation of how the entity’s cybersecurity capabilities measure against the applicable requirements – must be completed within 60 days after the risk-level assessment is transmitted. In practice, an entity therefore has up to 120 days from the DNSC decision across the two exercises, but each deadline is enforced on its own clock.

The recurring compliance clock

Registration is the beginning of the cycle, not the end of it:

  • The maturity self-assessment must be repeated annually, approved by the entity’s management, for both essential and important entities.
  • Where the annual self-assessment identifies deficiencies, essential entities must submit a management-approved remediation plan within 30 days of completing the assessment.
  • The entity risk score must be recalculated at least every three years – and earlier when relevant triggers occur, such as significant changes to services, infrastructure or exposure.

Changes that must be reported to DNSC

Registration data is not static. GEO 155/2024 and its implementing orders set event-driven update periods:

  • No later than two weeks – for relevant core changes to the registered information.
  • No later than three months – for specified information concerning representation, the Member States where services are provided and network-related details.
  • Within 30 days – where the entity concludes it no longer meets the applicability criteria and requests deregistration.

Platform-availability deadlines

Notifications, assessments and updates are submitted through the DNSC’s dedicated platform, NIS2@RO. Where the platform is unavailable, entities may use the available offline tools and alternative submission mechanisms – unavailability of the platform does not suspend the underlying obligations. Information or assessments previously submitted through alternative channels may then need to be uploaded to the platform within 20 days following the relevant platform-availability notification.

Management and RSSI obligations

NIS2 places accountability on management bodies: they approve the risk-management measures, oversee their implementation and must themselves undergo cybersecurity training. Responsibility cannot simply be delegated to IT.

Alongside this, entities must designate a security officer for networks and information systems (RSSI) following the DNSC registration decision. For qualifying essential entities, the designated RSSI must obtain the applicable accredited qualification within 12 months from designation. This 12-month period is sometimes misread as a general grace period for NIS2 compliance – it is not. It applies only to the RSSI qualification; every other clock described in this article runs independently.

Incident reporting: the operational clock

Incident reporting is the fastest clock in the framework, and the legal trigger is when the entity becomes aware of the incident or of the relevant information – not when the incident originally began. A compromise discovered months after the initial intrusion starts the reporting clock at discovery.

Reporting stage Deadline
Information enabling assessment of cross-border impact No later than 6 hours after awareness
Early warning regarding a significant incident No later than 24 hours after awareness
Incident notification with initial severity, impact and available indicators of compromise No later than 72 hours after awareness
Intermediate report At the national CSIRT’s request
Final report Within one month after the 72-hour notification
Incident still ongoing at the one-month point Progress report, followed by a final report within one month after the incident is handled

The six-hour obligation is a Romanian particularity worth planning for: where the entity holds information enabling the national CSIRT to determine that an incident has a cross-border impact, that information must be provided within six hours of awareness. Meeting it requires escalation paths and decision authority that function outside business hours.

Who is in scope

GEO 155/2024 follows the NIS2 model: entities operating in the sectors of high criticality – energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space – and in the other critical sectors, including postal services, waste management, chemicals, food, manufacturing, digital providers and research.

The widely quoted threshold of 50 employees or EUR 10 million turnover is only a screening indicator, not the complete test. The full applicability assessment may depend on the sector, employee count, turnover, balance-sheet total, the treatment of partner and linked enterprises under the SME methodology, size-independent inclusion criteria – some entities are in scope regardless of size – and sector-specific legislation. Borderline organizations should perform the analysis properly and document it, whichever way the conclusion falls.

Risk-management obligations

In-scope entities must implement appropriate and proportionate technical, operational and organizational measures. These span risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, security in acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, human-resources security, access control and asset management, and multi-factor authentication where appropriate. The applicable depth of implementation follows the entity’s category and risk – which is precisely why the risk-level and maturity assessments matter beyond their filing deadlines: they determine what “proportionate” means for your organization.

Sanctions and supervision

Non-compliance carries administrative fines of up to EUR 10 million or 2% of net turnover, whichever is higher, for essential entities, and up to EUR 7 million or 1.4% of net turnover for important entities – alongside supervisory measures that can include binding instructions and remediation orders.

Under Order no. 3/2025, the DNSC’s supervision, verification and control framework is already operational: inspections and audits, defined rights and obligations for inspected entities, and a mechanism for identifying and sanctioning offences. Supervision is evidence-based – the practical question an entity must be able to answer is not “do we have a policy?” but “can we demonstrate that the measure operates?”

What organizations should do now

  1. Confirm applicability and notification status. Perform and document the scope analysis; notify the DNSC if required, including where the initial window was missed.
  2. Establish governance and designate accountable roles. Management ownership, the RSSI designation and qualification path, and clear internal accountability.
  3. Prepare separately for the risk-level and maturity assessments. Treat them as two exercises with two deadlines, with data collection started before the DNSC decision arrives.
  4. Build a risk-based remediation programme – owners, deadlines, evidence and management approval of residual risk, rather than an undifferentiated list of findings.
  5. Establish six-hour, 24-hour and 72-hour incident-reporting readiness – detection, escalation, decision authority and pre-agreed reporting templates that work outside business hours.
  6. Maintain a continuous evidence lifecycle rather than assembling documents immediately before an audit or DNSC control.

Where Avencyx can help

Avencyx supports Romanian organizations across this entire chain: applicability and registration analysis, the entity risk assessment, the maturity assessment, governance and RSSI support, implementation of the applicable Basic, Important and Essential controls, and risk-based remediation – extending to supplier and supply-chain security, managed detection and response and vulnerability management, incident-reporting readiness, digital forensics and incident response, management training and cyber exercises, and regulator-ready evidence management. This work is anchored in Avencyx GRC.

The objective is not to create a larger collection of policies. It is to establish a defensible cybersecurity programme in which governance, processes, people and technology operate together – and can be demonstrated to management, auditors and the DNSC. If NIS2 is on your board’s agenda, talk to us – we will give you an honest, evidence-led view of where you stand and the smallest step that changes your risk position.

This article is a general overview and does not constitute legal advice. Obligations depend on your entity’s classification, sector and circumstances, and implementing legislation continues to evolve – verify current requirements against the official texts linked above, the DNSC and qualified counsel.

Frequently asked questions

What is the NIS2 compliance deadline in Romania?

There is no single deadline. Romanian NIS2 compliance is a chain of obligations: notification to the DNSC within 30 days of entering scope, entity-specific assessment deadlines triggered by the DNSC registration decision (60 days for the risk-level assessment, then 60 days for the maturity self-assessment), annual reassessment, event-driven data updates, and immediate incident-reporting deadlines.

What if we missed the initial DNSC registration window?

The initial notification period expired in September 2025, but the obligation is rolling — organizations that missed it should notify the DNSC immediately rather than wait for supervisory contact. Late notification is a far better position than discovered non-notification, and the DNSC's supervision and control framework under Order no. 3/2025 is already operational.

Who decides whether we are an essential or important entity?

The DNSC. Your organization performs the applicability analysis and submits the notification, but the formal identification as an essential or important entity — and the registration itself — is made by the DNSC through its decision, issued within up to 60 days for essential entities and up to 150 days for important entities.

How quickly must incidents be reported under NIS2 in Romania?

From the moment your organization becomes aware: no later than 6 hours for information enabling assessment of cross-border impact, 24 hours for the early warning, 72 hours for the incident notification, and one month after that notification for the final report — with progress reports where the incident is still ongoing.