Skip to main content
Avencyx

NIS2 in Romania: what organizations must do now

Romania has transposed the NIS2 Directive through GEO 155/2024 and Law 124/2025, with registration and compliance obligations already in effect. A concise overview of the timeline, obligations, deadlines, and a pragmatic path to compliance.

Romanian organizations in critical and important sectors are no longer preparing for NIS2 — they are already subject to it. The transposition framework is in force, the registration window has closed, and supervisory activity by the National Cyber Security Directorate (DNSC) is built on obligations that apply now. This overview summarizes where the framework stands, what it requires, and how to approach compliance without turning it into a paper exercise.

The NIS2 Directive in brief

Directive (EU) 2022/2555 — NIS2 — replaces the original NIS Directive and sets a common, significantly higher baseline for cybersecurity across the EU. It expands the regulated sectors, introduces a size-based scoping rule, makes management bodies explicitly accountable, imposes concrete risk-management measures, and standardizes incident reporting. Member states had until 17 October 2024 to transpose it into national law.

Timeline in Romania

  • 16 January 2023 — NIS2 enters into force at EU level.
  • 17 October 2024 — EU transposition deadline.
  • 31 December 2024 — Romania’s transposition, Government Emergency Ordinance No. 155/2024 on the cybersecurity of networks and information systems, enters into force, designating the DNSC as the national competent authority.
  • 10 July 2025Law No. 124/2025, approving and amending GEO 155/2024, enters into force and refines the framework’s scope.
  • 20 August 2025 — DNSC Orders No. 1/2025 and 2/2025 enter into force, operationalizing entity registration and risk assessment. In-scope entities had 30 days to register with the DNSC (a deadline of approximately 19 September 2025).
  • Following identification — entities notified by the DNSC as essential or important must submit the required self-assessment within 60 days of that communication.
  • Ongoing (2026) — further implementing legislation, including detailed security-measure norms, continues to be developed by the DNSC. Verify the current status of secondary legislation directly with the DNSC before relying on it.

Who is in scope

GEO 155/2024 follows the NIS2 model: entities operating in the sectors of high criticality (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space) and other critical sectors (including postal services, waste management, chemicals, food, manufacturing, digital providers, and research) fall in scope, generally where they meet the size threshold of at least 50 employees or over EUR 10 million annual turnover. Certain entities are in scope regardless of size. Entities are classified as essential or important, with stricter supervision for the former.

Core obligations

  1. Registration — notify and register with the DNSC, and keep the registered information current.
  2. Risk-management measures — implement appropriate and proportionate technical, operational, and organizational measures, including risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication where appropriate.
  3. Incident reporting — report significant incidents to the DNSC: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
  4. Management accountability — management bodies must approve and oversee the risk-management measures and undergo cybersecurity training; responsibility cannot simply be delegated to IT.
  5. Sanctions — administrative fines of up to EUR 10 million or 2% of worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4% for important entities, alongside supervisory measures.

A pragmatic path to compliance

Compliance efforts fail most often by starting with documents instead of risk. A defensible program is usually phased:

  1. Confirm applicability and registration status. Determine your classification and sector mapping; if registration obligations were missed, address them now rather than waiting for supervisory contact.
  2. Assess against the required measures. A focused gap assessment against the risk-management measures and reporting obligations — grounded in your real architecture and operations, not an idealized target.
  3. Prioritize by risk, remediate in phases. Start with the highest-risk assets and the failure modes most likely to produce a reportable incident. Track actions with ownership, deadlines, and validation.
  4. Build reporting readiness before you need it. The 24-hour early warning is achievable only with prepared playbooks, decision paths, and evidence-collection discipline tested in advance.
  5. Produce evidence as you go. Maturity progress, control operation, and incident readiness documented in a form you can show the DNSC, your board, and your auditors.

Where Avencyx can help

Avencyx is prepared to support Romanian organizations across this entire path — from applicability analysis, registration, and gap assessment through phased implementation, incident-reporting readiness, and regulator-ready evidence. This is the core of Avencyx GRC, backed where needed by our detection and response and incident readiness services. If NIS2 is on your board’s agenda, talk to us — we will give you an honest, evidence-led view of where you stand and the smallest step that changes your risk position.


This article is a general overview, not legal advice. Obligations depend on your specific classification and sector, and implementing legislation continues to evolve — verify the current requirements with the DNSC and qualified counsel.