Risksoft Blog / Security & compliance
NIS2 in Romania: who must comply, by when, and what happens if you don't
Five questions that tell you where your company stands, the deadlines that matter now, and the part almost nobody writes down: who is actually accountable.
In short
If your company has more than 50 employees or over EUR 10 million in turnover and operates in one of the sectors listed in the law, you most likely fall under NIS2. You must notify the National Cyber Security Directorate, carry out a risk assessment, and report incidents within 24 hours.
Accountability doesn't sit with the IT person. The law places it on executive management. And even if you don't fall under it directly, you'll probably be asked anyway — by your larger clients, who do.
The correct act is GEO 155/2024
The European directive is called NIS2, adopted in 2022. In Romania it was transposed through Government Emergency Ordinance no. 155/2024, in force since 30 December 2024, approved with amendments and additions through Law no. 124/2025, published in the Official Gazette no. 638 of 7 July 2025. The updated text is public.
You'll find plenty of articles online citing "Law 58/2024". That is not the act that binds you. It's worth remembering for a practical reason: if someone offers you compliance services citing the wrong legal basis, you already have a clue about how carefully they've read the rest.
The implementing rules arrived a year later, through DNSC Orders no. 1 and no. 2/2025, published in the Official Gazette no. 776 of 20 August 2025. The first sets out how you register. The second sets out how you calculate your risk level.
Do you fall under it or not? Five questions
1. Do you operate in one of the sectors in the annexes of the law?
There are eighteen. Among them: energy, transport, healthcare, water, digital infrastructure, management of ICT networks and systems, manufacturing, food industry, waste management.
2. Do you have more than 50 employees, or over EUR 10 million in turnover or balance sheet total?
This is the general threshold for medium-sized enterprises. Below it, small and micro companies are, as a rule, outside the scope.
3. Are you the sole provider of a service that others depend on?
Here the size threshold no longer protects you. A small company can be included precisely because it has no replacement.
4. Are you a supplier to an essential or important entity?
It doesn't include you automatically. But it has consequences, which I'll return to below.
5. Do you operate in two or more sectors from the annexes?
The law is clear: in this case the measures that apply to you are those corresponding to the highest level, not the average of them.
If you answered "yes" to the first and the second, treat yourself as within scope until you verify it officially.
If you're in scope: the order things happen in
The general notification deadline was in September 2025, 30 days after the orders were published. The rule that matters now is different: you have 30 days from the moment you become a covered entity — when you cross the employee threshold, when you enter a new sector, or after an acquisition.
After notification, the process runs like this:
- DNSC issues the identification decision and enters you in the register: 60 days for essential entities, 150 days for important ones.
- Within 30 days of the decision being communicated, you designate in writing the person responsible for the security of networks and information systems.
- Within 60 days of the decision, you submit the risk level assessment.
- Within 60 days of the risk assessment, you carry out the maturity self-assessment of the measures you have in place.
In parallel, at all times: significant incidents are reported within 24 hours through an initial notification, within 72 hours through an intermediate report, and within 30 days through a final report. These are calendar days. A Friday-evening incident doesn't wait until Monday.
The part most articles miss
Article 14 of the ordinance states that the management bodies approve the security measures, oversee their implementation, and are responsible for any breach of these provisions. Members of management are also obliged to undergo cybersecurity training.
And Law 124/2025 added a clarification that completely changes the conversation in Romanian companies: the general meeting of shareholders and the board of directors are not "management bodies" within the meaning of this ordinance.
Translated: accountability doesn't rise up to the shareholders and doesn't dissolve into a board. It stays with executive management. With you.
This is not a legal detail. It's the reason security can no longer be a budget line you approve and forget. The person who signs is the person who answers for it.
Even if you're not in scope, you'll still be asked
NIS2 requires covered entities to manage the risks coming from their supply chain as well. In practice, the obligation propagates through contracts.
What this means for a 40-person company that's in none of the annex sectors: when you renew your contract with a large client, you receive a security questionnaire. You're asked for written policies, proof that you make backups, proof that you test them, two-factor authentication, an incident-management process. Sometimes you're asked for a certificate.
It's not a legal obligation of yours. It's a commercial condition. And the practical difference between the two is zero: if you can't answer, you lose the contract.
What the company risks
The penalties are set out in Article 60 of the ordinance and come in two tiers.
Fixed fines range from 1,000 to 300,000 lei for important entities and from 1,500 to 500,000 lei for essential ones — for things like failing to submit the notification, the risk assessment, or the self-assessment on time.
On top of these, for breaching security obligations: up to EUR 7 million or 1.4% of annual worldwide turnover for important entities, and up to EUR 10 million or 2% for essential ones. The percentage is calculated on the group's global turnover, not just the Romanian one.
Three things you can check today
How we know this
Risksoft has managed the IT infrastructure of more than 70 companies in Romania for 25 years. Our information security management system is certified to ISO/IEC 27001:2022. You can verify it yourself, in thirty seconds, in the public IAF CertSearch database — we don't ask you to take our word for it.
That audit is repeated every year. The same categories of measures NIS2 requires from you are the ones we demonstrate, annually, in front of an external auditor.
Certificate no. RO231109006 · issued by LMS Assessments Limited · verify in IAF CertSearch
The next step
If you're not sure where your company stands against the requirements above, let's look at it together. The assessment takes 45 minutes, it's free, and it ends with a written list: which category you fall into, what you already have covered, and what's missing, in the order it should be fixed.
Book the 45-minute assessmentNo product pitch. If you leave the conversation concluding you don't need us, you still keep the list.
The information in this article reflects the legal framework in force at the date of publication. Legislation may change; for your company's situation, check the updated text on the Legislative Portal or consult a specialist.