Security & compliance

NIS2 in Romania: who must comply, by when, and what happens if you don't

Five questions that tell you where your company stands, what the law requires in concrete documents, where to download the official DNSC tools, and the part almost nobody writes down: who is actually accountable.

14 August 2026 Updated 31 August 2026 16 min read Checked against the law in force

In short

As a general rule, NIS2 targets at least medium-sized companies, meaning over 50 employees or over EUR 10 million in turnover, operating in the sectors listed in the law. The final classification also depends on the sector, the company's structure and the applicable exceptions, so it is something you verify rather than assume.

If you are in scope, you register with Romania's National Cyber Security Directorate, run a risk assessment, and for a significant incident you send an early warning within 24 hours, followed by the reports the law requires. Both the scope check and the registration form are done with tools DNSC publishes, and further down we set out exactly where to download them and how they are submitted.

Accountability does not sit with the IT department. The law places it on the management bodies. And if your company stays outside the law, the cost doesn't go away: for a mid-sized business the fine is a distant possibility, but losing a contract, when a larger client asks for evidence of security, is far more likely.

On a Tuesday morning, a director gets an email from the company's largest client. It is not an order. It is a security questionnaire, forty questions long, with a two-week deadline.

He forwards it to whoever handles IT, with the message „can you take a look at this?". That is the normal reflex. It is also the first mistake.

The law behind that questionnaire contains a clarification almost nobody reads. Added in the summer of 2025, two lines long, it rules out both the general meeting of shareholders and the board of directors: neither is a „management body" within the meaning of the ordinance. Accountability does not climb to the shareholders and does not drop to the IT department. It stays with executive management.

The rest of this article is about how you find out whether it applies to you, what you have to do, and in what order.

What NIS2 is, and what it actually asks of a company

NIS2 is a European law about cybersecurity. It came out of a simple observation: when one company is attacked, the effect rarely stops there. If an energy supplier, a hospital, or a company that keeps other companies' systems running goes down, their customers go down with them. The law tries to raise the minimum level of security in exactly the sectors the rest of the economy depends on.

What it asks comes down to three things:

  • Make yourself known. You register with the national authority, so it knows who you are and which service you keep running.
  • Keep your risks under control, and be able to prove it. Tested backups, control over who has access to what, two-step authentication, a clear process for incidents, training for your employees, attention to your suppliers.
  • Say something when it breaks. A significant incident is flagged through an early warning, within 24 hours.

Worth saying what it does not ask: it doesn't tell you which products to buy and it doesn't require a particular certificate. It requires that measures exist, that they are documented, and that you can show them to someone who asks.

Which is also why the subject goes beyond compliance. That list is, almost word for word, the list of things that separate a two-hour incident from a two-week one. Companies that already have them have little to do. Companies that don't would need them anyway, law or no law.

Which law implements NIS2 in Romania

NIS2 is an EU directive from 2022, and directives don't apply to companies directly: each country rewrites them into its own law, and the national version is the one that binds you.

Here, that act is Government Emergency Ordinance no. 155/2024. It has been in force since 30 December 2024 and was approved, with amendments, by Law no. 124/2025, published in the Official Gazette on 7 July 2025.

You will find plenty of articles online citing „Law 58/2024". That is not the act that binds you. It is worth checking the legal basis every time you read about NIS2, because a lot of what is online was written before the rules settled.

The concrete rules only arrived a year later, through DNSC Orders no. 1 and no. 2/2025, published in August 2025. The first says how you register. The second, how your risk level is calculated.

Does NIS2 apply to my company? Five questions

The questions below are a quick orientation, not an official classification.

An example, so none of this stays abstract

The company is invented, the situation is not. A transport company, 45 employees, EUR 9 million in turnover. It belongs to a group, alongside a warehousing company with 35 people.

At first glance it sits below the thresholds, so outside the law. We come back to it as we go.

1. Do you operate in one of the sectors listed in the annexes?

There are eighteen sectors in total: eleven of high criticality and seven other critical sectors. Among them: energy, transport, health, water, digital infrastructure, managed network and information system services, manufacturing, food production, waste management.

2. Do you have more than 50 employees, or over EUR 10 million in turnover or balance sheet total?

Those are the thresholds that make a company medium-sized. Below them you count as small or micro, and you usually stay outside the law.

3. Are you the sole provider of a service someone else depends on?

Here size stops protecting you. A small company can be pulled in precisely because it has no substitute.

4. Do you supply an essential or important entity?

You don't automatically fall under the law. But it affects you anyway, and we explain below why.

5. Do you operate across two or more of the listed sectors?

The law is clear here: you have to meet the measures for the highest of those levels, not an average.

If you answered yes to the first two, you have a serious reason to verify your classification formally, before concluding that the law doesn't apply to you.

That formal check can be started today, with the official tool. DNSC publishes an Excel file, the NIS2@RO instrument, which you download and fill in locally. It gives you a preliminary read on your classification, and the registration form is generated from the same file. Further down we cover where to get it and how it works.

Why classification is more complex than it looks

The five questions above point you in the right direction. They do not give you a classification, because the law builds one in several steps, and the order of those steps matters.

  • Activity first, size second. You check first whether the activity you actually carry out falls into one of the sectors in the law, and only then whether the company crosses the thresholds. What counts is what you do, not every activity code you happen to have registered.
  • Size is not calculated on your company alone. The thresholds follow the rules in small and medium enterprise legislation, which require the data of linked and partner enterprises to be included, meaning the companies that own you, that you own, or with which you share control. The company in our example has 45 employees of its own, but 80 together with the warehousing company in the group. It crosses the threshold without hiring anyone.
  • Some entities are in scope whatever their size. Sole providers of a service someone else depends on, entities individually designated by the authority for their strategic role or systemic impact, and those classified as critical under critical entity resilience legislation.
  • Others are excluded entirely. Institutions in the fields of defence, public order and national security do not fall under this ordinance.
  • The assessment is done per service, not per company. You look at each service you provide that might fall into the annexes of the law, not at the company as a block. A company can have one service in scope and everything else outside it.
  • Classification is not permanent. You redo it whenever something changes: you cross a threshold, enter a new sector, buy or sell a company.

Four recommendations, so you don't get the classification wrong

  • 1. Do not start from the headcount. Start from what the company does, day to day. If the activity is not in a listed sector, the rest of the discussion does not matter.
  • 2. Ask your accountant for the group-level calculation. With linked and partner enterprises included. This is the single most common place where a company believes it is out of scope and is not.
  • 3. Document the analysis, with a date and the name of whoever did it. In a review, what counts is that you analyzed it and when, not only what you concluded.
  • 4. Do not decide on your own that it doesn't apply to you. It is the one conclusion in this whole process that cannot be corrected retroactively. The other steps can be caught up late; a classification that is wrong on the low side usually surfaces when it is too late.

A note on who does what, so you don't ask either side for something they cannot give. Legal classification, the notification and the paperwork are handled with a consultant or a lawyer. A managed IT provider, which is what we are at Risksoft, can tell you what equipment you have, who has access to what, and which security measures are missing. These are two separate conversations, and mixing them is the most common way to lose time.

Essential or important entity? What the difference means

The two terms run through the whole law, and both the deadlines and the fines depend on them. Almost nobody explains what they mean, so here goes.

Essential entities are companies in the sectors considered critical: energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, public administration. Large companies also land here, meaning over 250 employees or over EUR 50 million in turnover, in any of the sectors covered by the law.

Important entities are the other companies in scope: generally medium-sized enterprises in sectors such as digital services, IT service providers, waste management, food production, postal and courier services.

Many medium-sized companies in the covered sectors are classified as important entities, but the category has to be verified against the sector and the criteria that apply to your company.

The company in our example, transport, medium-sized: most likely an important entity. That means 150 days before DNSC decides, and a lower ceiling on fines. The security obligations, however, stay the same as for an essential entity.

What that changes in practice, if you are an important entity:

  • you get more time before DNSC decides, 150 days instead of 60;
  • the ceiling on fines is lower;
  • the supervision regime is lighter than for essential entities.

The security obligations themselves, however, are the same. The difference is in oversight and penalties, not in effort.

Careful: „essential" means two different things

This is the most common confusion in NIS2 conversations, and it comes from the same words being used in two contexts that are not directly connected.

  • The classification of the entity: essential or important. It follows from the sector you operate in and from your size, and DNSC confirms it through a decision.
  • The level of measures: Basic, Important or Essential. It follows from the risk score calculated under the methodology in Order no. 2/2025, and it tells you how many security measures you have to implement.

In other words, you can be classified as an important entity and still land on the „essential" level of measures, if your risk score comes out high. Or the other way round. When someone tells you „you are essential", ask which of the two they mean, because the implementation effort depends on the second, not the first.

What measures the law actually requires

So far we have covered who is in scope and by when. Next comes the question everyone asks immediately after: what do I actually need to have in place?

Article 11 of the ordinance requires technical, operational and organizational measures, proportionate to the risk, to the size of the company, and to the impact an outage of your service would have. It is not a list of products, but a list of areas you have to cover. Here is what each one means, in documents and practices you either have or do not have:

  • Risk analysis and security policy. A document setting out which systems you have, what can happen to them, and what you do to stop it happening. Approved by management, with a date on it. Without this document, none of the other measures has anything to rest on.
  • Incident handling. A written procedure saying who decides an event is an incident, who you call in the first hour, what gets recorded, who informs affected clients, and who submits the report to the authority. Walked through at least once as a drill, not merely written.
  • Continuity and recovery. Backups that run automatically, are kept separately from the main system, and are test-restored periodically. Plus a committed time in writing: how long each service has to be back after an outage.
  • Supply chain security. A list of the suppliers who touch your data or systems, what access each has and for how long, plus security clauses in their contracts. This also covers the rules for acquiring, developing and maintaining systems.
  • Access control, assets and authentication. An inventory of equipment and accounts. Rights granted by role rather than by person, and reviewed periodically. A procedure for closing access when someone leaves. Two-step authentication on admin accounts and on those with access to sensitive data.
  • Cyber hygiene and employee training. Updates applied on time, minimum rights, passwords that are not reused, encryption wherever data leaves the company. Training for employees, with a record of who attended and when.
  • Checking that the measures work. Procedures for periodically testing whether what you implemented actually holds, plus the cybersecurity audit, at a frequency set by DNSC order.

A simple test for each of them: if an auditor asked you for the evidence tomorrow, what would you show? If the answer is „I would explain how we do it", the measure does not exist yet.

The detail that changes the inventory conversation: on request from DNSC, the company has to provide the list of relevant assets, meaning the equipment, systems and applications the service depends on, together with the list of risks identified in the analysis. In other words, an inventory of equipment and access is no longer a good practice you postpone. It is a document you can be asked for.

And one more requirement that touches the org chart, for essential entities: the person responsible for network and information system security has to operate independently of the company's IT structures. Public administration, small and micro enterprises are exempt.

How you register with DNSC and what deadlines follow

The general registration deadline fell in September 2025. The rule that matters now is a different one: you have 30 days from the moment you come into scope, whether you cross 50 employees, enter a listed sector, or complete an acquisition.

From there, everything is counted in days, and each deadline starts from the one before it. They add up faster than they look:

  • DNSC issues the identification and registration decision: 60 days from receiving the notification for essential entities, 150 days for important ones. These are deadlines for the authority, not for you. (art. 18 para. 4 and 5)
  • Within 30 days of the decision being communicated, you formally appoint the person responsible for network and information system security. (art. 14 para. 3)
  • Within 60 days of the decision being communicated, you submit the risk level assessment. It shows how much disruption an outage of your service would cause to others. (art. 18 para. 6)
  • Within a further 60 days of submitting that assessment, you complete the maturity self-assessment: which security measures you already run and how well they work. It repeats annually. (art. 18 para. 7)

Running through all of it, permanently: a significant incident has to be flagged through an early warning, meaning a short message saying something has happened, before you have all the details, within 24 hours, described in a report at 72 hours, and closed with a final report at 30 days. These are calendar days, not working days. An incident on a Friday evening does not wait until Monday. Reporting goes through the national platform, PNRISC.

Where to download the DNSC tools

For each stage, DNSC provides two mechanisms: one online, on the platform, and one downloadable for when the platform is unavailable. They all start from the same official page, entity registration.

  • For classification and for the notification form: the NIS2@RO platform, with a user account, at platformanis2.ro. When the platform is unavailable, you use the NIS2@RO instrument, version 2.3. The form is generated through one of those two, and nowhere else.
  • An English version of the instrument exists and can be downloaded here. It is useful if the person deciding does not read Romanian. One caveat: the form is submitted to DNSC in Romanian. The English version is there to help you understand what is being asked.
  • For the risk level assessment: the ENIRE@RO instrument, downloaded from dnsc.ro or platformanis2.ro. It is also used for a pre-assessment, before you submit anything officially. It calculates a score based on the size of the company, the types of attack that are possible, the impact and the probability.
  • For the disruptive-effect analysis: DNSC has published a dedicated guide, version 1.0, supporting the self-assessment under Article 9 of the ordinance. You need it when the ordinary data does not make clear whether you are an essential or an important entity.
  • For the maturity self-assessment: the tools DNSC publishes for each of the three levels of measures. Essential entities also submit a plan for remedying the gaps found.

One practical note: the submission channel has already changed once since the orders came into force, and the platform was brought online gradually. Before you submit anything, check on dnsc.ro which channel is live at that moment, and whether the file you downloaded is still the current version.

What the NIS2@RO instrument actually does

Its official name says more than it appears to: an instrument for assessing scope and generating notification data. It does two things, in this order.

First it shows you where you stand. You fill in the company details, then the size: average annual headcount, net turnover and total assets. Then the services you provide, ticked by sector and sub-sector, the company's relationship with the Romanian state, and whether you also provide services in other EU countries. If that data does not settle whether you are essential or important, you also complete the section on disruptive effect. At the end you get a preliminary assessment: out of scope, important entity, or essential entity.

Then it generates the notification form, with the data already filled in, ready to be signed and submitted.

Two points from the instrument's own instructions, both counterintuitive:

  • The preliminary assessment is not a classification. The form goes to DNSC whatever the result says, so the authority can confirm your status. The file guides you through the notification; it does not excuse you from it.
  • If the result is „out of scope", DNSC recommends registering voluntarily, for companies in important sectors that are not in the annexes, and for those expecting to cross the thresholds soon.

The instrument runs locally, on your own machine, once downloaded. It is an Excel file, so you need Excel to open it. If you reuse it, reset everything you filled in previously first.

How the form is submitted, in four steps

  • You fill in the data, either on the platform or in the downloaded instrument.
  • You save the notification form as a PDF.
  • Your company's legal representative signs it: with a qualified electronic signature if you submit it electronically, or a handwritten signature if you submit it on paper.
  • You send it to evidenta@dnsc.ro, together with supporting documents where applicable, or you deliver it on paper to the DNSC office at Strada Italiană 22, sector 2, Bucharest.

If you used the downloadable instrument because the platform was unavailable, you are still required to create an account on the NIS2@RO platform once it becomes available.

Who to call at DNSC

Three numbers and two addresses, depending on what you need:

  • Records and support: (+40) 316.202.167
  • Verification and control: (+40) 316.202.156
  • Auditor accreditation and authorisation of training providers: (+40) 316.202.182
  • evidenta@dnsc.ro, where the notification form is sent
  • nis@dnsc.ro, where you ask for help with identification, amendment or removal

Who is legally accountable: management or the IT department?

Management. And it is stricter than most owners expect.

Article 14 of the ordinance says that management bodies approve the security measures, supervise how they are put into practice, and are liable if they aren't. Members of management are also required to complete cybersecurity training.

This is where the clarification from the opening of this article comes in, added by Law 124/2025: the general meeting of shareholders and the board of directors are not „management bodies" within the meaning of this ordinance.

What that means for you: responsibility cannot be handed over wholesale to the IT department, nor pushed up to the shareholders. Exactly which individuals count as „management bodies" is determined by each company's legal form and management structure, so it is worth establishing who they are in your case before anyone signs anything.

That is not a legal detail. It is the reason security can no longer be a budget line you approve once and forget. It is also the reason the notification form requires the legal representative's signature, not the signature of whoever handles IT.

If there is another director or partner who signs contracts, this is the section worth passing on to them.

We're not in scope, but clients ask for proof. What now?

You answer the questionnaire. Not because the law requires it, but because your client does.

NIS2 requires companies in scope to manage the risks coming from their suppliers too. And they do that the only way they can: through contracts.

In practice, for a 40-employee company in none of the listed sectors: at contract renewal with a larger client, you receive a security questionnaire. As a rule, it asks for:

  • written security policies;
  • evidence that you take backups and that you test them;
  • two-step authentication;
  • a clear process for incidents;
  • sometimes, a certificate.

In practice it makes no difference that this is a commercial requirement rather than a legal one. If you cannot answer, you lose the contract. For most small and mid-sized companies, that is the closest cost of this subject, not the fine.

NIS2 fines in Romania

Sanctions are set out in Article 60 and come in two tiers.

  • Fixed fines, for administrative failures, meaning you did not submit the registration, the risk assessment, or the self-assessment on time: between RON 1,000 and RON 300,000 for important entities, between RON 1,500 and RON 500,000 for essential ones.
  • Fines for breaching the security obligations themselves: up to EUR 7 million or 1.4% of worldwide annual turnover for important entities, and up to EUR 10 million or 2% for essential ones.

Note the word „worldwide": the percentage is calculated on the whole group's turnover, not just on what you do in Romania.

Three things you can do today

These first checks can be started internally, without a complex project and without new purchases. And once they're done, you already have the answer to the first questions in any conversation on this subject, whether it comes from the authority, from an auditor, or from a client sending you a questionnaire.

The transport company in our example found out it was in scope only when its accountant ran the calculation at group level. Until then, the client's questionnaire sat unopened on the IT person's desk.

NIS2 questions we get asked most

Where do I download the DNSC notification form?

You don't download it ready-made. You generate it, either on the NIS2@RO platform or from the NIS2@RO instrument, the Excel file DNSC publishes on its entity registration page. You fill it in, save the result as a PDF, have the legal representative sign it, and send it to evidenta@dnsc.ro or deliver it on paper to the DNSC office.

The instrument says I am out of scope. Am I done?

No. The instrument's own instructions call for the form to be submitted to DNSC regardless of the result, so your status can be confirmed. What you get is a preliminary assessment that guides you through the notification. On top of that, if your company sits in an important sector that is not in the annexes, or you expect to cross the thresholds soon, DNSC recommends registering voluntarily.

Does NIS2 apply to companies with fewer than 50 employees?

As a rule, no. The exceptions are companies providing a service with no substitute, and those individually identified by the authority. If you supply a larger company in a listed sector, you are not bound by the law, but you will receive the requirements through your contract.

What counts as a „significant incident"?

Not every phishing email. The law targets incidents with real effect: those causing serious disruption to the service or financial loss, and those affecting other people or organizations through material or other damage. One infected laptop, isolated in ten minutes, does not belong here. An outage of the service you provide to clients does. If you hesitate, ask before letting the 24 hours run out.

What happens if I missed the registration deadline?

The deadline passing does not remove the obligation to register. If you are past it, the situation is worth reviewing and putting right as soon as possible, documenting when the company established the obligation and when it started the process. For a specific case, ask a consultant or a lawyer before you submit anything.

How long does it take to prepare for NIS2?

It depends where you start. Add up the statutory deadlines and you get several months from registration to self-assessment, in the best case. The part that takes longest is not the paperwork. It is the inventory: who uses which device, what access they hold, and who closes it when they leave. We wrote about that part separately, in the article on the accounts of an employee who leaves the company.

Does ISO 27001 make me NIS2 compliant?

No. These are two different things. One is a standard for managing information security, the other is a legal obligation with deadlines, notifications, and a register held by the authority. A certified system helps, because part of your practice is already documented, but it does not save you a single step of the legal procedure.

Who submits the notification to DNSC?

The company, through its legal representative. A consultant or a supplier can prepare it, but the declaration belongs to the company, and the liability stays with its management bodies.

About Risksoft

We have managed IT infrastructure for over 70 companies in Romania for 25 years. Most of them have between 10 and 300 employees.

Our own information security management system is certified to ISO/IEC 27001:2022 and externally audited every year. You can check the certificate yourself, in a public database.

Certificate no. RO231109006 · issued by LMS Assessments Limited · verify it in IAF CertSearch

Want to see where you stand?

The legal side, scope and registration, is handled with a consultant or a lawyer. We take care of what sits underneath, as part of managed IT: the asset inventory, who has access to what, backups and the testing of them, authentication, incident handling.

In 45 minutes we look at what you have today, and you leave with a written list: what is covered, what is missing, and the order worth fixing it in.

Book the review

The conversation is free and commits you to nothing.

This article reflects the legal framework in force at the date of publication and is general in nature. It is not legal advice. Legislation changes and the DNSC tools are reissued in new versions; for your company's classification, check the current text on the Romanian Legislative Portal and the current version of the tools on dnsc.ro, or consult a specialist.

See all articles