Romania's NIS2 Regime: DNSC, Deadlines and Fines
While Brussels rewrites the EU's cybersecurity rulebook, Romania has already turned NIS2 into national law — and 2026 is the year the grace period starts to close. For any company operating in Romania, the questions are no longer theoretical: are you in scope, are you registered with the DNSC, and could you survive an audit.
How NIS2 landed in Romanian law
Romania transposed the NIS2 Directive through Government Emergency Ordinance (GEO) No. 155/2024, adopted on 30 December 2024 and in force from 31 December 2024. The ordinance sets out the categories of "essential" and "important" entities, their security obligations and the incident-notification regime, with the Directoratul Național de Securitate Cibernetică (DNSC) — Romania's National Cyber Security Directorate — as the competent authority.
The operational detail arrived in 2025. On 20 August 2025 the DNSC issued Order No. 1/2025 and Order No. 2/2025: the first sets the notification procedure and how information must be transmitted to the authority; the second defines the criteria and thresholds for what counts as a significant service disruption. Those orders turned GEO 155/2024 from principle into paperwork.
Registration and the 2026 posture
Entities in scope were required to register with the DNSC by 19 September 2025. Registration is not a formality — it is how the authority builds its map of who must comply and what they operate.
The DNSC has signalled that its priority for the first part of 2026 is voluntary compliance: helping companies understand their obligations and get their houses in order rather than immediately reaching for penalties. That is a window, not an amnesty. The legal obligations are already in force; the enforcement posture is simply, for now, cooperative. Organisations that read "voluntary" as "optional" are miscalibrating the risk.
The fines are real
NIS2's teeth are financial, and Romania kept them sharp. For essential entities, fines can reach up to €10 million or 2% of annual worldwide turnover, whichever is higher. For important entities, the ceiling is €7 million or 1.4% of worldwide turnover. Those figures deliberately echo the GDPR model: large enough that a data-security programme is cheaper than the penalty for not having one.
What Romanian entities should be doing now
The checklist is not exotic:
- Determine scope. NIS2 reaches far beyond "critical infrastructure" — digital providers, manufacturing, food, postal services, waste management and many mid-sized firms are pulled in. Assuming you are out of scope is the most common and most expensive mistake.
- Register with the DNSC if you have not, and keep your entity details current.
- Stand up an incident-notification path that meets the Order No. 1/2025 procedure — an early warning within tight deadlines, then a fuller report. Practise it before you need it.
- Manage the supply chain. NIS2 makes you responsible for the security of your vendors and dependencies, not only your own systems.
- Reduce blast radius. Encrypt sensitive data, minimise what any single system can expose, and avoid moving credentials and secrets through channels you do not control.
Romania's approach mirrors the wider EU trajectory covered in our companion piece on the EU cybersecurity package: harmonised obligations, a real incident-reporting duty, and penalties designed to make security the cheaper option. The difference is that in Romania the framework is not a proposal — it is already the law, and 2026 is when the DNSC starts expecting to see results.
