We help you get ready for NIS2 in Romania
Romania transposed NIS2 through OUG 155/2024, approved and amended by Law 124/2025, supervised by the DNSC.
Audit41 Readiness assesses you against the Romanian requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.
This page covers the Romanian NIS2 obligations. The Audit41 Readiness NIS2 variant for Romania is not available yet - the free self-check below determines your scope, and ISO 27001 and NIST SP 800-53 assessments are available now.
- 1
Registration
19 September 2025
- 2
Measures
60 plus 60 plus 30 days from registration
- 3
Audit
Article 11(5) obliges an audit. Periodicity is set by DNSC Director order under Article 12(1), still in draft
Which tier are you?
Entitate esențială. Organisations whose disruption would have a significant effect, in the covered sectors and above the larger size thresholds, plus certain entities identified by the DNSC regardless of size.
Penalties
Up to 10 million EUR or 2 percent of net turnover, whichever is higher.
Entitate importantă. Organisations in the covered sectors that meet the size thresholds but are not essential.
Penalties
Up to 7 million EUR or 1.4 percent of net turnover, a distinct lower cap Romania sets for important entities.
Your obligations under OUG 155/2024
Determine whether you are an essential or important entity under the sector and size criteria, or by DNSC identification.
Register with the DNSC within the statutory window after you are identified as in scope, through the DNSC platform.
Appoint a person responsible for NIS2 within the statutory window after registration.
Implement the technical and organisational measures OUG 155/2024 requires, covering the risk-management areas the law lists.
Where required, submit a risk self-assessment to the DNSC within the statutory window after identification.
Undergo periodic cybersecurity audits, carried out by an auditor from the national Body of Cybersecurity Auditors.
Report significant incidents to the DNSC under the statutory timelines.
Provide continuous staff training and management preparation as the law requires.
OUG 155/2024 does not mandate a single standard. The DNSC recommends CyFun 2025, and ISO 27001 or NIST CSF also map onto the required measures. An ISO 27001 certification gives you a recognised structure, but certification does not replace the statutory measures or the cybersecurity audit.
Sectors in scope
The audit periodicity is not yet fixed
OUG 155/2024 requires periodic cybersecurity audits, but the frequency and methodology are set by a DNSC Director order that remains in draft and public consultation, not yet adopted. Any specific audit interval quoted today is provisional. We track the DNSC order and will reflect the final rule when it is published.
Audits by an attested auditor
Romania created a national Body of Cybersecurity Auditors, going beyond the NIS2 minimum. Your cybersecurity audit must be carried out by an auditor attested through this corps, so the pool of eligible auditors is defined and limited.
A distinct, lower cap for important entities
Romania sets a separate penalty ceiling for important entities, lower than the essential-entity maximum, rather than applying one cap to both. Your entity classification directly sets your maximum exposure.
A self-assessment of service disruption
Entities not already classified must self-assess the potential disruption of the services they provide, under the DNSC methodology, as part of establishing whether and how they fall in scope.
From gap report to audit-ready
Between registering with the DNSC and passing your cybersecurity audit, most entities reach for a consultant. Audit41 Readiness assesses you against the measures OUG 155/2024 requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Know where you stand on NIS2 in Romania
The free self-check applies the Romanian rules, tells you your entity type, and recommends the right assessment.
Check your Romania NIS2 scopeThis self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.