We help you get ready for NIS2 in Romania

Romania transposed NIS2 through OUG 155/2024, approved and amended by Law 124/2025, supervised by the DNSC.

Audit41 Readiness assesses you against the Romanian requirements, shows you exactly where you stand, and gives you the ranked actions to close each gap.

This page covers the Romanian NIS2 obligations. The Audit41 Readiness NIS2 variant for Romania is not available yet - the free self-check below determines your scope, and ISO 27001 and NIST SP 800-53 assessments are available now.

Check your Romania NIS2 scope
  1. 1

    Registration

    19 September 2025

  2. 2

    Measures

    60 plus 60 plus 30 days from registration

  3. 3

    Audit

    Article 11(5) obliges an audit. Periodicity is set by DNSC Director order under Article 12(1), still in draft

Which tier are you?

Essential entity

Entitate esențială. Organisations whose disruption would have a significant effect, in the covered sectors and above the larger size thresholds, plus certain entities identified by the DNSC regardless of size.

Penalties

Up to 10 million EUR or 2 percent of net turnover, whichever is higher.

Important entity

Entitate importantă. Organisations in the covered sectors that meet the size thresholds but are not essential.

Penalties

Up to 7 million EUR or 1.4 percent of net turnover, a distinct lower cap Romania sets for important entities.

Your obligations under OUG 155/2024

1

Determine whether you are an essential or important entity under the sector and size criteria, or by DNSC identification.

2

Register with the DNSC within the statutory window after you are identified as in scope, through the DNSC platform.

3

Appoint a person responsible for NIS2 within the statutory window after registration.

4

Implement the technical and organisational measures OUG 155/2024 requires, covering the risk-management areas the law lists.

5

Where required, submit a risk self-assessment to the DNSC within the statutory window after identification.

6

Undergo periodic cybersecurity audits, carried out by an auditor from the national Body of Cybersecurity Auditors.

7

Report significant incidents to the DNSC under the statutory timelines.

8

Provide continuous staff training and management preparation as the law requires.

OUG 155/2024 does not mandate a single standard. The DNSC recommends CyFun 2025, and ISO 27001 or NIST CSF also map onto the required measures. An ISO 27001 certification gives you a recognised structure, but certification does not replace the statutory measures or the cybersecurity audit.

Sectors in scope

EnergyTransportBankingFinancial market infrastructureHealthDrinking waterWaste waterDigital infrastructureICT service managementPublic administrationSpacePostal and courier servicesWaste managementChemicalsFoodManufacturingDigital providersResearch

The audit periodicity is not yet fixed

OUG 155/2024 requires periodic cybersecurity audits, but the frequency and methodology are set by a DNSC Director order that remains in draft and public consultation, not yet adopted. Any specific audit interval quoted today is provisional. We track the DNSC order and will reflect the final rule when it is published.

Audits by an attested auditor

Romania created a national Body of Cybersecurity Auditors, going beyond the NIS2 minimum. Your cybersecurity audit must be carried out by an auditor attested through this corps, so the pool of eligible auditors is defined and limited.

A distinct, lower cap for important entities

Romania sets a separate penalty ceiling for important entities, lower than the essential-entity maximum, rather than applying one cap to both. Your entity classification directly sets your maximum exposure.

A self-assessment of service disruption

Entities not already classified must self-assess the potential disruption of the services they provide, under the DNSC methodology, as part of establishing whether and how they fall in scope.

From gap report to audit-ready

Between registering with the DNSC and passing your cybersecurity audit, most entities reach for a consultant. Audit41 Readiness assesses you against the measures OUG 155/2024 requires and gives you the part that actually gets you ready: every gap ranked by severity, with the specific action that closes each one. Sage, the advisor built into the platform, explains what a requirement means when it is not obvious and helps you draft the policy text a fix needs. You leave with a prioritised list of what to do, not a number to interpret.

Page one of an Audit41 Readiness Assessment Report, showing a readiness score, the four band scale, a control breakdown, and the top critical gaps and priority actions.

Know where you stand on NIS2 in Romania

The free self-check applies the Romanian rules, tells you your entity type, and recommends the right assessment.

Check your Romania NIS2 scope

This self-check result is for information only. Audit41 and EMP42 Consulting Kft. accept no liability for the accuracy of the classification. Consult a qualified legal advisor before making a final decision.