NIS2 · National implementation

NIS2 in Romania

Romania transposed NIS2 through Government Emergency Ordinance 155/2024, approved and adjusted by Law 124/2025, effective from 31 December 2024 with obligations phasing through 2025.

National law
OUG 155/2024, as amended by Legea 124/2025
Government emergency ordinance implementing NIS2
Status
In force
In force
31 December 2024
Authority
DNSC

Supervision

The DNSC (Directoratul Național de Securitate Cibernetică) is the national authority and CSIRT. Entities self-identify and register with DNSC within the statutory window, and DNSC maintains the national registry.

What is specific to Romania

Using an emergency ordinance meant Romania moved fast but then adjusted the regime via the approval law — so Romanian entities must read OUG 155/2024 as amended by Law 124/2025, not the original. DNSC has been active with implementing orders on registration and incident reporting formats.

Official sources

Primary references: the national statute book at legislatie.just.ro and the national cybersecurity authority at dnsc.ro.

NIS2 in Romania: frequently asked questions

Last reviewed:

Related reading

All 27 EU member states