NIS2 · National implementation
NIS2 in Romania
Romania transposed NIS2 through Government Emergency Ordinance 155/2024, approved and adjusted by Law 124/2025, effective from 31 December 2024 with obligations phasing through 2025.
- National law
- OUG 155/2024, as amended by Legea 124/2025
- Government emergency ordinance implementing NIS2
- Status
- In force
- In force
- 31 December 2024
- Authority
- DNSC
Supervision
The DNSC (Directoratul Național de Securitate Cibernetică) is the national authority and CSIRT. Entities self-identify and register with DNSC within the statutory window, and DNSC maintains the national registry.
What is specific to Romania
Using an emergency ordinance meant Romania moved fast but then adjusted the regime via the approval law — so Romanian entities must read OUG 155/2024 as amended by Law 124/2025, not the original. DNSC has been active with implementing orders on registration and incident reporting formats.
Official sources
Primary references: the national statute book at legislatie.just.ro and the national cybersecurity authority at dnsc.ro.
NIS2 in Romania: frequently asked questions
Last reviewed:
Related reading
Definitions
