Romania’s Cybersecurity and Defence Law Connects Civil and National-Security Response
Romania’s Law 58/2023 created a national framework for cybersecurity and cyber defence that connects institutions, incident information and the providers whose technical services can reveal a wider threat.
Law No. 58 of 14 March 2023 was published on 15 March 2023. It establishes the legal and institutional framework for organising cybersecurity and cyber-defence activities, cooperation mechanisms and responsibilities for authorities and relevant legal persons.
The law sits beside Romania’s later NIS2 implementation. It should not be read as the ordinary civil NIS2 regime; its focus includes national security, defence, public order and government functions. Its importance for the technology sector is the way it formalises cooperation and information flows across those boundaries.
Cybersecurity and cyber defence are connected but distinct
The statute defines cybersecurity, cyber defence, incidents, risk management, supply-chain risk and resilience. Cyber defence concerns threats to systems supporting military-defence capabilities, while the broader security framework also addresses networks and systems supporting national functions.
That distinction affects escalation. A company may first see an event as fraud, ransomware or a vulnerability in a commercial product. Context can show that the same event affects public administration, strategic systems or national-security interests. Incident plans need a route for reassessment when the target, actor or affected dependency changes.
Teams should avoid a rigid “civil” or “defence” label at first contact. They should record facts, affected systems, customers, indicators and potential propagation, then engage the competent route on the basis of the applicable law and official instructions.
Technical security providers can hold national context
The law recognises providers of technical cybersecurity services—entities performing activities such as implementing, evaluating, monitoring and testing security measures or managing risk, threats, vulnerabilities and incidents.
These providers may see patterns that no single customer can observe: the same exploit across several networks, command infrastructure reused in different sectors or a compromised product update. The implementing framework allows competent authorities, in defined circumstances, to request incident, threat, risk or vulnerability information from such providers.
Providers therefore need a lawful-response process. It should verify the requesting authority and scope, preserve the request, identify responsive information, protect unrelated customer and personal data, and document disclosure. The process should also recognise legal secrecy, classification and contractual obligations rather than treating every request as an ordinary support ticket.
Supply-chain risk spans the lifecycle
The law’s definitions describe supply-chain cybersecurity risk across design, development, production, integration, implementation, configuration, use and disposal of software, hardware, systems and networks.
That lifecycle view is useful. A secure procurement checklist at purchase does not address an abandoned dependency, compromised update service or unsupported product five years later. Buyers need an inventory that connects products and service providers to critical functions, update mechanisms, administrative access and end-of-life dates.
Suppliers should retain provenance and vulnerability-handling evidence. Where a product supports Romanian public or strategic functions, disclosure routes and secure update capability can become more important than a point-in-time certificate.
National alert levels need local actions
The institutional framework includes national cyber-alert levels and coordinated response. An alert only changes security if organisations translate it into defined actions.
For each relevant level, an organisation should predefine monitoring changes, contact readiness, update restrictions, backup checks, supplier confirmation and executive reporting. Actions should be proportionate and reversible. An indiscriminate shutdown can cause the disruption the threat actor sought.
The record should show when an alert was received, who assessed it, which systems were relevant and which measures were taken. That evidence also helps after-action review.
The operating questions
Organisations touching relevant Romanian systems should ask:
- Which services could affect public, national-security or defence functions?
- Which authority or customer must be contacted for each context?
- Can a technical-service provider identify and disclose the minimum responsive information securely?
- Are product and supplier risks tracked across the full lifecycle?
- Do national alerts trigger rehearsed local measures?
- Can incident evidence be preserved for coordinated investigation?
Law 58/2023 treats cyber resilience as a network of responsibilities. The value of that network depends on controlled information sharing: fast enough to reveal a national pattern, disciplined enough to preserve confidentiality and clear enough that every participant knows when to act.
Official sources
- Romanian Legislative Portal: Law No. 58 of 14 March 2023
- Romanian Legislative Portal: 2024 methodology on cyber-alert levels
- Romanian Legislative Portal: rules for information requests to technical cybersecurity providers
Continue the series
- Next in Romania: Romania Transposed NIS2 by Emergency Ordinance
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



