
Romania Transposed NIS2 by Emergency Ordinance
Romania’s NIS2 framework arrived on the final day of 2024 through an emergency ordinance, turning a delayed transposition into an immediate scope, registration and governance exercise.
Emergency Ordinance No. 155 of 30 December 2024 was published and entered into force on 31 December 2024. It established the framework for a high common level of cybersecurity in Romania’s national civil cyberspace and designated the National Cyber Security Directorate, DNSC, as the central competent authority, supervisory body, single point of contact and national CSIRT.
Edit on the 12th of July 2025: Parliament later approved and amended the ordinance through Law No. 124 of 7 July 2025. Organisations should therefore use the current consolidated text, not an isolated copy of the original ordinance.
Immediate commencement did not mean complete implementation
The ordinance took effect on publication, while requiring DNSC to issue subordinate rules for scope thresholds, risk-management measures, incident reporting and registration. This creates a familiar compliance problem: the primary duty exists while operational details continue to develop.
Organisations should maintain a legal-change register that connects each DNSC order to the affected process. Waiting for a single final implementation manual can leave scope and contact work too late. Conversely, freezing the programme around the December 2024 text can miss later amendments.
Scope needs evidence at entity level
The framework covers essential and important entities in highly critical and other critical sectors, with annexes listing the relevant types of service. Size is important, but the ordinance also contains special rules and exclusions.
A group should assess each Romanian legal entity and service. Shared infrastructure does not make classification automatically shared. The file should include employee and financial data, service descriptions, sector mapping, exclusions and any DNSC decision concerning identification and entry in the register.
Once an entity is identified, management must designate responsible security personnel and maintain permanent contact means within the applicable period. Those contacts should be monitored functions with deputies, not individual mailboxes that fail during absence.
Management owns resources as well as approval
Governing bodies of essential and important entities approve cybersecurity risk-management measures, oversee their implementation and ensure the necessary resources. The ordinance also connects leadership to training and accountability.
That makes budget decisions part of the compliance record. If a material continuity gap is accepted because remediation is unfunded, the minutes should show the risk, reasoning, compensating measures and review date. A board cannot demonstrate oversight by approving a policy while having no view of the regulated services and their dependencies.
Incident reporting is staged
The NIS2 model requires rapid reporting of significant incidents: an early warning within 24 hours, a fuller incident notification within 72 hours and a final report generally within one month, subject to the detailed national rules.
The early warning may need to indicate whether malicious action is suspected and whether the event could have cross-border impact. It is not a demand for complete attribution. Teams should be able to notify while recording uncertainty and then update the account.
Supplier escalation needs to be faster than the external deadline. Contracts should require immediate notice of events that may affect the regulated service, named contacts, minimum facts, preservation of evidence and continuing updates.
DORA and national-security boundaries matter
The ordinance excludes defence, public-order and national-security institutions and classified systems from its ordinary scope, subject to specific exceptions and other Romanian law. It also limits the overlap for entities covered by the EU Digital Operational Resilience Act, applying specified provisions rather than duplicating the full operational regime.
An organisation should document which rule governs each service and incident. “We are regulated by DORA” is not a complete analysis if another group entity or non-financial service falls under the ordinance.
The implementation spine
Romanian entities should connect:
- current scope and registration evidence;
- services, systems, assets and suppliers;
- management approval, resources and training;
- DNSC orders and resulting control changes;
- permanent contacts and security-responsible persons; and
- staged incident decisions and reports.
Romania’s emergency route made the effective date dramatic, but the durable task is ordinary governance: keep the scope current, follow subordinate rules and make sure technical events reach DNSC through an authorised process before the reporting clock expires.
Official sources
- Romanian Legislative Portal: Emergency Ordinance No. 155/2024
- Romanian Legislative Portal: official publication and commencement record
Continue the series
- Also in Romania: Romania’s Cybersecurity and Defence Law Connects Civil and National-Security Response
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



