NIS2 in Romania — GEO 155/2024, the DNSC, and clocks that start on a notice.
Romania transposed NIS2 by Government Emergency Ordinance 155 of 30 December 2024, approved with amendments by Law 124/2025 in force from 10 July 2025. The Directoratul Național de Securitate Cibernetică (DNSC) — established in September 2021 to take over the former CERT-RO — is both competent authority and national CSIRT. The secondary legislation that made the regime operational arrived on 20 August 2025, when DNSC Orders 1 and 2 of 2025 entered into force and started a 30-day registration clock.
TruSecure's Romanian entity is itself subject to this regime — one of the jurisdictions we operate in, met as a subject as well as described.
Who it applies to
Entities operating in the sectors of Annex 1 or Annex 2 to GEO 155/2024 that meet the size thresholds — with Law 124/2025 adding pharmaceutical wholesale and retail and medicinal-product distribution to Annex 1. Every such entity had to notify the DNSC for registration within 30 days of 20 August 2025, filing a service-disruption assessment with the form. Once the DNSC notifies an entity of its classification as essential or important, two further clocks start: a cybersecurity risk-level self-assessment within 60 days, and the appointment of persons responsible for network and information security within 30 days.
The clock
Competent authority: DNSC (Directoratul Național de Securitate Cibernetică). Transposition: GEO 155/2024, approved by Law 124/2025.
| When | What happens |
|---|---|
| 30 December 2024 | GEO 155/2024 transposes NIS2 |
| 10 July 2025 | Law 124/2025 approves the ordinance · pharmaceutical entities added · security-officer duty introduced |
| 20 August 2025 | DNSC Orders 1 and 2 of 2025 enter into force · 30-day registration window opens |
| On DNSC classification | Risk self-assessment within 60 days · responsible persons appointed within 30 days |
A regime built in orders, not a single act
Romania's transposition is layered: an emergency ordinance, an approving law that amended it, and DNSC orders that define the registration form, the service-disruption criteria and the risk-assessment methodology. The obligations that bite day to day — the self-assessment, the responsible-person appointment, the NIS2@RO platform filings — live in the orders and in DNSC's classification notices, not in the headline act. That is where teams lose track. TruSecure holds each DNSC instrument and each notice as a dated record against the entity, so the 60-day and 30-day clocks are computed from the actual notification date rather than remembered, and the self-assessment is generated from live control state instead of being written once and filed.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Romania transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Notify the DNSC for registration, with the disruption assessment | Entity profile · registration facts and filed assessments as records |
| File the risk-level self-assessment within 60 days of classification | Risk register · assessment generated from live control state, clock from the notice |
| Appoint responsible persons within 30 days of classification | Governance workspace · named owners, appointment dated |
| Report significant incidents: 24 hours, 72 hours, one month | Incident workflow · clocked from awareness, each stage pre-built from the last |
| Train staff regularly, and show it | Training records · per person, per cycle |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Classification
- essential · DNSC notice received
- Self-assessment
- filed · day 41 of 60
- Responsible persons
- 2 appointed · day 12 of 30
- Controls evidenced
- 56/61 · 5 open, each with an owner and a date
- Export
- sealed · sha256:4c9e...a1b3
Where teams usually start
With a demo walked through by TruSecure — your Annex 1 or Annex 2 position under GEO 155/2024, the clocks that follow a DNSC classification notice, the controls you already operate mapped against the ordinance, and the self-assessment generated in front of you. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Romania by DNSC (Directoratul Național de Securitate Cibernetică). TruSecure determines applicability against Romania's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.