Skip to main content
NIS2 · ROMANIA

NIS2 in Romania — GEO 155/2024, the DNSC, and clocks that start on a notice.

Romania transposed NIS2 by Government Emergency Ordinance 155 of 30 December 2024, approved with amendments by Law 124/2025 in force from 10 July 2025. The Directoratul Național de Securitate Cibernetică (DNSC) — established in September 2021 to take over the former CERT-RO — is both competent authority and national CSIRT. The secondary legislation that made the regime operational arrived on 20 August 2025, when DNSC Orders 1 and 2 of 2025 entered into force and started a 30-day registration clock.

TruSecure's Romanian entity is itself subject to this regime — one of the jurisdictions we operate in, met as a subject as well as described.

Who it applies to

Entities operating in the sectors of Annex 1 or Annex 2 to GEO 155/2024 that meet the size thresholds — with Law 124/2025 adding pharmaceutical wholesale and retail and medicinal-product distribution to Annex 1. Every such entity had to notify the DNSC for registration within 30 days of 20 August 2025, filing a service-disruption assessment with the form. Once the DNSC notifies an entity of its classification as essential or important, two further clocks start: a cybersecurity risk-level self-assessment within 60 days, and the appointment of persons responsible for network and information security within 30 days.

The clock

Competent authority: DNSC (Directoratul Național de Securitate Cibernetică). Transposition: GEO 155/2024, approved by Law 124/2025.

NIS2 in Romania · timeline
WhenWhat happens
30 December 2024GEO 155/2024 transposes NIS2
10 July 2025Law 124/2025 approves the ordinance · pharmaceutical entities added · security-officer duty introduced
20 August 2025DNSC Orders 1 and 2 of 2025 enter into force · 30-day registration window opens
On DNSC classificationRisk self-assessment within 60 days · responsible persons appointed within 30 days

A regime built in orders, not a single act

Romania's transposition is layered: an emergency ordinance, an approving law that amended it, and DNSC orders that define the registration form, the service-disruption criteria and the risk-assessment methodology. The obligations that bite day to day — the self-assessment, the responsible-person appointment, the NIS2@RO platform filings — live in the orders and in DNSC's classification notices, not in the headline act. That is where teams lose track. TruSecure holds each DNSC instrument and each notice as a dated record against the entity, so the 60-day and 30-day clocks are computed from the actual notification date rather than remembered, and the self-assessment is generated from live control state instead of being written once and filed.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Romania transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Romania requirements · how TruSecure answers them
What the law asksWhere it is answered
Notify the DNSC for registration, with the disruption assessmentEntity profile · registration facts and filed assessments as records
File the risk-level self-assessment within 60 days of classificationRisk register · assessment generated from live control state, clock from the notice
Appoint responsible persons within 30 days of classificationGovernance workspace · named owners, appointment dated
Report significant incidents: 24 hours, 72 hours, one monthIncident workflow · clocked from awareness, each stage pre-built from the last
Train staff regularly, and show itTraining records · per person, per cycle

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Romania NIS2 readiness file · excerptSample data
Classification
essential · DNSC notice received
Self-assessment
filed · day 41 of 60
Responsible persons
2 appointed · day 12 of 30
Controls evidenced
56/61 · 5 open, each with an owner and a date
Export
sealed · sha256:4c9e...a1b3

Where teams usually start

With a demo walked through by TruSecure — your Annex 1 or Annex 2 position under GEO 155/2024, the clocks that follow a DNSC classification notice, the controls you already operate mapped against the ordinance, and the self-assessment generated in front of you. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Romania by DNSC (Directoratul Național de Securitate Cibernetică). TruSecure determines applicability against Romania's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Is Romania's DNSC a new authority?
DNSC was established by Emergency Ordinance 104/2021 in September 2021, taking over the former CERT-RO, specifically for national cybersecurity oversight. TruSecure operates under the same authority.