Romania transposed the NIS2 Directive (Directive (EU) 2022/2555) through Ordonanța de urgență a Guvernului nr. 155/2024 (OUG 155/2024), signed 30 December 2024 and published in Monitorul Oficial nr. 1332 din 31 decembrie 2024. The Government's own preamble cites a first-quarter-2024 ransomware incident that compromised a managed-service provider and disrupted 26 hospitals nationwide as the specific trigger for the updated supply-chain-security and management-accountability duties.
Article 66(1)(a) repeals Romania's earlier NIS1-era statute, Legea nr. 362/2018 privind asigurarea unui nivel comun ridicat de securitate a rețelelor și sistemelor informatice, outright, so no predecessor regime survives alongside OUG 155/2024 the way Ireland's 2018 NIS Regulations survive pending its own Bill.
Multiple independent Romanian legal-commentary sources (Biris Goran, avocatnet.ro, EuroAvocatura, Lege5.ro) report that Parliament approved the OUG through Legea nr. 124/2025 din 7 iulie 2025 (Monitorul Oficial nr. 638 din 7 iulie 2025) by a single approving article; no primary text of Legea nr. 124/2025 itself was located for this review, so the fact and date of its approval rest on secondary reporting rather than a directly read primary source.
The OUG's own legislatie.just.ro portal page independently corroborates this within what this review did read: its "Forma consolidată" history note records the consolidated text as last revised 10.07.2025, three days after the reported publication date, consistent with the reported approval and commencement dates, though this review did not confirm whether Legea nr. 124/2025 changed any substantive provision or approved the OUG unchanged.
Articles 11 through 14 impose the risk-management duty and Articles 15 through 17 the incident-reporting duty; both took effect on the OUG's own publication date, 31 December 2024 (Article 65(4) delayed only Articles 60 and 61, the sanctions-enforcement machinery, by 30 days).
Article 11(1) requires an essential or important entity to take proportionate technical, operational and organisational measures across ten baseline categories mirroring NIS2 Article 21(2): risk-analysis and information-security policy and its periodic review, evaluating the effectiveness of risk-management measures, cryptography and encryption policy, supply-chain security including the relationship with direct suppliers and service providers, security of system acquisition, development, maintenance and decommissioning including vulnerability management and disclosure, human-resources security and access control and asset management, incident management, business continuity including backup management, disaster recovery and crisis management, basic cyber-hygiene practices and training, and multi-factor or continuous authentication.
Article 12(1) separately requires the DNSC director to issue an implementing order detailing the technical, operational and organisational requirements within 120 days of the OUG's entry into force (due by roughly 30 April 2025); this review did not confirm whether that order has since issued.
Article 14(1) requires the entity's governing body to approve these risk-management measures, supervise their implementation, and bear responsibility for them, and Article 14(3) requires it to designate a network-and-information-system security officer.
Article 15 sets a graduated incident-notification clock to the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC) run by the national CSIRT: an early warning within 24 hours of becoming aware of a significant incident (stating whether it is suspected unlawful, malicious, or cross-border in effect), a fuller incident report within 72 hours with an initial severity and impact assessment, an interim report on the CSIRT's request, and a final report within one month of the 72-hour report, or a progress report followed by a final report if the incident is still ongoing at that point, transposing NIS2 Article 23 on the same clock the corpus has already confirmed for Germany, Ireland, Lithuania, Portugal, Slovenia, Latvia, Estonia, Liechtenstein, Sweden and Slovakia.
Article 5 and Article 6, read with Article 8's cross-reference to Legea nr. 346/2004's SME criteria, bind a large or medium enterprise within the Anexa nr. 1 or Anexa nr. 2 sector lists as an essential or important entity respectively; central public-administration bodies and entities designated as critical entities under Romania's critical-entity-resilience legislation are essential regardless of size, and a public-electronic-communications-network or -service provider or a managed-security-service provider is essential even at only medium size.
Article 4's definitions (letters q, u and v) expressly recognise a piață online (online marketplace), a motor de căutare online (online search engine), and a platformă de servicii de socializare în rețea (social-networking-services platform) as digital-provider categories drawn from EU law, matching NIS2's own digital-provider sector; only this digital-provider slice is flagged on this jurisdiction's rows, and the wider sector classes OUG 155/2024 also reaches (energy, transport, banking, health, water, digital infrastructure, public administration, and the size-gated telecom and managed-security-service carve-outs) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.
Article 48 empowers DNSC to issue a warning or an amendă contravențională (administrative fine); Article 60(1) lists violating the Article 11(1) risk-management duty at letter a), and violating the Article 15(1) reporting clock or the duty to notify service recipients at letters l) and m), among the contravenții (regulatory administrative offences) it sanctions, unless the same conduct also meets a criminal offence's elements under separate law, in which case it is prosecuted as a crime instead of as this administrative offence.
Article 60(2)(a)-(b) applies the top penalty tier, the greater of a fixed euro-equivalent-in-lei cap or a percentage of net turnover, to a violation of letters a) through m) (which includes both the Article 11(1) risk-management duty and the Article 15(1) reporting-clock and notification duties): up to EUR 10,000,000 or 2 percent for an essential entity, and up to EUR 7,000,000 or 1.4 percent for an important entity, mirroring NIS2 Article 34(4) and (5) exactly; a separate Article 15(3) information-reporting violation at letter n) instead falls in the lower fixed-lei tier Article 60(2)(c)-(d) sets.
DNSC, the Directoratul Național de Securitate Cibernetică, enforces; its sanction decisions are reviewable in contencios administrativ before the Curtea de Apel București within 30 days without a mandatory prior administrative appeal, and this review found no private right of action.
No Romanian instrument reviewed here imposes a mandatory product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Romania has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, which sits in the privacy topic rather than here, and Article 62 of OUG 155/2024 separately requires DNSC to inform ANSPDCP, Romania's data-protection authority, without undue delay when a cybersecurity incident it supervises also implicates personal-data protection, a coordination duty distinct from an entity's own GDPR Article 33 and 34 breach-notification duty.