DNSC Romania NIS2 national cybersecurity authority network infrastructure

How to Register with Romania’s DNSC Under NIS2: NIS2@RO Tool, 30-Day Window, and What Auditors Expect

Romania moved faster than most EU member states on NIS2 implementation. Government Emergency Ordinance 155/2024 entered force on December 31, 2024. Law 124/2025 followed in July, adding pharmaceutical wholesalers and retail pharmacies to scope — a sector expansion not found in any other member state’s transposition at the time of publication. Then, on August 20, 2025, the National Cybersecurity Directorate (DNSC) published two implementing orders that triggered the registration clock: entities had 30 days to notify, or face fines of up to RON 500,000.

If you operate in Romania and are covered by NIS2, you will deal with one institution across three distinct functions: regulatory supervision, compliance registration, and incident response. This guide explains those functions, walks through the NIS2@RO Tool registration process step by step, maps the five post-registration compliance milestones, and identifies the evidence trail DNSC auditors examine.

DNSC and CERT-RO: Two Names, One Institution

Romania’s National Cybersecurity Directorate — Directoratul Național de Securitate Cibernetică, or DNSC — is the competent authority responsible for NIS2 supervision, enforcement, and registration. Under Article 8 of Directive 2022/2555, member states must designate one or more competent authorities for cybersecurity; Romania consolidated that responsibility into a single institution.

The second name — CERT-RO — is where confusion enters. When DNSC was established by Government Emergency Ordinance 104/2021, it absorbed the former National Center for Response to Cyber Security Incidents, which had operated under the CERT-RO brand since Government Decision 494/2011. DNSC retained CERT-RO as the operational name for its national CSIRT (Computer Security Incident Response Team) function.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Function Operational brand What it covers
Entity registration, audit oversight, penalty enforcement DNSC (National Competent Authority) Supervision and regulatory enforcement of GEO 155/2024
Cybersecurity incident notification (24h/72h reports) CERT-RO (national CSIRT) DNSC’s operational incident response team
Cross-border NIS2 coordination with EU/ENISA DNSC (single point of contact) Cooperation with other member state authorities

DNSC also acts as Romania’s single point of contact under Article 8 of the Directive, handling cross-border cooperation with other national authorities and ENISA. These are not two separate organisations: same address, same director, same budget. The distinction matters in practice because registration submissions and compliance correspondence go to DNSC’s regulatory mailbox, while incident early warnings go to CERT-RO’s operational team. Sending an incident notification to the registration channel — or compliance documentation to the incident team — creates processing delays that DNSC can treat as non-compliance.

Does NIS2 Apply to Your Organisation?

NIS2 scope in Romania follows Article 3 of Directive 2022/2555, implemented through GEO 155/2024 as amended by Law 124/2025.

Essential entities are organisations in Annex I sectors — energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space — that exceed medium-enterprise size thresholds (more than 250 employees or annual turnover above €50 million, per EU Recommendation 2003/361/EC). Qualified trust service providers, top-level domain name registries, and DNS service providers qualify as essential regardless of size.

Important entities are medium-to-large organisations in Annex I or Annex II sectors that do not reach the essential threshold. Annex II adds postal services, waste management, chemicals, food production, manufacturing, digital providers, and research organisations.

Romania’s Law 124/2025 added two sectors not found in the original Directive: pharmaceutical wholesalers (CAEN code 4646) and retail pharmacies (CAEN code 4773). If your organisation falls in either category, you are in scope regardless of whether counterparts in other EU member states face the same obligation.

Excluded from scope: defence, national security, law enforcement, and systems handling classified information.

Organisation type Sector Size threshold NIS2 classification
Large enterprise Annex I >250 employees or >€50M turnover Essential
Medium enterprise Annex I or II 50–250 employees, €10M–€50M turnover Important
Small/micro enterprise Annex I or II <50 employees Generally out of scope (exceptions apply)
DNS provider or QTSP Any No size floor Essential
Pharmacy or pharma wholesaler Romania-specific (Law 124/2025) Any size In scope

Edge cases — particularly SMEs embedded in critical supply chains or providing DNS resolution services — are covered in the essential vs important entity classification guide.

The NIS2@RO Tool: How Registration Actually Works

Registration operates in two phases. The first uses the NIS2@RO Tool, an interim mechanism currently active on the DNSC website. The second phase — the NIS2@RO Platform — is a dedicated compliance portal under development; DNSC had not published a confirmed launch date as of June 2026.

Current process: NIS2@RO Tool

The NIS2@RO Tool generates a PDF notification form. Entities download the tool, complete all required sections, sign the form, and submit it by email to evidenta@dnsc.ro. When the NIS2@RO Platform launches, entities that registered through the Tool will need to create individual accounts and re-enter their data into the Platform — registration via the Tool does not carry over automatically.

The notification form has six mandatory sections:

  1. Entity identification — legal name, registered address, legal representative details
  2. Size metrics — employee headcount, annual turnover, total assets
  3. Self-assessment results — four pre-registration checks: service disruption impact under Order 2/2025 criteria, critical entity status under resilience legislation, dependence on national-interest telecommunications infrastructure, and sole-provider status for essential services
  4. Supporting documentation — financial statements, ONRC company extracts, evidence substantiating your self-assessment answers
  5. Proposed classification — your assessment of essential or important entity status, with CAEN sector codes from the applicable Annex
  6. Legal representative authorisation — signed authorisation for the individual completing the notification

Qualified electronic signatures are the standard requirement. For submissions via the NIS2@RO Tool specifically, handwritten signatures on the PDF are accepted.

ENIRE@RO: the risk pre-assessment tool

Before completing section 3 of the form, entities can run a preliminary cybersecurity risk calculation using the ENIRE@RO Tool, downloadable separately from the DNSC website. This tool processes four variables — attack type exposure, threat actor profile, entity size, and service disruption probability — and produces a preliminary risk score (basic, important, or essential cybersecurity requirements). The ENIRE@RO result informs your section 3 answers but is not submitted to DNSC at the registration stage; it becomes relevant again at the 60-day risk assessment milestone.

DNSC processing timelines

After receiving your notification, DNSC has up to 60 days to confirm registration for essential entities and up to 150 days for important entities. During this window, DNSC may request additional documentation. Incomplete form sections — particularly missing financial statements or unsupported self-assessment answers — are the most common cause of processing delays and restarts.

The NIS2 entity registration guide covers how other EU member states structure their registration processes and what documentation patterns typically satisfy competent authorities across jurisdictions.

The 30-Day Registration Window: Mechanics and Ongoing Obligations

DNSC Orders 1/2025 and 2/2025 entered force on August 20, 2025. From that date, entities already in scope had 30 calendar days to submit their notification form — placing the original deadline at approximately September 19, 2025.

Late registration and new entrants

The September 2025 window applied to organisations identifiable as essential or important when the orders entered force. Entities that become covered later — through growth, acquisition, or a change in sector activity — face the same 30-day clock running from the date they first meet the qualifying criteria. DNSC does not proactively identify in-scope organisations: self-identification is the entity’s obligation.

Ongoing notification obligations

Registration is not a one-time event. Any material change to the data in your notification form — legal representative change, address update, new sector activity, changed public IP ranges — must be reported to DNSC within a further 30-day window following the change.

Penalties for non-notification

Failure to register within the required window is a standalone violation, assessed separately from any security measure deficiencies. Fines range from RON 1,000 to RON 300,000 for important entities and from RON 1,500 to RON 500,000 for essential entities. Repeat violations attract a 50% uplift on the base fine. An entity that has also failed to submit a risk assessment and missed an incident notification window can face multiple concurrent fines, each calculated independently.

After Registration: Five Compliance Milestones

DNSC’s formal confirmation of your registration status starts a second compliance clock. Five sequential obligations follow from that confirmation date:

Milestone Deadline from DNSC confirmation What is required
1. Appoint cybersecurity officer 30 days Designate the person responsible for cybersecurity decisions; this role must operate independently from the Head of IT
2. Risk-level assessment 60 days Submit formal cybersecurity risk assessment using the Order 2/2025 methodology via NIS2@RO Platform (or ENIRE@RO Tool if Platform unavailable)
3. Maturity self-assessment 120 days (60 days after risk submission) Evaluate current cybersecurity measure maturity across Article 21 measure categories
4. Remediation plan submission 150 days (30 days after maturity assessment) Submit gap-closure plan to DNSC addressing weaknesses identified in the maturity assessment
5. Ongoing periodic audits Recurring Conduct cybersecurity audits at regular intervals; communicate results to DNSC

The maturity assessment score drives the intensity of ongoing DNSC supervision. Entities at basic maturity should expect more frequent audit requests and tighter scrutiny of remediation plan progress than those demonstrating important or essential-level controls from the outset.

Management body involvement is mandatory throughout this cycle. Article 20 of the Directive requires management bodies to formally approve the cybersecurity risk-management measures adopted under Article 21, oversee their implementation, and document both. Management body members must also complete regular cybersecurity training; DNSC has published a list of recognised certifications for the cybersecurity responsible person, and board-level training programmes satisfy the governance training obligation.

What Auditors Examine: The Evidence Trail

DNSC audits — whether scheduled or triggered by an incident — examine evidence, not stated intentions. Enforcement patterns emerging from early NIS2 audits across the EU consistently show that findings more often result from missing documentation than from the scale of an actual security failure.

Management approval trail. Board minutes or written resolutions documenting the management body’s approval of cybersecurity risk-management measures under Article 21. Article 20 of the Directive makes this approval mandatory and places personal liability on management body members for non-compliance under Romanian law. Oral decisions are not auditable.

Cybersecurity officer appointment record. Written appointment documentation, a role description showing operational independence from IT leadership, and evidence of recognised training qualifications from DNSC’s published certification list.

Risk assessment documentation. A completed risk register covering the threat categories specified in Order 2/2025 Annex 2, with mitigation actions mapped to each identified risk and a record of the ENIRE@RO Tool output used to generate the preliminary risk score.

Incident response records. Logs confirming that all significant incidents were reported to CERT-RO within the required timeframes — 24-hour early warning, 72-hour follow-up. Missing or backdated incident logs are among the most cited findings in NIS2 audit reports across the EU; DNSC’s own guidance notes that audit outcomes most often turn on incomplete paper trails.

Remediation plan and progress evidence. Documentation showing that gaps identified in your maturity self-assessment are being actively closed — with timelines, named owners, and completion status — not merely listed.

For entities contesting DNSC findings, the appeals mechanism runs through the Bucharest Court of Appeal, with a 15-day filing window from the date of the DNSC decision.

Incident Reporting to CERT-RO

For cybersecurity incidents that significantly affect service delivery, GEO 155/2024 — implementing Article 23 of the Directive — imposes a three-stage reporting obligation to CERT-RO, DNSC’s operational CSIRT. An incident is reportable under Article 23 when it causes or could cause severe operational disruption or financial loss, or when it has affected or could affect third parties through considerable material or non-material damage.

Stage Deadline Content required
Early warning Within 24 hours of becoming aware Suspected cause; cross-border impact assessment
Incident notification Within 72 hours Updated assessment; initial impact scope; measures applied so far
Final report Within 1 month of incident notification Full description, root cause, mitigation steps, cross-border effects

For trust service providers, the 24-hour early warning timeline carries additional urgency requirements. The Article 23 incident notification guide covers the significance thresholds in detail, how to structure each report stage, and how to coordinate with CERT-RO when an incident has cross-border implications.

Frequently Asked Questions

Is DNSC the same as CERT-RO?
They are the same institution operating under two functional identities. DNSC was created in 2021 and absorbed all CERT-RO functions. CERT-RO remains the operational brand for DNSC’s incident response team. For NIS2 registration and compliance correspondence, engage DNSC’s regulatory function. For incident notifications, the receiving team operates under the CERT-RO identity.

What is the NIS2@RO Platform and when does it launch?
The NIS2@RO Platform is a dedicated compliance portal for registration, risk assessment uploads, and ongoing submissions. As of June 2026, DNSC has not published a confirmed launch date. The NIS2@RO Tool remains active in the interim. Entities should monitor dnsc.ro for announcements.

What if I missed the September 2025 registration deadline?
Entities already in scope in August 2025 that have not yet registered are exposed to penalties. The recommended course is to file the notification immediately, before DNSC opens an enforcement action. Voluntary late filing with supporting remediation documentation typically results in a lower assessed fine than a DNSC-initiated finding. Consult a qualified legal professional on your specific situation.

Can SMEs be in scope?
Generally no, but exceptions apply. Micro and small enterprises that provide DNS services, operate top-level domain registries, or hold qualified trust service provider status are in scope regardless of size. Some SMEs may also be designated by DNSC based on critical supply chain role or sole-provider status for an essential service.

Do penalties stack across multiple failures?
Each distinct violation — non-registration, failure to submit a risk assessment, missed incident notification — is assessed as a separate infraction. An entity can face concurrent fines across multiple failures, with the 50% repeat-violation uplift applied independently on each.

Key Takeaways

DNSC is the institution where you register, get audited, and face enforcement action. CERT-RO is the operational name for the same institution’s incident response function — the team that receives your 24-hour early warnings. The NIS2@RO Tool is the current registration mechanism; the NIS2@RO Platform will replace it at a date DNSC has not yet confirmed. The September 2025 initial window has passed, but the 30-day obligation applies to any entity that newly meets the criteria. After DNSC confirms your registration, five sequential milestones run over 150 days. Auditors look for documented evidence — approval minutes, appointment records, risk registers, incident logs. Enforcement activity is expected to increase through 2026; early registration with a complete evidence trail is the lowest-cost route to compliance.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: