Romania NIS2: The 50% Repeat-Infringement Uplift DNSC Can Apply — and the €10M Fine Tiers Behind It
Romania completed its NIS2 transposition ahead of most EU member states, adopting Government Emergency Ordinance No. 155/2024 (GEO 155/2024) on 30 December 2024 and refining it through Law No. 124/2025. The base penalty structure mirrors Article 34 of NIS2 Directive (EU) 2022/2555 — €10 million or 2% of global turnover for essential entities, €7 million or 1.4% for important ones — but Romania added provisions the EU Directive does not mandate.
The most consequential of these is the 50% repeat infringement uplift introduced by Law 124/2025. For a company already facing a €10 million fine, a second violation under Romanian law raises the ceiling to €15 million. For a large essential entity where the turnover-based calculation applies, the repeat exposure scales with revenue and is not capped at the nominal figure.
This article explains Romania’s fine tiers under GEO 155/2024, how the 50% uplift works and what triggers it, the full ladder of DNSC supervisory measures from binding instructions to management disqualification, and the pharmaceutical sector expansion that Law 124/2025 added to the scope.
Essential vs. Important Entities: Who Romania’s Rules Target
Romania’s NIS2 framework classifies in-scope organisations into two categories with different penalty ceilings and supervisory intensities. Understanding which category applies to your organisation is the necessary first step before assessing fine exposure.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Entity Type | Classification Criteria | Sector Examples |
|---|---|---|
| Essential | Highly critical sector AND ≥250 employees or ≥€50M turnover | Energy, transport, banking, health, digital infrastructure, water |
| Important | Critical or highly critical sector, 50–249 employees or €10M–€50M turnover | Postal services, food, chemicals, waste management, manufacturing, digital providers |
The National Directorate of Cyber Security (DNSC) holds binding authority to register entities and confirm their classification. [5] For essential entities, DNSC has 60 days from notification to issue a classification decision; for important entities, 150 days. [5]
Whether your organisation is essential or important determines not just the maximum fine but how DNSC supervises you — a distinction with significant practical implications covered in the enforcement section below. The full scope criteria for both categories follow Annexes I and II of the NIS2 Directive. If your organisation operates in Romania, employs 50 or more people, and works in any of the 18 listed critical sectors, registration with DNSC is mandatory.
GEO 155/2024 Fine Tiers: The Complete Picture
GEO 155/2024 implements the fine structure from Article 34 of NIS2 Directive (EU) 2022/2555 directly. [1] Romania denominates all fines in Romanian leu (RON), calculated at the euro exchange rate in force at the time of the sanction. [6]
| Entity Type | Minimum Fine | Maximum Fine | Or, If Higher |
|---|---|---|---|
| Essential | RON equiv. €5,000 | RON equiv. €10,000,000 | 2% of total worldwide annual turnover |
| Important | RON equiv. €5,000 | RON equiv. €7,000,000 | 1.4% of total worldwide annual turnover |
The “or, if higher” column changes the exposure calculation for large multinationals significantly. An essential entity with €800 million in global annual revenue faces a maximum first-violation fine of €16 million (2% of €800M = €16M), because that figure exceeds the €10M nominal ceiling. [1] The calculation uses global revenue, not Romanian subsidiary revenue alone. [4]
Beyond monetary penalties, GEO 155/2024 authorises DNSC to impose complementary sanctions:
- Temporary suspension of activities — available for repeated or severe violations [8]
- Temporary prohibition from exercising management functions — a personal consequence directed at individual directors [8]
- Mandatory remediation orders — requiring specific vulnerabilities to be fixed within a binding timeframe set by DNSC [2]
- Mandatory customer notification — requiring entities to inform users about active cyber threats affecting their services [2]
The prescription period for offences under GEO 155/2024 is three years from the date of the infringement. [8]
The 50% Repeat Infringement Uplift — Romania’s Unique Provision
Law No. 124/2025, which formally approved and amended GEO 155/2024, introduced a mandatory 50% increase in the applicable fine for repeat violations. [4] This provision is not mandated by the EU Directive. Article 34 of NIS2 Directive (EU) 2022/2555 requires only that member-state fines be “effective, proportionate and dissuasive” — it does not prescribe a specific percentage multiplier for recidivism. [1] Romania’s legislature codified an explicit rate, replacing what had previously been a discretionary adjustment. [4]
| Entity Type | First Violation Cap | Repeat Violation Cap (+50%) |
|---|---|---|
| Essential | €10,000,000 | €15,000,000 |
| Important | €7,000,000 | €10,500,000 |
If the turnover-based calculation exceeds the nominal cap, the 50% uplift applies to that higher figure, not to the nominal ceiling alone. An essential entity with €800 million in global revenue faces €16 million for a first violation and €24 million for a repeat infringement. [1][4]
What constitutes a “repeat violation” under Romanian law has not yet been defined in DNSC implementing guidance. Until clarification is issued, prudent compliance practice treats any second NIS2 infringement by the same entity within the three-year prescription window as potentially triggering the uplift. This provision removes the nominal cap’s comfortable role as a ceiling for organisations that might otherwise treat a first penalty as an acceptable business cost.
Compare this with how other EU member states have approached the same issue: Germany’s enforcement framework and France’s ANSSI-led enforcement model both implement the base Article 34 tiers without a codified uplift percentage, leaving repeat-infringement increases to regulatory discretion. Romania’s explicit 50% rate provides more legal certainty — in the direction of higher exposure.
DNSC’s Enforcement Ladder: From Warnings to Management Bans
DNSC’s enforcement toolkit follows a progressive escalation model grounded in Articles 32 and 33 of NIS2 Directive (EU) 2022/2555, with the essential/important classification shaping both the tools available and the circumstances under which they are deployed.
| Step | Measure | Applies to | NIS2 Directive Basis |
|---|---|---|---|
| 1 | Written warning identifying the infringement | Essential + Important | Articles 32, 33 |
| 2 | Binding instruction specifying remedial measures and a compliance deadline | Essential + Important | Articles 32, 33 |
| 3 | Compliance audit order — essential entities face regular proactive audits; important entities face ad hoc audits triggered by incidents, complaints, or risk flags | Essential (proactive) / Important (reactive) | Articles 32, 33 |
| 4 | Public disclosure order — DNSC requires the entity to publicly disclose specific compliance failures | Important entities | Article 33 |
| 5 | Monitoring officer appointment — DNSC places a supervisory officer within the entity to oversee remediation | Essential | Article 32 |
| 6 | Temporary suspension of certifications or operating authorisations | Essential | Article 32 |
| 7 | Management disqualification — temporary prohibition on named directors exercising their functions | Essential | Article 32 |
The essential vs. important supervision asymmetry matters in practice. Essential entities face proactive supervision: DNSC can conduct scheduled audits and random checks without waiting for an incident to occur. [2] Important entities are supervised ex post — DNSC investigates following a breach notification, complaint, or sector-specific risk flag. [3] An essential entity in energy, banking, or digital infrastructure should treat periodic DNSC contact as routine, not as a signal of suspicion.
For important entities specifically, public disclosure (Step 4) operates as a powerful reputational lever. A DNSC order requiring an entity to publish specific compliance failures is often commercially more damaging than the monetary fine itself, particularly in sectors with consumer or partner trust dependencies. [3] The public disclosure authority is explicitly enumerated in Article 33 of the NIS2 Directive and is not available to DNSC for important entities unless the supervisory conditions of that article are met.
Steps 6 and 7 — temporary suspension and management disqualification — require procedural safeguards and are reserved for cases where earlier measures have failed to secure compliance. [2] They are not first-resort tools. DNSC’s implementing Order No. 3/2025 sets out the detailed procedural rules for inspection activities, including the rights and obligations of entities during an inspection and the criteria for identifying and sanctioning offences.
Pharmaceutical Sector Expansion Under Law 124/2025
Law No. 124/2025 explicitly added three pharmaceutical entity types to Romania’s highly critical sector list, a step not required by the EU Directive. [4]
- Medicinal product distribution authorisation holders — entities licensed at the national level to distribute medicinal products
- Wholesale pharmaceutical and medical products distributors — NACE code 4646
- Specialised retail pharmaceutical stores (pharmacies) — NACE code 4773
This expansion reflects Romania’s stated policy priority of health system resilience, informed by supply chain vulnerabilities that became visible during the COVID-19 period. [4] The minimum transposition of NIS2 did not require member states to include pharmaceutical retail; Romania’s decision to do so places it among the more expansive national implementations in the EU.
Practical implications for pharmaceutical companies:
- Entities newly brought into scope must complete DNSC registration and risk assessment under the timelines established by DNSC Orders 1/2025 and 2/2025
- Retail pharmacies (NACE 4773) represent a large population of businesses that had no prior NIS2 obligations; the 50–249 employee threshold for important entity classification captures many mid-size chains and regional distributors
- The mandatory cybersecurity officer designation — within 30 days of receiving formal DNSC notification — applies from the moment of registration [4]
- Pharmaceutical companies that were already captured through the “manufacture of medical devices” or “production of chemicals” categories under GEO 155/2024 should verify whether Law 124/2025’s additions change their entity classification or fine ceiling
The essential or important designation for pharmaceutical entities depends on size, not sector alone: 250 or more employees or €50 million-plus in global annual turnover results in essential classification; 50–249 employees or €10–€50 million turnover results in important classification.
Management Liability and Board Accountability
GEO 155/2024 and Law 124/2025 introduce direct personal accountability for management bodies, not just organisational-level fines. Three provisions are particularly relevant for boards and directors.
Cybersecurity officer designation: Within 30 days of receiving formal notification from DNSC, entities must designate a named individual responsible for cybersecurity and report that person’s identity to DNSC. [4] Failure to comply is attributable to the management body and can independently trigger enforcement proceedings.
Mandatory training: Law 124/2025 upgraded cybersecurity training for all staff from discretionary to mandatory. Management bodies must specifically maintain “an adequate level of cybersecurity knowledge and skills” to perform risk oversight and governance decisions. [4] This obligation cannot be delegated to the IT function alone — the law requires board-level engagement with cybersecurity risk as a governance matter.
Management disqualification: DNSC can temporarily prohibit named individuals from exercising managerial functions, following escalation through earlier enforcement steps. [2] This measure is most likely to apply where an entity has received binding instructions, demonstrably failed to act, and where the compliance failure is attributable to deliberate inaction or gross negligence at management level. [10]
Directors who treat cybersecurity as an IT operational matter rather than a governance obligation create exactly the compliance profile that DNSC’s escalated enforcement measures are designed to address. The Article 23 incident notification obligations — 24-hour initial notification, 72-hour detailed report, 30-day final evaluation — are among the first places DNSC identifies management-level accountability gaps, because late or incomplete notifications often trace to unclear governance rather than a missing technical capability.
Key Compliance Deadlines Under DNSC Orders
DNSC issued two implementing orders on 20 August 2025, triggering a cascade of compliance obligations with defined timelines.
| Obligation | Deadline |
|---|---|
| Registration with DNSC via the NIS2@RO platform | 30 days from order — approximately 19–22 September 2025 [9] |
| Risk assessment completion | 60 days from registration [9] |
| Maturity self-assessment | 60 days from registration [9] |
| Remediation plan submission to DNSC | 30 days after self-assessment [9] |
| Cybersecurity officer designation | 30 days from DNSC formal notification [4] |
| First security audit | 12 months from registration; biennial thereafter [8] |
| Initial incident notification | 24 hours from awareness of a significant incident [8] |
| Detailed incident notification | 72 hours from awareness [8] |
| Final incident report | 30 days from initial notification [8] |
Entities that missed the September 2025 registration window are exposed to sanctions for the registration failure itself — a separate infraction from any substantive security obligation breach. [9] Registration does not apply retroactively; organisations that register late do not receive a clean compliance slate from the date of registration.
Frequently Asked Questions
Does the 50% repeat uplift apply to the nominal cap or to the actual fine imposed?
Based on the available legislative text, the 50% uplift applies to the applicable fine figure — whether that is the nominal ceiling (€10M for essential entities) or the higher turnover-based calculation (2% of global revenue where that exceeds €10M). [4] Until DNSC issues specific guidance, the prudent assumption is that the uplift applies to whichever of the two calculations produces the higher result.
Can DNSC require public disclosure for essential entities?
Public disclosure as an enumerated enforcement measure is specified in Article 33 of the NIS2 Directive, which governs important entity supervision. For essential entities, Article 32 provides a broader toolkit including monitoring officers, temporary suspension of authorisations, and management disqualification — measures that are generally more operationally severe than public disclosure alone. Significant compliance failures by essential entities often become public through DNSC’s incident coordination role regardless of formal disclosure orders.
Are Romanian pharmacies classified as essential or important entities?
The three pharmaceutical categories added by Law 124/2025 are included in the highly critical sectors list, but the essential or important designation depends on size. Entities with 250 or more employees or €50 million-plus in global annual turnover are essential; those with 50–249 employees or €10–€50 million turnover are important. [4][5] Most individual pharmacies fall into the important category; large national distribution chains or authorisation holders with significant operations may qualify as essential.
What if our Romanian subsidiary is small but the parent group is large?
The fine calculation uses “total worldwide annual turnover” of the entity, not just Romanian revenue. [4] If a large multinational group operates through a Romanian subsidiary, the subsidiary’s NIS2 classification and fine exposure are assessed against the group’s global consolidated revenue unless the subsidiary meets the criteria for independent classification. This is a point requiring specific legal advice for group structures.
Romania’s NIS2 implementation occupies the stricter end of EU member-state transpositions. The €10M/2% and €7M/1.4% fine tiers mirror the Directive, but the 50% repeat infringement uplift, the pharmaceutical sector expansion, and mandatory training obligations all represent national additions that exceed minimum transposition requirements. For compliance officers and boards operating in Romania, the practical implication is that a second NIS2 violation carries a fine ceiling beyond what the EU Directive itself contemplates — and DNSC’s progressive enforcement ladder means that inaction after a first enforcement action is the highest-risk compliance position any in-scope entity can take.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive (EU) 2022/2555, Article 34 — Administrative Fines
- NIS2 Directive (EU) 2022/2555, Article 32 — Supervisory and Enforcement Measures for Essential Entities
- NIS2 Directive (EU) 2022/2555, Article 33 — Supervisory and Enforcement Measures for Important Entities
- CMS Law: Romania Expands NIS2 Scope Under Law No. 124/2025
- Kinstellar: Cybersecurity — Romania Transposes the NIS2 Directive
- Copla: NIS2 Romania Compliance — Timelines, Fines, and Roadmap
- ClujIT: NIS 2 in Romania — Key Changes Under GEO 155/2024
- Grecu Partners: Romania and the NIS2 Directive
- Wolf Theiss: Deadline Approaches — NIS2 Registration and Risk Evaluation in Romania
- ISMS.online: NIS 2 Romania — DNSC Authority, CSIRT Response, Audit and Enforcement
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
