Skip to content
Cyber Security

NIS2: what it is and whether it applies to your company

NIS2 is law in Romania through OUG 155/2024. A practical guide for SMEs: how to check whether you are in scope, what you must do and why it matters anyway.

As of September 2026, NIS2 is no longer a conference topic. The DNSC has started sanctioning procedures, for now against the companies that never registered. The fines in the law start at 1,000 lei and can reach 10 million euros or a percentage of turnover.

Most of the business owners we talk to have heard of NIS2 and have two questions: "does it apply to me?" and "what exactly do I have to do?". This article answers both, in that order.

A necessary warning: we are not lawyers, and whether a company is in scope depends on its concrete situation. What follows is an orientation guide, not a legal opinion.

What NIS2 is, in short

NIS2 is the European directive on the cybersecurity of networks and information systems. Its purpose is simple to state: the companies the economy and society depend on must have a minimum, verifiable level of cybersecurity, and they must report serious incidents.

In Romania, the directive was transposed through Emergency Ordinance (OUG) 155/2024, in force since 30 December 2024, approved and amended by Law 124/2025. The competent authority is the National Cyber Security Directorate (DNSC), which keeps the register of entities, receives incident reports and applies the sanctions.

The law splits the companies in scope into two categories: essential entities (broadly, large companies in the critical sectors) and important entities (large and medium-sized companies in the targeted sectors that are not essential). The obligations are similar, but supervision and fines differ.

Does it apply to your company? Three questions

The biggest practical difficulty of NIS2 is precisely working out its scope. Not every company that uses computers falls under the law. The check takes three steps.

1. Do you operate in a sector listed in the annexes?

Annexes 1 and 2 of OUG 155/2024 list the sectors in scope. Among them: energy, transport, banking and financial market infrastructure, health, drinking water and waste water, digital infrastructure, electronic communications, cloud services and data centres, managed IT and security services, public administration, postal and courier services, waste management, food production and distribution, the chemical industry, certain manufacturing activities (including medical devices, electronics, machinery and equipment), online marketplaces, search engines, social platforms and research organisations.

Mind one detail: the annexes describe concrete types of entities, not just sectors. The main CAEN code is not enough to decide. What counts is the actual activity.

2. Are you a medium-sized or large enterprise?

As a general rule, NIS2 applies to companies in these sectors that exceed the small-enterprise threshold: at least 50 employees, or an annual turnover and balance sheet above 10 million euros. Micro and small enterprises are, in general, outside the scope.

Two nuances catch many companies off guard. First: size is calculated including partner or linked enterprises, so a small company inside a group can be brought into scope through the group. Second: the law refers to the criteria in Law 346/2004, and the thresholds there do not always read intuitively. When the figures are close to the threshold, a careful check is worth it.

3. Are you a special case?

Certain categories fall under the law regardless of size: DNS service providers, top-level domain registries, qualified trust service providers, central public administration. In addition, the DNSC can classify a company as essential or important if it is the sole provider of a critical service or if a disruption of its service would significantly affect health, public safety or the economy.

If the answer to the first two questions is "yes", or if you sit in a grey area, the DNSC's recommendation is to complete the assessment through the NIS2@RO tools and submit the notification. The DNSC analyses it and tells you whether the company is essential, important or outside the scope. The company does not decide on its own.

"I'm not directly in scope." Fine, but your clients are

This is the part most SMEs miss.

Among the mandatory measures for essential and important entities is supplier and supply-chain security. A company under NIS2 has to manage the risk its suppliers bring. In practice, that means it will ask you for: security clauses in the contract, an obligation to notify it in case of an incident, evidence that you have basic measures in place, sometimes a right to audit.

If you provide IT services, software, maintenance, logistics, accounting or anything else to a company in the sectors above, these requirements reach you through the contract, not through the law. And the answer "we are not under NIS2" does not get you out of them. It gets you off the supplier list.

For an SME, this is the real exposure to NIS2 in most cases: not the fine from the DNSC, but the contract you can no longer sign or renew.

If you are in scope: what you have to do

The main obligations, in the order they arise:

Registration with the DNSC. For companies that were already in scope when the procedure launched, the general deadline expired on 22 September 2025. Missing it did not remove the obligation; the DNSC has warned that the penalty for failing to register can reach 500,000 lei, and the first sanctioning procedures target exactly these companies. Companies that fall under the law later must submit the notification within 30 days at most.

The NIS2 officer. The company must designate a person responsible for cybersecurity and declare them to the DNSC. For small companies an external or shared officer is acceptable, but the person must exist and must be trained.

Risk assessment and maturity self-assessment. After the DNSC's decision to enter the company in the register, the company has 60 days to submit an assessment of its own risk level, following the DNSC methodology, and another 60 days for the self-assessment of the maturity of its security measures. The deadlines run in sequence, so there is no single cut-off date for everyone.

Technical and organisational measures. The law requires measures proportionate to the risk, covering, among other things: risk analysis and management, incident prevention and handling, business continuity and disaster recovery, backups that are made and tested, supplier security, access control and asset management, multi-factor authentication, staff training and periodic evaluation of how effective the measures are. These are not recommendations. Their absence is an offence.

Reporting significant incidents. An early warning within 24 hours of becoming aware, an incident report within 72 hours, a final report within one month at most. For information on cross-border impact, the deadline is 6 hours.

Management responsibility. Management must approve and supervise the measures, and members of the management bodies have a training obligation. Law 124/2025 strengthens the personal liability of management. Concretely: NIS2 compliance cannot be delegated wholesale to the IT department or the IT provider.

The fines

For major breaches (failing to implement the measures, failing to meet audit and reporting obligations), the caps are up to 10 million euros or 2% of turnover for essential entities and up to 7 million euros or 1.4% for important entities, whichever is higher. Law 124/2025 specifies that the percentage applies to global turnover, not just the Romanian one.

For other offences, fines range from 1,000 to 300,000 lei for important entities and from 1,500 to 500,000 lei for essential ones. In aggravating circumstances, the amount can be doubled.

The DNSC has indicated that, in a first stage, it will apply values from the lower end of the ranges. Which does not mean the fine is not coming, only that it comes gradually.

What we do in practice, in both cases

The good news is that the NIS2 list of measures contains nothing exotic. It is the list a properly built IT setup should cover anyway: centrally managed identities with multi-factor authentication, backups that are tested, not just configured, role-based access, an inventory of systems and suppliers, an incident response plan that someone has read and rehearsed, security clauses in supplier contracts.

A study published in September 2026 on a sample of 211 Romanian organisations shows why testing matters: 45% described themselves as having high cyber maturity, but only 27% passed three practical checks, permanent monitoring, a tested response plan and regular exercises. Many companies have the measures on paper. Few have put them to the test.

If you are under NIS2, the order is: check your classification through NIS2@RO, register, designate the officer, run a gap analysis against the list of measures, remediate in order of risk and prepare the documentation for the assessments the DNSC requires.

If you are not directly in scope, the order is the same, minus registration. Because the basic measures are the ones your clients will ask you for, and they are the ones that actually matter on the day something happens.

That is what we do: we check the classification, run the gap analysis, put identities, access, backups and documentation in order, and prepare the company for the conversation with the DNSC or with the client asking for guarantees. If you have already received a security questionnaire from a client, or you are not sure which category you fall into, this is the right moment for a conversation.

Sources: OUG 155/2024, Law 124/2025, DNSC Orders 1/2025, 2/2025 and 1/2026, DNSC communications (dnsc.ro). Always check the official text and seek legal advice on your company's concrete classification.