Protect//NIS2 guide
Essential or important entity? How NIS2 classification works in Romania
The classification depends on your sector and company size. It determines the fine ceilings, the requirements for the NIS officer and how DNSC supervises you.
Updated: 02.10.2026 · ~7 min read
GEO 155/2024, approved and amended by Law 124/2025, splits the organizations covered by NIS2 into two categories: essential entities and important entities. The core obligations are the same for both, but the fine ceilings, the conditions for the NIS officer, the remediation plan and the supervision regime differ. DNSC sets the final classification through its identification and registration decision, but you can estimate it yourself in two steps: sector and size.
Step 1: Which sector are you in?
The law uses two annexes:
- Annex I, sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, space.
- Annex II, other critical sectors: postal and courier services, waste management, chemicals, production, processing and distribution of food, manufacturing (medical devices, electronics, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers, research.
The full list, with subsectors, is on the Who needs NIS2 page. Mind the terminology: the law classifies entities as essential or important; sectors are only “of high criticality” or “other critical sectors”.
Step 2: How large is the organization?
Size is determined under Law 346/2004, art. 4:
- Medium-sized enterprise: at least 50 employees, OR turnover and balance sheet total both above EUR 10 million.
- Large enterprise: 250 employees or more, OR turnover above EUR 50 million and balance sheet total above EUR 43 million.
- Micro and small: generally exempt, with the exceptions below.
If the company is part of a group, check the Law 346/2004 rules on partner and linked enterprises: their figures may be aggregated, so a company that is small on paper can turn out medium-sized or large.
The result: classification matrix
| Situation | Category |
|---|---|
| Large enterprise in Annex I | Essential |
| Medium-sized enterprise in Annex I | Important |
| Medium-sized or large enterprise in Annex II | Important |
| Micro or small, no exception applies | Generally outside NIS2 |
Exceptions: covered regardless of size
- As essential entities: DNS service providers, TLD name registries, qualified trust service providers, central public administration and critical entities (Law 294/2024).
- As important entities: providers of public electronic communications networks or services and non-qualified trust service providers.
- Individual designation: DNSC can bring any entity into scope (art. 9), for example the sole provider of an essential service in an area.
Cloud, data centres, CDNs, MSPs/MSSPs and digital providers are not covered regardless of size: the normal thresholds apply to them.
What actually differs between the two categories
| Aspect | Essential | Important |
|---|---|---|
| Category I fines (serious breaches) | RON 10,000 – EUR 10 million or 2% of worldwide turnover | RON 5,000 – EUR 7 million or 1.4% of worldwide turnover |
| Category II fines | RON 1,500 – 500,000 | RON 1,000 – 300,000 |
| NIS officer: cumulative conditions (art. 14(4)) | Yes: independent from IT/OT structures, with access to resources, specialist training within 12 months of appointment | These cumulative conditions do not apply |
| Remediation plan sent to DNSC | Yes, within 30 days of the self-assessment | Not as a separate obligation |
| Supervision (NIS2 Directive, art. 32–33) | Proactive: inspections and audits can be ordered at any time | Reactive: mainly when there are signs of non-compliance |
The cumulative NIS officer conditions for essential entities do not apply to public administration or micro-enterprises. For fines, the higher of the fixed amount and the percentage applies.
What they have in common
- notification and registration with DNSC;
- appointing a NIS officer (in the law, the “person responsible for the security of network and information systems”) within 30 days of the DNSC decision being communicated;
- a risk level assessment under the DNSC Order 2/2025 methodology and an annual maturity self-assessment, signed off by management;
- technical and organizational risk-management measures (policies, incidents, continuity, supply chain, access, encryption, training);
- reporting significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month;
- management accountability and its training obligation.
Not in scope? Your clients may be
Essential and important entities must manage supplier risk (art. 21, supply chain security). If you sell IT services, software, maintenance or equipment to an NIS2 entity, expect security questionnaires, new contract clauses and requests for evidence. This is how NIS2 requirements reach companies the law does not cover directly.
Common classification mistakes
- Using the NACE (CAEN) code as the only criterion. What matters is the activity actually carried out, including secondary activities on the company record.
- Ignoring the group. Employees and figures of linked companies can change the size class.
- Assuming cloud or MSP means automatic NIS2. The normal thresholds apply.
- Waiting for DNSC to get in touch. The duty to notify and register lies with the entity.
Want an answer for your organization? The NIS2 simulator walks through sector, size and exceptions in a few minutes. For confirmation on your company's real data, request a free assessment. The next steps are in the NIS2 compliance guide and the deadline calendar.
Request a free NIS2 assessment
Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.
Request free assessment