Protect//NIS2 guide
The NIS officer: role, legal conditions and how to appoint one
What Romanian law expects from the person responsible for cybersecurity in an NIS2 entity, and how to choose between an employee and an outsourced service.
Updated: 02.10.2026 · ~7 min read
Every essential or important entity must appoint a NIS officer. In GEO 155/2024 the role is called the “person responsible for the security of network and information systems”, and the appointment must be made within 30 days of the DNSC identification and registration decision being communicated (art. 14(3)). This guide explains what the role involves, which conditions the person must meet and how a medium-sized company can organize it.
What the NIS officer does
The law places the obligations on the entity and its management. The NIS officer is the person who carries them out and keeps track of them. The role usually covers:
- coordinating the risk level assessment, using the DNSC Order 2/2025 methodology, and the annual maturity self-assessment;
- proposing technical and organizational measures and following up on their implementation;
- drafting and updating security policies and procedures;
- coordinating incident response and reporting significant incidents to DNSC;
- liaising with DNSC on notifications, data updates and requests;
- staff training and periodic reports to management.
The NIS officer does not take over management's accountability. Management approves the measures, allocates the resources and answers for them, whoever holds the role.
The legal conditions
For essential entities, art. 14(4) sets three cumulative conditions. The appointed person:
- operates independently from the entity's IT and operational technology (OT) structures;
- has access to the resources needed to oversee and implement the measures;
- obtains specialist training recognized by DNSC within 12 months of appointment.
These conditions do not apply to public administration or micro-enterprises. Important entities must appoint a NIS officer, without the cumulative conditions. Even so, an officer with no specialist training, or one who reports to the IT team they are meant to check, will struggle with the first risk assessment.
Independence from IT has a practical reason: the officer must be able to flag infrastructure problems without assessing their own work. That is why the company's system administrator is rarely the right choice for an essential entity.
Specialist training
The NIS officer programme ends with a specialization certificate issued by DNSC. The course takes 5 days (30 hours, half theory and half practical work). For essential entities, the training must be completed within 12 months of appointment. If you choose an officer who already holds the certificate, the deadline is no longer an issue.
In-house or outsourced
The law does not prohibit outsourcing the role, and it is common practice on the market. The choice depends on company size, the security budget and whether there is a suitable person on the team.
| Criterion | In-house employee | Outsourced service |
|---|---|---|
| Cost | A specialist salary, typically EUR 3,000–5,000 gross per month, plus recruitment and training | Monthly subscription, from EUR 335/month excl. VAT at nis-iasi.ro |
| Availability | Depends on recruitment; leave and resignations leave the role uncovered | From the day the contract is signed |
| Independence from IT | Must be set up through the job description and reporting line | Follows from the contractual relationship |
| Knowledge of the company | High, from the inside | Built through a systems inventory and talks with the team |
| Training | To be obtained within 12 months (essential entities) | At nis-iasi.ro, the NIS Officer is DNSC-certified |
When outsourcing, the contract should clearly describe the tasks, incident response times, access to information and reports to management. Management's accountability stays the same, and for essential entities the external person must meet the same conditions as an employee.
What happens if no officer is appointed
Failing to appoint the officer is sanctioned as a contravention. The maximum fines under GEO 155/2024 are EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important ones. Without an officer, the other obligations also lack an owner: the risk assessment, the self-assessment and incident reporting are left uncovered.
Details about our outsourced NIS officer service are on the services page. If you do not yet know whether your company is covered, start with the NIS2 simulator or the guide Essential or important entity?
Request a free NIS2 assessment
Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.
Request free assessment