Protect//NIS2 guide
NIS2 deadlines in Romania: what has expired and what is running now
Few NIS2 deadlines are fixed calendar dates. Most run individually, from the DNSC decision issued for each entity.
Updated: 02.10.2026 · ~6 min read
The general deadline for notification and registration with DNSC expired in September 2025. The obligations that follow registration, however, have relative deadlines that run from the DNSC decision issued for each entity, so a company registered later still has deadlines running. Both types are listed below, with the source of each.
Fixed calendar dates
| Date | What happened |
|---|---|
| 10 July 2025 | Law 124/2025 enters into force, approving and amending GEO 155/2024 |
| 20 August 2025 | DNSC Order 1/2025 (notification and registration) and DNSC Order 2/2025 (risk assessment methodology) enter into force |
| September 2025 | The deadline for notification and registration with DNSC expires: 30 days after DNSC Order 1/2025 entered into force |
Deadlines that run individually
Once DNSC issues the identification and registration decision, each entity has its own calendar:
| Deadline | Obligation |
|---|---|
| 30 days from the DNSC decision being communicated | Appointing the NIS officer (art. 14(3)) |
| 60 days from the registration decision | Risk level assessment, using the DNSC Order 2/2025 methodology (art. 18(6)) |
| 60 days from the risk assessment | First maturity self-assessment, signed off by management (art. 18(7)) |
| 30 days from the self-assessment | Remediation plan sent to DNSC (essential entities only) |
| 12 months from appointment | Specialist training of the NIS officer (essential entities) |
| Yearly | Renewing the maturity self-assessment |
| At least every 3 years | Updating the risk assessment, or sooner after incidents or major changes |
The differences between essential and important entities are explained in the guide Essential or important entity?
Incident reporting deadlines
The deadlines are counted from the moment the organization becomes aware of a significant incident:
- 24 hours: early warning to DNSC;
- 72 hours: incident notification, with an initial assessment;
- one month at most after the notification: final report.
For a company without a written procedure, 24 hours is not much. Someone has to know in advance who decides whether an incident is significant, who sends the early warning and through which channel. The details are in the guide on incident reporting.
What to do if you missed registration
- Check your classification. Use the NIS2 simulator or the Who needs NIS2 page.
- Notify DNSC as soon as possible. The general deadline has expired, but the duty to notify remains, and the relative deadlines above only start after the DNSC decision.
- Prepare for the calendar that follows. After the decision you have 30 days for the NIS officer and 60 days for the risk assessment. It pays to start preparing before the decision arrives.
- Document what you do. Evidence of compliance efforts matters in dealings with the authority.
If you want to know where your company stands in this calendar, request a free assessment: we will tell you which deadlines apply to your organization and in what order to tackle them. The full steps are in the NIS2 compliance guide.
Request a free NIS2 assessment
Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.
Request free assessment