Protect//NIS2 guide
Management obligations under NIS2: what directors are accountable for
GEO 155/2024 makes cybersecurity the responsibility of company management. What directors must do, what they can delegate and what they risk personally.
Updated: 02.10.2026 · ~6 min read
One of the significant changes brought by NIS2 is where accountability sits. Until now, many companies treated information security as a technical topic, delegated to the IT team or a supplier. Art. 14 of GEO 155/2024, however, assigns the obligations directly to the management bodies of essential and important entities: directors, the board of directors or the management board, as the case may be. The general meeting of shareholders is not a management body within the meaning of the ordinance.
What management must do
Under art. 14, management bodies:
- approve the cybersecurity risk-management measures and oversee their implementation, with a written trail: decisions, minutes, signed documents;
- follow training that enables them to identify risks, assess risk-management practices and understand the impact on the company's services;
- ensure regular training for all staff;
- allocate the necessary resources and set up permanent means of contact with DNSC;
- appoint the NIS officer within 30 days of the DNSC decision;
- sign off the annual maturity self-assessment, which is sent to DNSC.
What cannot be delegated
Management can outsource the work: an external NIS officer, a managed IT services provider, a consultant for the documentation. It cannot outsource the accountability. Approving the measures, budget decisions and overseeing implementation stay with management, however good the supplier contract is.
A frequent example: the company signs a contract with a supplier that “handles NIS2”, and management stops receiving any updates. During an inspection, the lack of approval decisions and reports to management is a problem in itself, even if the measures exist technically.
What management members risk personally
- A temporary ban from holding management positions at chief executive or legal representative level. DNSC can request it from the competent authorities for essential entities, if the remediation measures it ordered are not complied with.
- Civil liability. An incident caused by missing measures can be treated as a breach of contract with clients. If the risk was known and neglected, invoking force majeure becomes hard to sustain. Towards third parties, the general rules of tort liability apply (art. 1349 of the Romanian Civil Code).
- Liability towards the company, under company law rules, if the director's negligence caused losses to the company.
Administrative fines are imposed on the entity, with ceilings of up to EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important ones.
What it means in practice for a director
For a medium-sized company, management's obligations translate into a few habits that are easy to check:
- a short security report presented to management every quarter or half-year;
- written approval of the security policy, the risk assessment and the remediation plan;
- an explicitly decided security budget, even a modest one;
- management taking part in training and in at least one incident response exercise per year;
- a file with all of the above, kept in order for a possible DNSC inspection.
None of this requires technical knowledge. What it requires is security being a fixed item on management's agenda.
If your company is covered and you want to know what management is missing, request a free assessment. The role of the person who prepares all of this is described in the guide on the NIS officer.
Request a free NIS2 assessment
Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.
Request free assessment