What NIS2 is
Directive (EU) 2022/2555 — the Network and Information Security Directive 2 (NIS2) — replaces the original NIS Directive. Member States were required to transpose it into national law by 17 October 2024. It applies to "essential entities" and "important entities" across a broad range of sectors and subsectors, including energy, transport, banking, financial market infrastructure, health, digital infrastructure, public administration and others.
Who it catches
NIS2 catches medium and large entities in the listed sectors. It also covers entities that are the sole providers of a service in a Member State and entities designated as critical by national authorities regardless of size. Specific size thresholds and sector lists are set out in the directive's Annexes. Smaller entities may be excluded by the thresholds but can still be brought in by designation or by national rules that are stricter than the minimum EU requirements.
What it requires: Article 21
Article 21 sets out cybersecurity risk-management measures that entities must put in place. The measures are proportionate and risk-based, but they cover a full security-management baseline: risk analysis and information-system security, incident handling, business continuity and crisis management, supply-chain security, security in network and information systems acquisition and development, policies for assessing the effectiveness of risk-management, basic cyber-hygiene and cybersecurity training, the use of cryptography and encryption, human-resources security, and multi-factor authentication and secured communications.
Reporting: Article 23
Article 23 imposes a three-stage reporting obligation on entities. They must notify their national CSIRT or competent authority of incidents that have a significant impact on the provision of their services:
- Initial notification: without undue delay and within 24 hours of becoming aware of a significant incident.
- Intermediate notification: within 72 hours of becoming aware, where possible.
- Final notification: one month after the intermediate notification, or when the incident is closed.
Management accountability: Article 20
Article 20 requires management bodies to approve the cybersecurity risk-management measures taken by the entity, oversee their implementation and follow training. Member States must ensure that management bodies can be held liable for failing to do so. This is the provision that has moved cybersecurity from an operational matter into a board-level governance question.
NIS2 in Romania
Romania transposed NIS2 through Government Emergency Ordinance 155/2024, approved and amended by Law 124/2025. The National Cyber Security Directorate (DNSC) supervises implementation. Registration and risk-assessment procedures are set by DNSC Orders 1/2025 and 2/2025.
Penalties: essential entities face fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; important entities face fines of up to EUR 7 million or 1.4% of total worldwide annual turnover, whichever is higher.
How CYBERVETTER helps
We help entities in scope build the evidence and governance that NIS2 demands, without assuming the structure of a much larger organisation. Our work includes:
- In-scope determination and gap assessment against the Article 21 measures.
- Incident-response and reporting procedures that meet the 24/72/one-month clock.
- Supply-chain security and third-party risk frameworks.
- Board and management-body accountability briefings and training evidence.
- Support during DNSC registration, risk assessment and supervisory engagement.