DEV Community

DEVALAND
DEVALAND

Posted on

NIS2 in Romania: how registration with DNSC works, step by step

If you run infrastructure for a company or an institution in Romania, sooner or later someone asks: do we have to register with DNSC for NIS2, and how? Romania transposed NIS2 through Emergency Ordinance (OUG) 155/2024, approved with amendments by Law 124/2025. Entities that qualify as essential or important must register with the national authority, DNSC.

Below are the steps exactly as DNSC describes them on its own site. This is a map of the process, not legal advice.

First: are you in scope?

Not every organisation is. What matters is the sector (annexes 1 and 2 of the ordinance) and, in most cases, the size of the organisation. The consolidated text is on legislatie.just.ro. DNSC also publishes a guide for the "disruptive effect" self-assessment under article 9, and answers questions about identification, changes or deregistration at nis@dnsc.ro.

Whether you are in scope is a legal call for management and a lawyer. It is not something an IT supplier, including us, should decide for you.

Step 1: the notification form

  1. The form is generated only on the NIS2@RO platform, or, when the platform is unavailable, with the NIS2@RO tool, a file you download from dnsc.ro and run locally. An English version of the tool exists to help you understand the fields, but the form is submitted in Romanian.
  2. Save it as PDF and have the legal representative sign it: a qualified electronic signature for electronic filing, or a handwritten signature on paper.
  3. Send it, with any supporting documents, to evidenta@dnsc.ro, or file it on paper at DNSC's office in Bucharest.
  4. If you could not register on the platform because it was down, you must create an account once it becomes available.

Step 2: the risk level assessment

Until the platform is fully operational, the risk assessment is produced with the ENIRE@RO tool, again downloaded and run locally. The report is saved as PDF, signed the same way and sent to evidenta@dnsc.ro or filed on paper, together with a justification if you changed any default values.

Step 3: the maturity self-assessment

Based on the ENIRE@RO score validated by DNSC, you use the self-assessment tool for your security level: Basic (EVAL_MMS_B), Important (EVAL_MMS_I) or Essential (EVAL_MMS_E). The PDF report is signed by the legal representative or a designated member of management, and emailed to evidenta@dnsc.ro together with the Excel file it was generated from. If the report is signed by hand on paper, the Excel file still goes by email.

Contacts DNSC lists for this process

  • evidenta@dnsc.ro: notification forms and reports
  • nis@dnsc.ro: help with identification, changes or deregistration
  • Phone, Records and Support: +40 316 202 167; Verification and Control: +40 316 202 156
  • Office: Strada Italiană 22, Sector 2, 020976 Bucharest

Registration is not incident reporting

Incidents go to the national platform PNRISC or to 1911, 24/7. DNSC notes that a PNRISC report does not replace a criminal complaint where one is needed.

The original, in Romanian: devaland.cloud. Sources: DNSC's pages "Înregistrare entități" and "Obligațiile entităților înregistrate" under Directiva NIS on dnsc.ro, the PNRISC platform and OUG 155/2024, checked 27 September 2026. We are a software company: we do not classify organisations under the ordinance or fill in these assessments.

Top comments (0)