IT Glossary
What is OUG 155/2024?
OUG 155/2024 is the emergency ordinance through which Romania transposed the EU NIS2 directive, defining who carries cybersecurity obligations and who supervises them.
Government Emergency Ordinance no. 155 of 30 December 2024 is the act that turned the EU NIS2 directive into Romanian law, later approved with modifications by Law no. 124 of 7 July 2025. The text establishes the cybersecurity framework for Romania's civil national cyberspace and designates DNSC — the National Cybersecurity Directorate — as the competent authority: covered entities register with DNSC, significant incidents are reported to it, and the orders the Directorate issued in 2025 detail the registration procedure and the risk-assessment methodology. The ordinance classifies regulated organizations into essential and important entities, across the sectors listed in its annexes — from energy, healthcare and drinking water to digital infrastructure and manufacturing — and generally targets medium-sized and large organizations; Article 9, however, allows coverage regardless of size in special situations, such as being the sole provider of an essential service. One detail frequently misrepresented in commercial pitches: in the public administration chapter, the ordinance covers central public administration entities, not every local institution. Entities that do fall in scope must notify DNSC within 30 days at most, under Article 18, and implement the risk-management measures the law requires.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
Why it matters for your business
The text that settles arguments
When an offer or a cold email invokes "the NIS2 law", the ordinance is the document the claim is checked against: the sectors in the annexes, the size thresholds and the special coverage paths are written down, not negotiable.
A single counterpart: DNSC
Registration, incident reporting and supervision all run through one authority, and its published procedures fix the forms and the steps — a clear administrative route for covered entities.
Verifiable classification criteria
Sector, size, the special situations in Article 9 and direct designation form a finite checklist; an organization can establish in writing whether it has obligations instead of paying preemptively for compliance services.
Frequently asked questions
What is the difference between NIS2 and OUG 155/2024?
NIS2 is the European directive — a framework each member state transposes into its own legislation. OUG 155/2024 is the Romanian transposition: it adopts the directive's architecture and concretely sets the competent authority, the registration procedure, the deadlines and the sanctions applicable in Romania. A Romanian organization reads its obligations from the ordinance and DNSC's orders, not from the directive directly.
Does OUG 155/2024 apply to city halls and local public institutions?
Not automatically. In the public administration chapter, the ordinance covers central public administration entities, according to Annex no. 1. A city hall or another local institution can fall in scope only through specific paths: if it operates services from the regulated sectors, if it meets the special criteria of Article 9, or if it is designated by DNSC — and the outcome of that check is worth documenting in writing.
What registration deadline does OUG 155/2024 set?
Entities that fall in scope must notify DNSC for registration within 30 days at most, under Article 18 — the term runs from the moment the law's provisions become applicable to that entity. Registration is followed by the stages set out in DNSC's procedures, including risk assessment and a maturity self-evaluation, with an ongoing duty to keep the submitted data current.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247