Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures
Ordonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor… informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 11-14
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 31 December 2024.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential or important entity under Articles 5 and 6, which name a piață online (online marketplace), a motor de căutare online (online search engine) and a platformă de servicii de socializare în rețea (social-networking-services platform) among the digital-provider categories it reaches expressly; the wider sector classes it also reaches (energy, transport, banking, health, water, digital infrastructure, public administration, and a size-gated telecom or managed-security-service provider) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
- Take technical, operational and organisational measures proportionate to your risk exposure to identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services.
- Cover at least: risk-analysis and system-security policy and its periodic review; evaluating the effectiveness of your risk-management measures; cryptography and encryption policy; supply-chain security, including the security of your relationship with your direct suppliers and service providers; security of system acquisition, development, maintenance and decommissioning, including vulnerability management and disclosure; human-resources security, access control and asset management; incident management; business continuity, including backups, disaster recovery and crisis management; basic cyber-hygiene practices and training; and multi-factor or continuous authentication.
- Have your governing body approve these measures, supervise their implementation, and bear responsibility for them; designate a network-and-information-system security officer; and expect the DNSC director to issue an implementing order narrowing these requirements within 120 days of the OUG's entry into force (due by roughly 30 April 2025).
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 60(1) makes a Article 11(1) violation a contravenție (an administrative regulatory offence) only "dacă nu au fost săvârșite în astfel de condiții încât să fie considerate infracțiuni potrivit legii" (unless committed under conditions that would make it a criminal offence under other law); this instrument's own sanction, an amendă contravențională under Article 48, is administrative rather than criminal.
Penalty structure
Article 60(2)(b) sets the maximum fine for an essential entity's violation of Article 60(1) letters a) through m) (which includes the Article 11(1) risk-management duty at letter a)) at the greater of EUR 10,000,000 in lei equivalent or 2 percent of net turnover. Article 60(2)(a) sets a lower tier for an important entity's violation of the same range of letters at the greater of EUR 7,000,000 in lei equivalent or 1.4 percent of net turnover, mirroring NIS2 Article 34(4) and (5).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Directoratul Național de Securitate Cibernetică (DNSC), or, for a sector with its own designated sectoral competent authority under Article 37, that authority acting alongside DNSC.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://www.dnsc.ro/pagini/legislatie-nis2
- Guidance body
- Directoratul Național de Securitate Cibernetică (DNSC)
- Open questions
- Has the Directorul DNSC issued the Article 12(1) order detailing the technical, operational and organisational risk-management requirements, due within 120 days of the OUG's entry into force, and does it narrow or add sector-specific requirements for an online marketplace, online search engine or social-networking-services platform specifically?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 11(1) requires an essential or important entity to take technical, operational and organisational measures proportionate to its risk exposure to identify, assess and manage the risks to the network and information systems it uses, across at least ten baseline categories mirroring NIS2 Article 21(2): risk-analysis and system-security policy and its periodic review; evaluating the effectiveness of risk-management measures; cryptography and, where applicable, encryption policy; supply-chain security, including the security of the entity's relationship with its direct suppliers and service providers; security of system acquisition, development, maintenance and decommissioning, including vulnerability management and disclosure; human-resources security, access-control policy and asset management; incident management; business continuity, including backup management, disaster recovery and crisis management; basic cyber-hygiene practices and cybersecurity training; and multi-factor or continuous authentication.
Article 12(1) requires the DNSC director to issue an implementing order on these technical, operational and organisational requirements within 120 days of the OUG's entry into force. Article 14 requires the entity's governing body to approve these measures, supervise their implementation and bear responsibility for them, attend training, allocate the resources needed to implement them, and designate a network-and-information-system security officer.
Article 66(1)(a) repeals the predecessor statute, Legea nr. 362/2018, outright as of this OUG's own entry into force. Article 4 defines a piață online (online marketplace) and a motor de căutare online (online search engine) as digital-provider categories among the entities Articles 5 and 6 bind as essential or important.
When LexLint raises it
operates_social_platform
Read the law
Ordonanța de urgență a Guvernului nr. 155/2024
consolidated text as of the 10 July 2025 revision, legislatie.just.ro, read from an Internet Archive Wayback Machine mirror of that page