Ordonanța de urgență nr. 155/2024, Incident Notification
Ordonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor… informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 31 December 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential or important entity under Articles 5 and 6, which name a piață online (online marketplace), a motor de căutare online (online search engine) and a platformă de servicii de socializare în rețea (social-networking-services platform) among the digital-provider categories it reaches expressly; the wider sector classes it also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
- Report to the national cybersecurity-incident-response team, without undue delay, any incident with a significant impact on the provision of your services, through the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC).
- Submit an early warning within 24 hours of becoming aware of a significant incident, stating whether it is suspected unlawful, malicious, or cross-border in impact; follow with a fuller incident report within 72 hours giving an initial severity and impact assessment and any known indicators of compromise; submit an interim report if the CSIRT requests one; and submit a final report within one month of the 72-hour report, or a progress report followed by a final report if the incident is still ongoing at that point.
- Where relevant, notify the recipients of your services of a significant incident that could affect them.
- If you are a trust service provider, report an incident affecting your trust services within a flat 24 hours of becoming aware of it, rather than on the graduated clock.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 60(1) letters l) and m) make a violation of the Article 15(1) reporting clock, or of the duty to notify service recipients, a contravenție (an administrative regulatory offence) only where the conduct does not separately meet a criminal offence's elements under other law; this instrument's own sanction, an amendă contravențională under Article 48, is administrative rather than criminal.
Penalty structure
Article 60(2)(a)-(b) applies the same top penalty tier that governs an Article 11(1) violation (EUR 10,000,000 or 2 percent of net turnover for an essential entity, EUR 7,000,000 or 1.4 percent for an important entity, whichever is greater) to a violation of Article 60(1) letters a) through m), which include letter l) (missing the Article 15(1) reporting clock or conditions) and letter m) (failing to notify service recipients under Article 15(1)). A separate Article 15(3) information-reporting violation at Article 60(1) letter n) instead falls in the lower fixed-lei tier Article 60(2)(c)-(d) sets for letters n)-t).
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Directoratul Național de Securitate Cibernetică (DNSC), acting as the national CSIRT that receives the notification, or, for a sector with its own designated sectoral competent authority under Article 37, that authority acting alongside DNSC.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://www.dnsc.ro/pagini/legislatie-nis2
- Guidance body
- Directoratul Național de Securitate Cibernetică (DNSC)
- Open questions
- Since Legea nr. 124/2025's approval of this OUG could not be directly verified against its own primary text in this review, does its single approving article change any Article 15 reporting threshold or clock, or does it approve the OUG unchanged as the secondary legal-commentary sources this review relied on report?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 15(1) requires an essential or important entity to report to the national cybersecurity-incident-response team, without undue delay, any incident with a significant impact on the provision of its services, and, where relevant, to notify the recipients of its services of a significant incident that could affect them. Article 15(2) routes this reporting through the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC).
Article 15(7) sets a graduated clock: an early warning within 24 hours of becoming aware of the significant incident, indicating whether it is suspected to be caused by unlawful or malicious acts or to have cross-border impact; an incident report within 72 hours, updating the early warning and giving an initial assessment of the incident's severity and impact, including indicators of compromise where available; an interim report on the national CSIRT's request; and a final report within one month of the 72-hour incident report, including a detailed description of the incident, its likely cause, mitigation measures applied and in progress, and any cross-border impact, or, if the incident is still ongoing at that point, a progress report followed by a final report once it has been resolved.
Article 15(8) sets a flat 24-hour clock for a trust service provider's incidents affecting its trust services. Article 16 lets an entity outside the mandatory scope voluntarily report incidents, cyber threats and near misses to the national CSIRT under the same Article 15 channel, without that report itself creating any additional obligation.
Article 17 extends Articles 15 and 16 to certain electronic-communications entities under Legea nr. 58/2023 that are identified as essential or important entities under this OUG. Article 62 separately requires DNSC to inform ANSPDCP, Romania's data-protection authority, without undue delay when a cybersecurity incident it supervises also implicates personal-data protection.
When LexLint raises it
operates_social_platform
Read the law
Ordonanța de urgență a Guvernului nr. 155/2024
consolidated text as of the 10 July 2025 revision, legislatie.just.ro, read from an Internet Archive Wayback Machine mirror of that page