Law No. 124/2025 – Approval of Government Emergency Ordinance No. 155/2024 on Cybersecurity of Networks and Information Systems in the National Civil Cyberspace (Romania)
În Monitorul Oficial al României, Partea I, nr. 638 din 7 iulie 2025, a fost publicată Legea nr. 124/2025 privind aprobarea, cu modificări și completări, a Ordonanței de urgență a Guvernului nr. 155/2024 Published in the Official Gazette of Romania, Part I, No. 638 of July 7, 2025, Law No. 124/2025 approves, with amendments and additions, Government Emergency Ordinance No. 155/2024, which establishes the legal framework for cybersecurity within the national civil cyberspace.
Key Provisions:
- Clarifies the applicability of the law in relation to personal data protection legislation, the Criminal Code, and critical entities resilience laws;
- Establishes the competencies of the National Cybersecurity Directorate (DNSC) regarding oversight, incident reporting management, and the confidentiality of submitted information;
- Revises the definition of social networking service platforms;
- Introduces mandatory cybersecurity training for leadership and staff of essential and important entities, and mandates the designation of cybersecurity officers;
- Redefines the criteria under which an incident is deemed significant;
- Regulates the obligation of the national single point of contact to share relevant information with ENISA and the European Commission;
- Clarificarea obligațiilor privind acordurile de schimb de informații în domeniul securității cibernetice;
- Clarifies requirements for information-sharing agreements in the field of cybersecurity;
- Establishes obligations for ICT manufacturers and providers regarding vulnerability reporting and remediation, including DNSC’s notification to the European Commission;
- Provides for cooperation between DNSC, the National Bank of Romania (BNR), and the Financial Supervisory Authority (ASF) in assessing and managing cyber risks in the financial sector;
- Modifies response and reporting deadlines for addressing deficiencies identified by DNSC;
- Updates the regime of serious contraventions and sanctions for essential and important entities, including derogations from Government Ordinance No. 2/2001;
- Updates annexes related to regulated sectors: health, digital infrastructure, and the food industry.
The law was adopted in accordance with Articles 75 and 76(2) of the Romanian Constitution.
Full text available at: https://legislatie.just.ro/Public/DetaliiDocument/299675
Legislation of Romania
1. General Framework: NIS & NIS2
NIS Directive (Network and Information Systems Directive)
The first European directive on cybersecurity, establishing minimum requirements for the security of networks and information systems.
NIS2 Directive
The revision of the NIS Directive, adopted at the EU level to strengthen cyber resilience. In Romania, transposed through Emergency Ordinance 155/2024.
2. Published Legal Acts
2.1. Emergency Ordinance no. 155/2024 – Transposition of the NIS2 Directive
Official document: See OUG 155/2025 - EN version
Regulates the minimum security requirements for essential and important entities. Introduces new obligations related to incident reporting and risk assessment.
2.2. Monitorul Oficial nr. 1332 – OUG NIS2 (31.12.2024)
Official document: 2.2. Official no. 1332 – NIS2 Emergency Ordinance (31.12.2024)
Official publication of the Emergency Ordinance for the implementation of NIS2.
3. DNSC Draft Orders under Public Consultation
3.1. Proiect Ordin – Notificare & Transmitere Informatii
Official document: See Draft Order – Notification
Details the notification process for registration and the method of data submission.
3.2. Draft Order – Criteria for Determining the Degree of Disruption
Official document: See Draft Order - Degree of Disruption
Establishes the criteria and thresholds for assessing service impact and risk level.
General Resources – DNSC
Updated legislation: DNSC Legislative Section