Romanian cybersecurity authority announces first sanction for failure to comply with NIS2 registration notification requirements

01.10.2026

On 30 September 2026, the Romanian National Cyber Security Directorate (DNSC) announced its first administrative sanction, amounting to the RON equivalent of approximately EUR 10,000, for failure to comply with the notification obligation under the Romanian NIS2 Law.

The sanction was imposed on 29 September 2026 on a body of the central public administration, falling within the public administration sector listed in Annex 1 to the Romanian NIS2 Law. According to DNSC, the entity had failed to notify the authority for registration purposes within the statutory deadline, as required for the identification of essential and important entities under the Romanian NIS2 framework.

DNSC also emphasized that compliance with the notification obligations under the cybersecurity framework contributes to the timely identification and management of incidents, as well as to strengthening the cyber resilience of entities covered by Romanian NIS2 Law.

The press release is available here (Romanian only).

Statistics