Skip to content

NIS2: fines reach €10 million, and 2026 is when the audits start

If your company is in a covered sector and has more than 50 employees, you are probably in scope — and the grace period is over. Romania transposed the directive through OUG 155/2024, amended by Law 124/2025, with DNSC as the competent authority.

Penalties run to €10 million or 2% of annual turnover, and the directive puts responsibility on management personally, not just on the IT department. That is the change from NIS1 that most boards have not absorbed yet.

Who has trusted us since 2004: Electrocentrale București · Poliția de Frontieră · ADR Nord-Vest · Andritz Hydro · Shell România. Public sector, energy and heavy industry — buyers who audit their suppliers before signing. See the case studies.

Check the current text before you act on dates. Transposition, thresholds and deadlines change. This page describes the mechanism and is not legal advice. We work from the text in force at project date and, where interpretation is needed, alongside your legal counsel.

The deadlines that apply once you are in scope

  • 30 days — register with DNSC
  • 60 days — gap analysis and risk treatment plan
  • 90 days — policies and procedures in place
  • 180 days — priority technical controls implemented

And once you are running: incident reporting at 24 hours (early warning), 72 hours (notification) and 30 days (final report). Those windows are short enough that they only work if someone has already decided in advance who makes the call.

Two ways this lands on your desk

You are in scope

Sector plus size puts you in as an essential or important entity. You owe DNSC registration, risk management, incident reporting, business continuity, supply chain assessment and management-level accountability.

We deliver: scope determination, gap analysis, system inventory, supplier register and questionnaires, and incident procedures with named owners and realistic timings.

You supply someone who is

You may be entirely out of scope yourself and still feel this — because your customers are obliged to assess their suppliers. That arrives as security questionnaires, new contract clauses and audit rights.

We deliver: prepared answers to those questionnaires, documented development and vulnerability practices, contract clauses you can actually meet, and preparation for customer audits.

If you are deploying AI, it is in scope too

An AI agent with access to your systems is not a separate legal category. Under NIS2 it is one more system on your attack surface and, usually, one more supplier in your chain. It has to be inventoried, risk-assessed, and covered by your incident procedures like anything else.

This is why we build agents with audit logging and system documentation from the start — so the thing that makes your operation faster does not simultaneously create a compliance gap.

Why us rather than a pure compliance consultancy

Most NIS2 consultancies produce documents. We build the systems that produce the evidence — because we have been building software for organisations that get audited hard: a state energy producer, a border police agency, a regional development agency. We know the difference between a policy that passes review and one that survives contact with an actual operation.

What we do not do: we are not a law firm and we do not issue legal opinions, and we are not a certification body. Where interpretation is needed, we work with your counsel.

The first question is free to answer

Most companies do not actually know whether they are in scope. That takes one short conversation — your sector, headcount and turnover. Book a free 30-minute call and we will tell you where you stand, and what it would cost to close the gap.

If AI is also on your roadmap, the readiness assessment covers both in a single engagement rather than two overlapping projects.

Find out what this would cost you — in 30 minutes, free

Tell us one process that eats your team's time. We will tell you on the call whether an AI agent can take it over, roughly what it costs, and what it would save. If it is not a good fit, we say so — we would rather lose the sale than sell you the wrong thing.