ITER/RORomania
What the record establishes for Romania: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | National Supervisory Authority for Personal Data Processing reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | The national cyber security incident response team binding | Not set by the ordinance. The Directorate names its platform PNRISC and publishes it on its own domain. The address is not recorded here: the host answers but refuses every automated request, so no page naming it was read. | ro oug 155 2024 |
| Financial supervisorDORA, article 19 | Banca Naţională a României reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Autoritatea de Supraveghere Financiara (ASF) reported | — | esma mar nca |
Transposition of NIS2 binding
| Act | Ordonanța de urgență nr. 155/2024 |
|---|---|
| In force | Published in Monitorul Oficial on 31 December 2024. Articles 60 and 61 take effect thirty days after publication. |
| Recipient | The national cyber security incident response team |
| Moves a term | No. None. The cascade is the Directive's, anchor included: the early warning «nu mai târziu de 24 de ore de la data la care au luat cunoștință de incidentul semnificativ», the incident report «nu mai târziu de 72 de ore din momentul în care au luat cunoștință», an interim report at the team's request, and the final report «în termen de cel mult o lună de la transmiterea notificării incidentului». |
| Standing | Read in the ordinance on the legislative portal. It names the recipient by function, the national incident response team, rather than by name, and does not set the channel. |
| Source | ro oug 155 2024 |
An event in Romania
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
