NIS2 (transposed in Romania through GEO 155/2024) raises the stakes significantly. For essential entities, fines can reach up to EUR 10 million or 2% of total worldwide annual turnover — whichever is higher. For important entities, the thresholds are EUR 7 million or 1.4%.
What truly changes the game is not only the amount, but management accountability. Management bodies must approve the cybersecurity measures and oversee their implementation. In addition, authorities can temporarily suspend responsible individuals from their functions and publicly name those at fault. Security is no longer "the IT team's problem" — it becomes a duty of the company's leadership.
The good news: compliance is a process, not a one-off expense. It starts with checking your scope and assessing existing measures, then a realistic, phased plan. We tell you for free, in about 5 minutes, whether you are in scope.
Sources
This article was generated with AI assistance.