On September 29, 2026, DNSC issued its first fine under the NIS2 law to an institution within the central public administration: RON 50,000. The reason was not a missed cyberattack or a hidden incident. It was something much simpler: the institution had failed to register in the DNSC registry on time.
We suspect that in many meetings, the question was asked the following morning: “Did we register?” It’s a good question, but it’s not the right one.
What happened
The sanction concerns a specialized body of the central public administration, within the Public Administration sector. It was imposed because the institution failed to submit, within the required timeframe, the notification provided for under Article 18(2) of Emergency Ordinance No. 155/2024, an offense sanctioned under Article 60(1)(o).
Article 18 refers to the notification through which essential and important entities register in the DNSC registry. In the case of the sanctioned entity, the general deadline for this notification expired on September 22, 2025. In other words, the sanction was not imposed for a mistake made under the pressure of an attack, but for an administrative step that had been overdue for a year.
Step zero
The notification for the purpose of registering in the DNSC registry is the basic requirement imposed by law. You tell the authority who you are, what you do, and that you fall under NIS2. It does not require a SOC or major investments, only that someone within the organization has read the law and asked: “Does this apply to us?”
If this step was missed, the question that matters to us is not why a form was not submitted, but what else was not done. Usually, an organization that fails to identify that it falls under NIS2 is likely to have other gaps as well: risk analysis, an incident response plan, management ownership of cybersecurity. The registry is simply where these gaps become visible.
The temptation to treat checking the boxes as the only requirement
This is where the risky part comes in: the natural reaction after a fine is to fix exactly what you were fined for. You submit the notification, receive confirmation, and close the subject. Checked.
Except that registering in the registry does not make you secure; it only makes you visible. From that point on, DNSC knows about you and can check the rest: risk management measures, incident reporting (an early warning within 24 hours, a complete notification within 72), and management responsibility. If you registered just to avoid the fine, you have simply moved the problem to the next inspection.
What are the costs, really?
RON 50,000 represents the smallest part of the bill. The real costs come on the day when you actually have an incident and discover that there is no one responsible for detecting it, no one to decide what needs to be done. In situations like these, we are talking about blocked services, lost data, and customers and partners finding out about the incident through the press.
And let’s talk about the responsibility of management: NIS2 has taken cybersecurity out of the IT department and put it on the boardroom table. If you invest only enough to avoid a fine, you remain exposed precisely to the costs that matter.
A small test for your next meeting
To see where you stand, before scheduling an audit, ask your management colleagues three things and listen to how quickly the answers come:
- Do we know for certain whether we fall under Emergency Ordinance 155/2024, and what type of entity are we?
- If we had been attacked yesterday, how and when would we have found out?
- Who decides, at 3 a.m., that we need to notify DNSC?
If the first question is followed by silence, start there. If the silence comes after the second or third question, the main problem is not the risk of a fine.
Instead of a conclusion
It would be a shame to read the first fine merely as an administrative reminder. It is more like a mirror: it does not show us how well we fill out forms, but how well we know our own organization.
Compliance is not the goal. It is simply proof that we have done our job.
At FORT, we help organizations be prepared, not merely covered. If you want to discover together where your organization currently stands, you can find us here.