Deadline Approaching for Identification of Critical Entities in Romania

The deadline of 17 July 2026 for the identification of critical entities under the Romanian critical entities resilience framework is here. By this date, the National Coordination Centre for Critical Infrastructure Protection (CNCPIC), with support from the relevant sectoral competent authorities, must identify the critical entities that will be subject to the compliance obligations under Law No. 294/2024 on the resilience of critical entities, which transposes the EU Critical Entities Resilience Directive (“CER Directive”) into Romanian law.
Law No. 294/2024 applies – with some exceptions – to public and private entities across the eleven critical sectors and sub-sectors provided by Law No. 294/2024.
The eleven sectors covered are: (1) Energy; (2) Transport; (3) Banking; (4) Financial market infrastructures; (5) Health; (6) Drinking water; (7) Wastewater; (8) Digital infrastructure; (9) Public administration; (10) Space; and (11) Food production, processing and distribution.
Once identified as a critical entity, organizations must comply with several core obligations related to risk assessment, implementation of resilience measures, the appointment of a liaison officer and the notification of incidents.
Additionally, the critical entities may request background checks through the sectoral competent authority for personnel who perform sensitive functions within or for the benefit of the critical entity; are authorized to have direct or remote access to the entity’s premises, information or control systems (including in relation to security); or are being considered for recruitment into positions meeting these criteria.
From among these critical entities, critical entities of particular European significance will also be identified. These will be subject to additional obligations, including cooperation with the European Commission and other Member States, and compliance with any specific measures established by the European Commission.
Non-compliance with the obligations under Law No. 294/2024 carries administrative fines. Failure by critical entities to conduct risk assessments, adopt technical, security and organizational measures, implement resilience plans, designate a liaison officer, or notify incidents is sanctioned with fines ranging from RON10,000 to RON30,000 (approximately EUR2,000 to EUR6,000).
Lesser sanctions of RON5,000 to RON10,000 (approximately EUR1,000 to EUR2,000) apply for failures related to informing CNCPIC about providing essential services in six or more Member States; complying with obligations established by the European Commission for critical entities of particular European significance; or cooperating with the European Commission and other Member States.
Irina Macovei, Head of Intellectual Property and Technology, Counsel, DLA Piper
Corina Bădiceanu, Managing Associate, DLA Piper
