Romania's compliance with the EU's NIS2 cybersecurity directive has come under scrutiny after a series of cyberattacks paralysed critical digital infrastructure, including the National Agency for Cadastre and Land Registration (ANCPI), disrupting public services and economic activity. In a parliamentary question submitted on 20 July 2026, ECR MEP Georgiana Teodorescu pressed the European Commission on whether Romania has properly transposed and applied the directive's supervisory framework for critical public services, and what support the EU Agency for Cybersecurity (ENISA) has provided.
The question, addressed to the Commission under parliamentary rules, seeks concrete answers on three fronts. First, Teodorescu asks whether the attacks were reported at EU level using the mechanisms set out in Directive (EU) 2022/2555 (NIS2) and what technical assistance ENISA has given Romanian authorities so far. Second, she queries whether the Commission considers that Romania has correctly implemented the NIS2 supervisory and control framework for critical public services. Third, she asks whether the Commission and ENISA intend to assess the cyber resilience of Romania's critical digital infrastructure and issue specific recommendations to strengthen institutional capacity and supervisory mechanisms.
The NIS2 Directive, which entered into force in January 2023 and required transposition by October 2024, obliges member states to designate national authorities responsible for supervision and incident reporting, and to ensure resilience of essential and important entities. The Commission monitors correct application of EU law. Teodorescu's question signals concern that Romania may be falling short of its obligations, particularly in the wake of attacks that brought a key public service to a standstill.
The Commission is expected to reply within approximately six weeks. Its answer will indicate whether it views Romania's transposition and enforcement as adequate, and whether further EU-level action—such as a resilience assessment or targeted recommendations—is planned. The outcome could have implications for other member states with similar vulnerabilities, as well as for the credibility of the NIS2 framework itself.