Practical guide 2026

NIS2 Auditor and Mandatory Documentation

A NIS2 auditor is a natural person individually certified by DNSC, or a firm authorised by DNSC based on the certified auditors it employs, to assess compliance with OUG 155/2024 (Romania's transposition of EU Directive 2022/2555). This guide clarifies the DNSC accreditation model (both individuals and firms), the mandatory documentation to prepare before the audit (~25 documents), how internal and external audits differ, and the stages of a complete compliance audit.

Updated: April 2026 · Applicable to essential and important entities in 18 regulated sectors

In brief

Who is a NIS2 auditor

A NIS2 auditor is a natural person who has completed a specific training program (covering OUG 155/2024 legislation, EU Directive 2022/2555, DNSC guidelines, audit methodology), passed an official exam and obtained an individual certification issued by DNSC. The auditor is professionally responsible for evaluating an organisation's compliance with NIS2 requirements.

A NIS2 auditor is not a consultant. The difference is functional: the consultant helps with implementation, the auditor evaluates the result. For independence, the same person (or team) cannot both advise and formally audit the same organisation in the same compliance cycle.

In practice, NIS2 auditor profiles typically combine multiple certifications for credibility and technical coverage:

Internal vs external NIS2 audit

AspectInternal auditExternal audit
Who performs itInternal auditor of the organisation, independent from the audited areaIndependent external auditor, DNSC certified
Typical frequencyAnnual or semi-annual, on rotating domainsAnnual or biennial, depending on sector and risk
MandatoryImplicitly mandatory (Art. 21(f))For certain categories of essential entities
Typical costInternal resource (indirect cost)5,000-25,000 EUR per cycle
Value at DNSC inspectionConfirms continuous self-assessment processBrings credibility through independence
Third-party recognitionLimitedAccepted by DNSC, B2B partners, insurers

Recommendation: both types are complementary. Internal audit provides continuity (identifying gaps between external cycles), while external audit independently validates the results.

Stages of a complete NIS2 audit

Stage 1 — Audit planning (1-2 weeks)

Defining audit scope (all 17 pillars or focus on specific domains), audit criteria (OUG 155/2024 + DNSC guidelines + CyFun® 2025 framework), allocated team, schedule. A confidentiality agreement is signed with the auditor.

Stage 2 — Preparation (2-4 weeks)

The organisation prepares the audit file: complete documentation (~30 documents), technical evidence lists (configuration screenshots, sample logs, tool reports), nominating people for interviews.

Stage 3 — On-site audit (3-10 days)

The auditor performs: document review, interviews (CISO, process owners, IT, legal, HR, management), technical inspection (configuration verification, SIEM operation observation, backup tests, MFA verification), possibly simulations (mock incident, table-top exercise).

Stage 4 — Reporting (1-3 weeks)

Audit report with: scoring per pillar (compliant/partial/non-compliant), detailed findings with evidence, remediation recommendations, proposed corrective action plan, formal auditor opinion.

Stage 5 — Corrective actions and closure (variable)

The organisation implements corrective actions. The auditor may perform a follow-up audit to verify remediation of major findings.

What the NIS2 auditor concretely checks

For each of the 17 pillars, the auditor checks four levels:

  1. Existence of documentation — formally approved policy/procedure, with version and date.
  2. Content quality — adapted to the real context of the organisation, not generic copy-paste.
  3. Effective application — interviews and direct observation confirm the described process is followed.
  4. Operational evidence — logs, reports, minutes, records that prove processes are running.

Example on the "Incident management" pillar: the auditor checks (1) existence of the IR policy and procedure, (2) the procedure explicitly includes 6h/24h/72h timelines, (3) interview with the IR team — they are familiar with the flow, (4) populated incident register, reports actually sent to DNSC for reportable incidents.

Types of evidence accepted at audit

CategoryExamples
Formal documentsApproved policies, management decisions, signed contracts, NDAs
Technical configurationsScreenshots of SIEM, EDR, firewall, AD, MFA systems, backup configurations
Logs (sample)Authentication logs, incident response logs, configuration change logs
Automated reportsVulnerability scanner reports, EDR reports, backup test reports
Operational recordsRisk meeting minutes, training reports, documented IR simulations, supplier evaluations
InterviewsVerbal confirmation of procedure knowledge (CISO, owners, users)
Direct observationAuditor witnesses execution of a process (key rotation, backup restore, alert triggering)

Auditors give maximum credibility to the combination: formal document + technical configuration + operational log + interview confirmation. A single category of evidence (e.g. only documents) is not sufficient.

Difference between NIS2 auditor and ISO 27001 auditor

CriterionNIS2 auditorISO 27001 auditor
Framework evaluatedOUG 155/2024 (transposition of EU Directive 2022/2555)ISO/IEC 27001:2022 standard
Who certifies the auditorDNSC (national authority)Accredited bodies (PECB, BSI, IRCA)
RecognitionNational (Romania)International
Main focusLegal compliance + critical sector resilienceISMS — Information Security Management System
Resulting certificationConformity attestation (not formal certificate)ISO 27001 certificate valid for 3 years
Specific requirementsDNSC registration, 6h/24h/72h reporting, legal sanctionsPlan-Do-Check-Act, Annex A controls
Overlap~70% of controls common. ISO 27001 implementation covers most NIS2 requirements.

Ideal profile: an auditor with both certifications — can simultaneously evaluate NIS2 compliance and ISMS maturity, efficient in time and budget.

Prepare your audit documentation

Access 100+ pre-filled NIS2 templates, risk register, compliance tracking. Free account, no card required.

Create free account View audit service

Frequently asked questions about NIS2 auditors

Who is a NIS2 auditor?
A natural person individually certified by DNSC, or a firm authorised by DNSC as a NIS2 audit service provider. Individual certification requires completing a specific training program and passing an official exam. Firm authorisation is based on the individually certified auditors they employ and meeting organisational requirements (processes, professional insurance, independence).
How do I check if an auditor is DNSC certified?
Verification is done at two levels. At firm level: ask for the DNSC authorisation number, exact name and tax ID, then check the public DNSC list of audit service providers. At individual level: ask for the exact name of the auditor who will sign the report, copy or number of their individual DNSC certification. An authorised firm must actually have certified auditors on the team — not just on paper.
Is the NIS2 audit mandatory?
Periodic internal audit — implicitly mandatory through Art. 21(f) (evaluation of measure effectiveness). External independent audit — not universally mandatory by law, but strongly recommended and required for certain categories of essential entities, specific sectors, or as a requirement from B2B partners / insurers.
How much does an external NIS2 audit cost?
For a small organisation (50-100 employees): 5,000-12,000 EUR. For medium (250 employees): 10,000-20,000 EUR. For large or with OT/SCADA systems: 20,000-50,000+ EUR. Costs include planning, on-site audit, reporting. Corrective actions are separate.
How long does a complete NIS2 audit take?
For a small organisation: 5-10 auditor days (3-5 on site + 2-5 writing the report). Medium: 10-20 auditor days. Large or complex: 20-40+ days. Document preparation before the audit typically takes longer than the audit itself.
Can I use the same auditor for NIS2 and ISO 27001?
Yes, if the person holds both certifications (DNSC + ISO 27001 Lead Auditor). A combined audit saves time and budget — there is ~70% overlap between requirements. Important: certifications must be valid, the person should have recent practical experience on both frameworks.
What documents must be prepared before the audit?
Minimum set: approved ISMS policy, risk register, risk treatment plan, IR policy and procedure (with 6h/24h/72h timelines), BCM plan, DR plan, access control policy, MFA policy, cryptography policy, SCRM policy, critical supplier register, internal audit plan, incident register, training records. Typical total: 25-30 documents.
Can the auditor be the same as the consultant who implemented?
Strong recommendation: NO. Classic conflict of interest. Best practice: one firm/person for implementation, another fully independent for audit. Or: same firm with formally separated teams, with documented separation. DNSC may reject audits with obvious conflicts or consider them less credible.
What happens if the audit finds non-conformities?
The auditor classifies non-conformities (major / minor / observations), includes them in the report with evidence and recommendations. The organisation develops a corrective action plan with deadlines. For major non-conformities, the auditor may perform a follow-up audit. Non-conformities do not prevent operation but must be remediated before DNSC inspection.
How often should the NIS2 audit be done?
Internal audit: annually (minimum), with rotation across domains if scope is large. External audit: annually or biennially, depending on sector, size and risk. Ad-hoc audit: after major incidents, significant infrastructure or legal requirement changes, or before announced DNSC inspections.
Can DNSC inspect me without prior audit?
Yes. DNSC can initiate inspections at any time after entity registration. Inspections can be planned (scheduled) or ad-hoc (after complaints, incidents). Constant preparation through internal and external audits is the practical defence — you cannot build compliance in one week when DNSC announces an inspection.
Who signs the NIS2 audit report?
The DNSC certified auditor, individually, signs and professionally assumes the report. For team audits, there is a lead auditor who signs the report, the rest of the team being mentioned by name with their roles. The audit firm may appear on the letterhead, but professional responsibility is individual.
Is there an official NIS2 certificate like ISO 27001?
No. Unlike ISO 27001, NIS2 has no formal certificate with fixed validity. The audit result is a conformity attestation issued by the auditor, valid at the audit date. Compliance must be continuously maintained and demonstrable at any moment of a possible DNSC inspection.

Glossary

NIS2 auditor
Natural person individually certified by DNSC for OUG 155/2024 compliance audit.
DNSC
National Cyber Security Directorate (Directoratul National de Securitate Cibernetica).
OUG 155/2024
The Government Emergency Ordinance transposing NIS2 into Romanian law.
ISMS
Information Security Management System.
ISO 27001 Lead Auditor
Individual certification for ISO 27001 system audit.
CISA
Certified Information Systems Auditor (ISACA) — IT audit certification.
Conformity attestation
Formal opinion of the auditor that the organisation meets NIS2 requirements at audit date.
Mock audit
Simulated audit before the real one, for gap identification.
Corrective actions
Concrete measures to remediate identified non-conformities.
Follow-up audit
Tracking audit for verifying remediation of major findings.
Auditor independence
Absence of conflicts of interest between auditor and audited area.
Audit evidence
Documents, configurations, logs, interviews, observations supporting auditor opinion.