In brief
- DNSC accredits both individuals and firms — firms are authorised based on the certified auditors they employ. Verify both components.
- Mandatory documentation: ~25 documents across governance, risk, incidents, BCM, access, technical, SCRM, audit categories.
- Periodic internal audit: implicitly mandatory (Art. 21(f), evaluation of measure effectiveness).
- External audit: not universally mandatory but strongly recommended and required for certain categories.
Who is a NIS2 auditor
A NIS2 auditor is a natural person who has completed a specific training program (covering OUG 155/2024 legislation, EU Directive 2022/2555, DNSC guidelines, audit methodology), passed an official exam and obtained an individual certification issued by DNSC. The auditor is professionally responsible for evaluating an organisation's compliance with NIS2 requirements.
A NIS2 auditor is not a consultant. The difference is functional: the consultant helps with implementation, the auditor evaluates the result. For independence, the same person (or team) cannot both advise and formally audit the same organisation in the same compliance cycle.
In practice, NIS2 auditor profiles typically combine multiple certifications for credibility and technical coverage:
- NIS2 auditor certification (DNSC) — mandatory
- ISO/IEC 27001 Lead Auditor (PECB, BSI, IRCA) — for ISMS competencies
- CISA (ISACA) — for IT audit
- CISSP or CISM — for advanced security competencies
- Sector certifications (e.g. IEC 62443 for OT, HCISPP for healthcare)
Internal vs external NIS2 audit
| Aspect | Internal audit | External audit |
|---|---|---|
| Who performs it | Internal auditor of the organisation, independent from the audited area | Independent external auditor, DNSC certified |
| Typical frequency | Annual or semi-annual, on rotating domains | Annual or biennial, depending on sector and risk |
| Mandatory | Implicitly mandatory (Art. 21(f)) | For certain categories of essential entities |
| Typical cost | Internal resource (indirect cost) | 5,000-25,000 EUR per cycle |
| Value at DNSC inspection | Confirms continuous self-assessment process | Brings credibility through independence |
| Third-party recognition | Limited | Accepted by DNSC, B2B partners, insurers |
Recommendation: both types are complementary. Internal audit provides continuity (identifying gaps between external cycles), while external audit independently validates the results.
Stages of a complete NIS2 audit
Stage 1 — Audit planning (1-2 weeks)
Defining audit scope (all 17 pillars or focus on specific domains), audit criteria (OUG 155/2024 + DNSC guidelines + CyFun® 2025 framework), allocated team, schedule. A confidentiality agreement is signed with the auditor.
Stage 2 — Preparation (2-4 weeks)
The organisation prepares the audit file: complete documentation (~30 documents), technical evidence lists (configuration screenshots, sample logs, tool reports), nominating people for interviews.
Stage 3 — On-site audit (3-10 days)
The auditor performs: document review, interviews (CISO, process owners, IT, legal, HR, management), technical inspection (configuration verification, SIEM operation observation, backup tests, MFA verification), possibly simulations (mock incident, table-top exercise).
Stage 4 — Reporting (1-3 weeks)
Audit report with: scoring per pillar (compliant/partial/non-compliant), detailed findings with evidence, remediation recommendations, proposed corrective action plan, formal auditor opinion.
Stage 5 — Corrective actions and closure (variable)
The organisation implements corrective actions. The auditor may perform a follow-up audit to verify remediation of major findings.
What the NIS2 auditor concretely checks
For each of the 17 pillars, the auditor checks four levels:
- Existence of documentation — formally approved policy/procedure, with version and date.
- Content quality — adapted to the real context of the organisation, not generic copy-paste.
- Effective application — interviews and direct observation confirm the described process is followed.
- Operational evidence — logs, reports, minutes, records that prove processes are running.
Example on the "Incident management" pillar: the auditor checks (1) existence of the IR policy and procedure, (2) the procedure explicitly includes 6h/24h/72h timelines, (3) interview with the IR team — they are familiar with the flow, (4) populated incident register, reports actually sent to DNSC for reportable incidents.
Types of evidence accepted at audit
| Category | Examples |
|---|---|
| Formal documents | Approved policies, management decisions, signed contracts, NDAs |
| Technical configurations | Screenshots of SIEM, EDR, firewall, AD, MFA systems, backup configurations |
| Logs (sample) | Authentication logs, incident response logs, configuration change logs |
| Automated reports | Vulnerability scanner reports, EDR reports, backup test reports |
| Operational records | Risk meeting minutes, training reports, documented IR simulations, supplier evaluations |
| Interviews | Verbal confirmation of procedure knowledge (CISO, owners, users) |
| Direct observation | Auditor witnesses execution of a process (key rotation, backup restore, alert triggering) |
Auditors give maximum credibility to the combination: formal document + technical configuration + operational log + interview confirmation. A single category of evidence (e.g. only documents) is not sufficient.
Difference between NIS2 auditor and ISO 27001 auditor
| Criterion | NIS2 auditor | ISO 27001 auditor |
|---|---|---|
| Framework evaluated | OUG 155/2024 (transposition of EU Directive 2022/2555) | ISO/IEC 27001:2022 standard |
| Who certifies the auditor | DNSC (national authority) | Accredited bodies (PECB, BSI, IRCA) |
| Recognition | National (Romania) | International |
| Main focus | Legal compliance + critical sector resilience | ISMS — Information Security Management System |
| Resulting certification | Conformity attestation (not formal certificate) | ISO 27001 certificate valid for 3 years |
| Specific requirements | DNSC registration, 6h/24h/72h reporting, legal sanctions | Plan-Do-Check-Act, Annex A controls |
| Overlap | ~70% of controls common. ISO 27001 implementation covers most NIS2 requirements. | |
Ideal profile: an auditor with both certifications — can simultaneously evaluate NIS2 compliance and ISMS maturity, efficient in time and budget.
Prepare your audit documentation
Access 100+ pre-filled NIS2 templates, risk register, compliance tracking. Free account, no card required.
Create free account View audit serviceFrequently asked questions about NIS2 auditors
Who is a NIS2 auditor?
How do I check if an auditor is DNSC certified?
Is the NIS2 audit mandatory?
How much does an external NIS2 audit cost?
How long does a complete NIS2 audit take?
Can I use the same auditor for NIS2 and ISO 27001?
What documents must be prepared before the audit?
Can the auditor be the same as the consultant who implemented?
What happens if the audit finds non-conformities?
How often should the NIS2 audit be done?
Can DNSC inspect me without prior audit?
Who signs the NIS2 audit report?
Is there an official NIS2 certificate like ISO 27001?
Glossary
- NIS2 auditor
- Natural person individually certified by DNSC for OUG 155/2024 compliance audit.
- DNSC
- National Cyber Security Directorate (Directoratul National de Securitate Cibernetica).
- OUG 155/2024
- The Government Emergency Ordinance transposing NIS2 into Romanian law.
- ISMS
- Information Security Management System.
- ISO 27001 Lead Auditor
- Individual certification for ISO 27001 system audit.
- CISA
- Certified Information Systems Auditor (ISACA) — IT audit certification.
- Conformity attestation
- Formal opinion of the auditor that the organisation meets NIS2 requirements at audit date.
- Mock audit
- Simulated audit before the real one, for gap identification.
- Corrective actions
- Concrete measures to remediate identified non-conformities.
- Follow-up audit
- Tracking audit for verifying remediation of major findings.
- Auditor independence
- Absence of conflicts of interest between auditor and audited area.
- Audit evidence
- Documents, configurations, logs, interviews, observations supporting auditor opinion.
