Selection guide 2026

NIS2 Consulting: how to choose the right consultant

NIS2 consulting is the professional service through which an organisation is assisted in interpreting OUG 155/2024 and implementing the 17 Art. 21 pillars. A correct NIS2 consulting project cannot be delivered by a single person — it requires a multidisciplinary team of DNSC certified NIS2 auditors, ISO/IEC 27001 Lead Auditors, GRC specialists and security engineers. This guide explains what to look for, what to avoid and how a real engagement is structured.

Updated: April 2026 · For essential and important entities in the 18 regulated sectors

In brief

What a NIS2 consultant does

A NIS2 consultant translates legal requirements (OUG 155/2024, EU Directive 2022/2555, DNSC guidelines) into concrete actions adapted to the organisation. The activity covers four areas:

1. Diagnostic (Gap Analysis)

Structured evaluation across the 17 Art. 21 pillars: questionnaire, interviews with process owners, review of existing documentation, direct system observation. Outcome: gap report with maturity score per domain, gap prioritisation by risk and effort, budget and schedule estimate.

2. Planning

Risk treatment plan, staged implementation calendar, budget allocation per category (consulting, software, hardware, training, audit), role definition (CISO, process owners, IR team), formal approval by the management body.

3. Assisted implementation

Drafting policies and procedures, support in choosing technical solutions (SIEM, EDR, MFA, backup), drafting SCRM contractual clauses, leading risk meetings, delivering specialised training, support with DNSC registration.

4. Audit preparation

Internal mock audit, incident simulations (table-top exercises, red team), evidence review, preparing the team for auditor questions, final remediation plans.

When you need NIS2 consulting

Consulting is not legally mandatory but becomes practically necessary when the organisation finds itself in one or more situations:

The multidisciplinary project team

NIS2 implementation is not a single discipline — it combines legal, organisational, technical and operational. A serious project allocates a team of 4-7 specialists with differentiated roles:

RoleContribution
Lead consultant / Project managerCoordination, communication with the client, progress reporting
NIS2 auditorInterpreting legal requirements, mock audit, formal reviews
ISO/IEC 27001 Lead Auditor / Lead ImplementerISMS framework, policy drafting, ISO ↔ NIS2 mapping
GRC specialistRisk register, impact analysis, management reporting
Cybersecurity engineerTechnical configurations (SIEM, EDR, MFA, network segmentation)

Note: a single person cannot credibly cover all these roles. The question "who will actually work on my project?" matters more than the firm's name.

Consultants' relationship with DNSC

DNSC accredits both individuals and legal entities. Individual auditors are nominally certified after training programs and exams. Firms are authorised as NIS2 audit/consulting service providers based on the certified auditors they employ and meeting organisational criteria.

What you can verify with DNSC:

In practice, the value of a firm comes from: (a) the number and quality of individually DNSC-certified auditors on the team, (b) complementary certifications (ISO 27001 LA, CISA, CISM), (c) concrete experience in your sector, (d) verifiable references.

Common engagement models

Fixed scope project

The most frequent form for initial implementation. Clear scope (e.g. "achieving NIS2 compliance in 9 months"), defined deliverables (Gap Analysis, plan, documentation set, mock audit), fixed price or range. Advantage: budget predictability. Disadvantage: rigid to scope changes.

Monthly retainer

Band of consumable hours per month (10-40h), with preferred rates, for compliance maintenance, incident support, periodic reviews. Useful after initial implementation, for the annual maintenance cycle.

Time and materials

Fixed hourly rate, billing based on actual consumption. Useful for targeted missions: drafting one policy, 2-week pre-audit support, expertise on a specific sector.

Hybrid model: platform + consulting

The client uses a self-service platform (CysNis or equivalent) for standardisable elements — documentation, tracking, reporting — and uses consulting only for non-standardisable areas (sector interpretation, architectural decisions, final audit). Significantly reduces total cost. See dedicated section below.

Sectors served

The 18 NIS2 sectors have different practical requirements. Ask the consultant what concrete experience they have in your sector:

EnergyICS/OT specialisation, IEC 62443, integration with ANRE and ENTSO-E regulations.
TransportTraffic management systems, civil aviation integration, connected vehicle security.
Banking and financialNIS2 + DORA, integration with BNR/ASF rules, stress testing.
HealthcareNIS2 + strict GDPR, medical device security, MDR/IVDR.
Water and waste waterDistributed SCADA systems, specific safety risks.
Digital infrastructureDNS, IXP, cloud, data center — advanced technical requirements.
Public administrationNIS2 + ANS rules, ROEDU integration, transparency obligations.
FoodTraceability, enterprise application security, industrial IoT.
B2B ICT servicesSaaS, MSP, security offering for NIS2 clients.
ResearchSensitive data security, information classification, IP protection.

How to choose the right NIS2 consultant

A practical evaluation grid:

  1. Request 2-3 references from your sector — from the last 18 months, directly contactable.
  2. Check a documentation sample — an example of a recently delivered policy or procedure. Drafting quality says everything.
  3. Ask about the framework used — a consultant who doesn't mention CyFun® 2025, ISO 27001, NIST CSF in the first interview is not prepared.
  4. Request a communication plan — meeting frequency, progress reporting, escalation.
  5. Check the knowledge transfer model — total dependence on the consultant at project end is a major risk.
  6. Beware of "guaranteed positive audit" — no serious consultant guarantees an audit outcome; they can guarantee the process.

Pitfalls to avoid

Hybrid model: platform + consulting

For small and medium organisations, the most efficient cost-result ratio is combining a self-service platform with targeted consulting:

Covered by platformCovered by consulting
Automatic classification checkArchitectural decisions (segmentation, zoning)
Guided Gap Analysis (questionnaire + PDF report)Sector-specific interpretations
Documentation template library (100+ documents)SCRM clause adaptation to specific suppliers
Compliance tracking across the 17 pillarsFinal mock audit and DNSC preparation
Risk register with 5x5 matrixRisk workshops with management
DNSC incident notification generatorReal support during an incident
60/150 day deadline trackingDNSC communication strategies

This combination typically reduces total cost by 40-60% compared to pure consulting, while preserving deliverable quality.

See the platform and request an evaluation

Free account, no card required. Access to automatic classification, internal evaluation and the NIS2 template catalog.

Create free account View consulting service

Frequently asked questions about NIS2 consulting

What is NIS2 consulting?
The professional service through which an organisation is assisted in interpreting OUG 155/2024 and implementing the 17 Art. 21 pillars. Covers diagnostic (Gap Analysis), planning, assisted implementation (policies, technical solutions, training) and audit preparation.
Are there DNSC accredited firms for NIS2?
Yes. DNSC accredits both individuals (auditors) and legal entities (audit/consulting firms). Firms are authorised as providers based on the certified auditors they employ and meeting organisational criteria. Ask for the firm's authorisation number and nominal list of auditors.
Can I implement NIS2 myself without a consultant?
Yes, if you have competent internal resources (experienced CISO, security team). In practice, small and medium organisations rarely have this complete capability. Efficient solution: self-service platform for standardisable parts + targeted consulting on complex technical areas.
How many consultants should a serious firm have?
For a complete NIS2 project, the usual allocation is 4-6 specialists with differentiated roles: lead consultant, NIS2 auditor, ISO 27001 Lead Auditor, GRC specialist, security engineer. A firm with 1-2 consultants can do Gap Analysis but not full implementation.
What deliverables do I get from a NIS2 consulting project?
Typical deliverables: Gap Analysis report with scoring per domain, risk treatment plan, complete set of policies and procedures (15-25 documents), populated risk register, implementation plan with calendar, documented technical configurations, training plan, mock audit report, DNSC-ready file. All formally approved by management.
How can I make sure I don't remain dependent on the consultant?
Explicitly request at contracting: (1) documented knowledge transfer, (2) training sessions for the internal team, (3) all templates and documents in editable format (DOCX, XLSX), (4) operational procedures written to be run internally, (5) a "decoupling" plan at contract end. Refusal of these points = deliberate lock-in signal.
Will the consultant also do my final audit?
Strong recommendation: NO. Classic conflict of interest — the implementing consultant cannot impartially audit. Best practice: one firm for implementation, another independent for audit. Or: same firm but completely separated teams with formal documented separation. DNSC may reject audits with obvious conflicts.
How does the first interview with a NIS2 consultant work?
Typically 60-90 minutes: organisation and sector presentation, first classification questions (size, sectors, infrastructure), discussion about current maturity, deadline expectation, indicative budget, questions about the consultant's team and methodology. Outcome: preliminary offer with scope, calendar, price, allocated team.
Can I change the NIS2 consultant during the project?
Yes, but the cost is significant — the new consultant must get acquainted with the context, which takes 2-4 weeks. Make sure documentation remains entirely with you (in editable format) and that processes are written — so migration is possible. Avoid lock-in to the consultant's proprietary tools.
What questions reveal whether a NIS2 consultant is good?
Filter questions: "Who concretely will work on my project and what certifications do they hold?", "Show me an example of a recently delivered policy", "What is the difference between Art. 20 and Art. 21?", "How do you integrate CyFun® 2025 with OUG 155/2024 requirements?", "What experience do you have in sector X?", "How do you handle a reportable incident occurring during the project?".

Glossary

NIS2
Directive (EU) 2022/2555, transposed in Romania through OUG 155/2024.
DNSC
National Cyber Security Directorate, the competent authority for NIS2 in Romania.
DNSC certified NIS2 auditor
Natural person individually certified by DNSC for NIS2 compliance audit.
ISO 27001 Lead Auditor
Individual certification for auditing Information Security Management Systems (ISMS).
CISA
Certified Information Systems Auditor — ISACA certification for IT audit.
CISSP
Certified Information Systems Security Professional — (ISC)² cybersecurity certification.
CRISC
Certified in Risk and Information Systems Control — ISACA IT risk certification.
CyFun® 2025
Best practices framework from the Centre for Cybersecurity Belgium.
SCRM
Supply Chain Risk Management.
GRC
Governance, Risk and Compliance — integrated discipline.
Mock audit
Simulated audit before the real one, for gap identification.
Retainer
Contract with a band of monthly consumable hours at preferential rate.