In brief
- Team, not individual: NIS2 auditor + ISO 27001 Lead Auditor + GRC specialist + security engineer.
- DNSC accredits both individuals and legal entities — firms are authorised based on the certified auditors they employ.
- Common models: fixed-scope project (4-12 months), monthly retainer, time and materials, hybrid platform + consulting.
What a NIS2 consultant does
A NIS2 consultant translates legal requirements (OUG 155/2024, EU Directive 2022/2555, DNSC guidelines) into concrete actions adapted to the organisation. The activity covers four areas:
1. Diagnostic (Gap Analysis)
Structured evaluation across the 17 Art. 21 pillars: questionnaire, interviews with process owners, review of existing documentation, direct system observation. Outcome: gap report with maturity score per domain, gap prioritisation by risk and effort, budget and schedule estimate.
2. Planning
Risk treatment plan, staged implementation calendar, budget allocation per category (consulting, software, hardware, training, audit), role definition (CISO, process owners, IR team), formal approval by the management body.
3. Assisted implementation
Drafting policies and procedures, support in choosing technical solutions (SIEM, EDR, MFA, backup), drafting SCRM contractual clauses, leading risk meetings, delivering specialised training, support with DNSC registration.
4. Audit preparation
Internal mock audit, incident simulations (table-top exercises, red team), evidence review, preparing the team for auditor questions, final remediation plans.
When you need NIS2 consulting
Consulting is not legally mandatory but becomes practically necessary when the organisation finds itself in one or more situations:
- Lack of dedicated internal resources — no CISO, IT team overloaded with operations, no specialist with detailed NIS2 knowledge.
- Sector with specific requirements — energy (NIS2 + ANRE rules + ENTSO-E), healthcare (NIS2 + strict GDPR + medical devices), financial (NIS2 + DORA), public administration (NIS2 + ANS rules).
- Critical OT/SCADA infrastructure — industrial systems with IEC 62443 requirements, strict IT/OT isolation, limited maintenance windows.
- Complex supply chain — dozens or hundreds of critical suppliers (cloud, MSP, telecom) requiring formal evaluation and dedicated contractual clauses.
- Short deadline — announced DNSC inspection, scheduled audit, security event that exposed gaps.
- Low initial cyber maturity — no formal policies, no SIEM, no widespread MFA, no incident response procedures.
The multidisciplinary project team
NIS2 implementation is not a single discipline — it combines legal, organisational, technical and operational. A serious project allocates a team of 4-7 specialists with differentiated roles:
| Role | Contribution |
|---|---|
| Lead consultant / Project manager | Coordination, communication with the client, progress reporting |
| NIS2 auditor | Interpreting legal requirements, mock audit, formal reviews |
| ISO/IEC 27001 Lead Auditor / Lead Implementer | ISMS framework, policy drafting, ISO ↔ NIS2 mapping |
| GRC specialist | Risk register, impact analysis, management reporting |
| Cybersecurity engineer | Technical configurations (SIEM, EDR, MFA, network segmentation) |
Note: a single person cannot credibly cover all these roles. The question "who will actually work on my project?" matters more than the firm's name.
Consultants' relationship with DNSC
DNSC accredits both individuals and legal entities. Individual auditors are nominally certified after training programs and exams. Firms are authorised as NIS2 audit/consulting service providers based on the certified auditors they employ and meeting organisational criteria.
What you can verify with DNSC:
- Certified individual auditors — public lists of natural persons with valid certification.
- Authorised firms — register of authorised NIS2 audit service providers.
- ICT supplier compliance — for certain critical ICT services there are notification/approval procedures.
In practice, the value of a firm comes from: (a) the number and quality of individually DNSC-certified auditors on the team, (b) complementary certifications (ISO 27001 LA, CISA, CISM), (c) concrete experience in your sector, (d) verifiable references.
Common engagement models
Fixed scope project
The most frequent form for initial implementation. Clear scope (e.g. "achieving NIS2 compliance in 9 months"), defined deliverables (Gap Analysis, plan, documentation set, mock audit), fixed price or range. Advantage: budget predictability. Disadvantage: rigid to scope changes.
Monthly retainer
Band of consumable hours per month (10-40h), with preferred rates, for compliance maintenance, incident support, periodic reviews. Useful after initial implementation, for the annual maintenance cycle.
Time and materials
Fixed hourly rate, billing based on actual consumption. Useful for targeted missions: drafting one policy, 2-week pre-audit support, expertise on a specific sector.
Hybrid model: platform + consulting
The client uses a self-service platform (CysNis or equivalent) for standardisable elements — documentation, tracking, reporting — and uses consulting only for non-standardisable areas (sector interpretation, architectural decisions, final audit). Significantly reduces total cost. See dedicated section below.
Sectors served
The 18 NIS2 sectors have different practical requirements. Ask the consultant what concrete experience they have in your sector:
How to choose the right NIS2 consultant
A practical evaluation grid:
- Request 2-3 references from your sector — from the last 18 months, directly contactable.
- Check a documentation sample — an example of a recently delivered policy or procedure. Drafting quality says everything.
- Ask about the framework used — a consultant who doesn't mention CyFun® 2025, ISO 27001, NIST CSF in the first interview is not prepared.
- Request a communication plan — meeting frequency, progress reporting, escalation.
- Check the knowledge transfer model — total dependence on the consultant at project end is a major risk.
- Beware of "guaranteed positive audit" — no serious consultant guarantees an audit outcome; they can guarantee the process.
Pitfalls to avoid
- "Cheap fixed packages" under 5,000 EUR for full implementation — real implementation requires tens to hundreds of hours. These packages deliver generic templates, not compliance.
- Firms invoking "DNSC accreditation" without proof — DNSC accredits both individuals and legal entities; ask for the firm's authorisation number and the nominal list of certified auditors.
- Consultant without a team — a single person, however talented, cannot cover technical + organisational + sector aspects.
- Lack of documented methodology — ask them to show their work process. Lack of methodology = improvisation.
- Documents fully generated by AI without human review — auditors and DNSC recognise them immediately. Low quality.
- Refusal to transfer knowledge — deliberate lock-in. Look for partners who want to make you autonomous.
- "NIS2 certification" promises — NIS2 has no formal official certification (unlike ISO 27001). "Conformity attestation" through audit is correct, "NIS2 certification" is not.
Hybrid model: platform + consulting
For small and medium organisations, the most efficient cost-result ratio is combining a self-service platform with targeted consulting:
| Covered by platform | Covered by consulting |
|---|---|
| Automatic classification check | Architectural decisions (segmentation, zoning) |
| Guided Gap Analysis (questionnaire + PDF report) | Sector-specific interpretations |
| Documentation template library (100+ documents) | SCRM clause adaptation to specific suppliers |
| Compliance tracking across the 17 pillars | Final mock audit and DNSC preparation |
| Risk register with 5x5 matrix | Risk workshops with management |
| DNSC incident notification generator | Real support during an incident |
| 60/150 day deadline tracking | DNSC communication strategies |
This combination typically reduces total cost by 40-60% compared to pure consulting, while preserving deliverable quality.
See the platform and request an evaluation
Free account, no card required. Access to automatic classification, internal evaluation and the NIS2 template catalog.
Create free account View consulting serviceFrequently asked questions about NIS2 consulting
What is NIS2 consulting?
Are there DNSC accredited firms for NIS2?
Can I implement NIS2 myself without a consultant?
How many consultants should a serious firm have?
What deliverables do I get from a NIS2 consulting project?
How can I make sure I don't remain dependent on the consultant?
Will the consultant also do my final audit?
How does the first interview with a NIS2 consultant work?
Can I change the NIS2 consultant during the project?
What questions reveal whether a NIS2 consultant is good?
Glossary
- NIS2
- Directive (EU) 2022/2555, transposed in Romania through OUG 155/2024.
- DNSC
- National Cyber Security Directorate, the competent authority for NIS2 in Romania.
- DNSC certified NIS2 auditor
- Natural person individually certified by DNSC for NIS2 compliance audit.
- ISO 27001 Lead Auditor
- Individual certification for auditing Information Security Management Systems (ISMS).
- CISA
- Certified Information Systems Auditor — ISACA certification for IT audit.
- CISSP
- Certified Information Systems Security Professional — (ISC)² cybersecurity certification.
- CRISC
- Certified in Risk and Information Systems Control — ISACA IT risk certification.
- CyFun® 2025
- Best practices framework from the Centre for Cybersecurity Belgium.
- SCRM
- Supply Chain Risk Management.
- GRC
- Governance, Risk and Compliance — integrated discipline.
- Mock audit
- Simulated audit before the real one, for gap identification.
- Retainer
- Contract with a band of monthly consumable hours at preferential rate.
