The NIS auditor in Romania: who may audit, the DNSC attestation and the public list

The NIS auditor, DNSC attestation and the public list

The cyber security audit is the one obligation in GEO no. 155/2024 that an entity cannot discharge on its own. The text requires an auditor holding a valid attestation issued by DNSC, and the list of attested auditors is public. A market has formed around that list, with offers that blur the line between the national attestation and commercial certifications. Below, what the law says and what to verify before signing.

The audit obligation

„Essential entities and important entities are required to undergo a cyber security audit under the conditions and with the periodicity established by the order of the DNSC director provided for in art. 12 para. (1), depending on the risk level referred to in para. (3).”

That is art. 11 para. (5). Para. (6) adds that where a sectoral competent authority exists, the conditions and periodicity are set by joint order.

Here there is a real problem worth stating plainly: the periodicity has not yet been set. Order of the DNSC director no. 1/2026, which is the very order issued under art. 12 para. (1), contains no provision on audit, periodicity or attestation. Neither the Measures in Annex no. 1 nor the self-assessment Methodology in Annex no. 2.

The useful conclusion: the audit obligation exists in the law, but the concrete interval has not been regulated through the order the law defers to. If a provider tells you „the audit is mandatory every year” or „every two years”, ask for the published legal basis. As at the date of this article, there is none.

Separately from the periodic audit, DNSC may order ad hoc audits as part of supervision, also carried out by an attested auditor.

Who may audit

Art. 58 para. (1): the audit is carried out by cyber security auditors holding a valid attestation issued by DNSC, except for audits at institutions in defence, public order and national security.

The attestation is personal, non transferable and valid for 3 years. This appears both in art. 58 para. (6) of the ordinance and in the Regulation approved by Order of the Secretariat General of the Government no. 559/2021, which remains applicable through art. 66 para. (2) of the ordinance even though it was issued under the now repealed Law no. 362/2018.

A new regulation, expressly required by art. 58 para. (2) letter b) and art. 65 para. (1) letter l), had not been published as at the date of this article. Until then, the attestation procedure remains the 2021 one.

The incompatibilities, the most ignored point

Art. 58 para. (3) prohibits the audit in three situations:

  • an attested auditor who currently provides cyber security services or CSIRT services to that entity, or is an employee of it;
  • an auditor holding a services contract for the audited network or system, ongoing or concluded within the last year;
  • an auditor who has already carried out 3 consecutive audits at the same entity.

The first eliminates a common practice: the firm that runs your security cannot audit your security. The second adds a one year cooling off period. The third forces rotation after three cycles.

If you receive a single offer covering both implementation and audit, ask who performs the audit and check whether that entity holds a current contract with you. An audit performed in breach of these rules is a contestable audit.

The list of auditors and how to check it

DNSC maintains the record of auditors under art. 58 para. (2) letter a) and publishes the list of validly attested cyber security auditors, known by its Romanian acronym LASC, on its own site, in dated versions. The list is already used as a qualification requirement in public procurement, where the bidder must appear in it.

What to ask a provider, in writing:

  1. the attestation number and issue date, so you can check the 3 year validity;
  2. the type of attestation and the audit types it covers;
  3. the version of the list in which they appear, with its date;
  4. a declaration on the incompatibilities in art. 58 para. (3), including contracts from the past year;
  5. the name of the individual who will sign the report, not only the company name.

What „accredited” really means

Under the 2021 Regulation, the attestation file requires, among other things, a valid criminal record certificate, evidence of experience, the auditor specialisation certificate issued by an authorised training provider, and professional certifications from an exhaustive list, Annex no. 5, which contains 37 certifications split between common and special audit activities.

One detail the market often gets wrong: ISO 27001 Lead Auditor does not appear in Annex no. 5. CISA does, under common audit activities. An ISO lead auditor certificate is professionally valuable, but it is not, by itself, a route to the DNSC attestation.

The experience requirement is alternative: at least 2 years administering or implementing networks and information systems, or 2 years in their security, or 1 year in investigations, testing or security audit. For an applicant, art. 27 of the ordinance allows DNSC to request security verifications, including from a national security perspective, and to interrupt the procedure depending on the outcome.

Auditors also carry ethical obligations under art. 58 para. (8): professional integrity, compliance with the applicable codes of ethics, absence of conflicts of interest, confidentiality.

What is penalised

Failure to undergo the audit under art. 11 para. (5) or (6) is the offence in art. 60 para. (1) letter b), which sits in the upper fine range: up to 7,000,000 euro or 1.4 per cent of total worldwide annual turnover for important entities, up to 10,000,000 euro or 2 per cent for essential ones, whichever is higher.

While the periodicity remains unset, arguing about „delay” is difficult. That does not mean the subject can be ignored: the risk level validated by DNSC and a possible ad hoc audit remain in play, and an audit done early is the cheapest way to find out what is missing.

Audit, self-assessment and gap analysis are three different things

Who performs itBasisOutput
Maturity self-assessmentthe entity, endorsed by managementart. 12 para. (4), Order no. 1/2026control scores, submitted annually to DNSC
Cyber security auditan auditor attested by DNSCart. 11 para. (5) and art. 58an independent audit report
Gap analysisany consultantcontractuala list of gaps and a remediation plan

Confusion between the first two is common. The self-assessment does not replace the audit, and the audit does not replace the annual self-assessment.

Where we can help

ProDefence is a cyber security auditor accredited by DNSC. If you want to know where you stand before a formal audit, the starting point is a NIS2 compliance analysis with a remediation plan, built on evidence. If you have nobody to appoint internally, the role can be covered through an outsourced NIS2 officer.

Mind the incompatibility rule: the same team cannot both run your security and audit the result. That separation is settled in the contract, not afterwards.

Sources

This material is informative and does not constitute legal advice. Quotations from the Romanian acts are working translations. The auditor list and the certification list are updated; check the version published on dnsc.ro at the time of contracting.

Frequently asked questions

Who may carry out the cyber security audit under GEO no. 155/2024?

Only cyber security auditors holding a valid attestation issued by DNSC, under art. 58 para. (1). Audits at institutions in defence, public order and national security are excepted. The attestation is personal, non transferable and valid for 3 years.

Where can I find the list of DNSC attested NIS auditors?

DNSC publishes the list of validly attested cyber security auditors, known as LASC, on its own site in dated versions. It is used as a qualification requirement in public procurement. Ask the provider for the attestation number, the issue date and the version of the list in which they appear.

How often must a NIS2 audit be performed in Romania?

Art. 11 para. (5) defers the periodicity to the order of the DNSC director under art. 12 para. (1). Order no. 1/2026, issued on that basis, contains no provisions on audit or periodicity. As at the date of this article the interval is not regulated, so a claim of „annually” or „every two years” has no published basis.

Can the company that manages our security also audit it?

No. Art. 58 para. (3) prohibits an audit by anyone currently providing cyber security or CSIRT services to the entity, by anyone holding a services contract for the audited network that is ongoing or was concluded within the last year, and by an auditor who has already performed 3 consecutive audits at the same entity.

Is ISO 27001 Lead Auditor enough for the DNSC attestation?

No. Annex no. 5 to the 2021 Regulation lists 37 accepted professional certifications exhaustively, and ISO 27001 Lead Auditor is not among them. CISA is, under common audit activities. The ISO certificate remains professionally valuable but does not by itself open the route to attestation.

Does the maturity self-assessment replace the audit?

No. They are separate obligations. The annual self-assessment is performed by the entity and endorsed by management, under art. 12 para. (4) and Order no. 1/2026. The audit is performed independently by an attested auditor, under art. 11 para. (5) and art. 58.

Skip to content