OUG 155/2024 requires essential and important entities to undergo a cybersecurity audit. Only an auditor holding a valid DNSC certificate may perform it, independent of your security providers. After the report, the deadlines are short: 5 days for the results and 15 working days for the remediation plan.
Two types of audit
- Periodic audit
- Carried out regularly, under the conditions and at the frequency set by the DNSC order on risk-management measures, according to the entity’s risk level. Where a sector authority exists, the conditions are set by joint order.
- Ad-hoc audit
- Exceptional, requested by DNSC, which tells the entity the reasons and objectives. It can be ordered after a significant incident, after a change with a significant impact on networks and systems but no later than 180 days after it, or when there are serious indications that an essential entity is breaking the law.
A change with a significant impact means a new network or system involved in delivering the service, a new technology, a change in how the service is operated, or a move from important to essential entity.
DNSC may also ask at any time for the results of audits by a certified auditor and the evidence behind them.
Who can perform the audit
Only cybersecurity auditors holding a valid certificate issued by DNSC. The certificate is valid for 3 years. DNSC keeps a record of auditors and publishes the list of validly certified ones, separately for legal entities and individuals, on its cybersecurity auditors page (in Romanian).
The audit follows the applicable European and international standards and specifications, whose list DNSC approves. Institutions with responsibilities in defence, public order and national security are exempt.
Who may not audit you
The law puts the auditor’s independence first. The following may not perform the audit:
- certified auditors who currently provide cybersecurity or CSIRT services to the entity, or who are its employees;
- an auditor with a service contract for the audited network or system that is ongoing or ended less than a year ago;
- an auditor who has already carried out 3 consecutive audits at the same entity.
The auditor may have no financial, personal or professional conflict of interest and must protect the confidentiality of the information obtained during the audit.
In practice, the provider that runs your SOC or your PenTest cannot also be your auditor. That is why TRU does not perform audits. Audits are performed by DNSC-certified auditors who are TRU partners, and you sign the contract directly with them.
What the audit checks
The audit is a systematic assessment of all policies, procedures and protection measures implemented in networks and information systems. Its purpose is to identify malfunctions and vulnerabilities and to recommend remediation measures.
In practice, the auditor works against the controls of your assurance level in DNSC Order No. 1/2026: 34, 133 or 218, depending on your risk level. At the important and essential levels, the status of the management controls is checked at every audit.
How to choose the auditor
The audited entity has the right to choose its auditor. Before signing, check:
- The certificate
- The auditor appears on the DNSC list of validly certified auditors, and the certificate remains valid for the whole audit.
- Independence
- They do not provide you with security services, had no contract for the audited system in the last year and have not already carried out 3 consecutive audits at your organisation.
- Experience
- They have audited organisations in your sector and know the controls of your assurance level.
- Scope and schedule
- Which systems are in scope, how many days it takes, when you receive the report and how it fits your deadlines.
- The report
- Clear recommendations that you can turn into the remediation plan within 15 working days.
- Confidentiality
- How the documents and evidence you provide are protected.
How to prepare
- the risk-level assessment and the self-assessment, completed and endorsed by management;
- formally approved policies and procedures, with documented exceptions;
- evidence of implementation: logs, testing reports, SOC reports, training records, configurations;
- the list of relevant assets and the list of identified risks, which DNSC may request at any time;
- one person who coordinates the audit and answers the auditor’s questions.
The self-assessment steps are in our guide to the NIS2 self-assessment (in Romanian).
After the audit
| Step | Deadline | Legal basis |
|---|---|---|
| Audit results sent to DNSC and, where applicable, the sector authority | within 5 days of the audit ending | OUG, art. 46(8) |
| Action plan to remedy all deficiencies, with deadlines | within 15 working days of receiving the report | OUG, art. 57(8) |
| Implementing the plan | within the committed deadlines, justified for each measure | OUG, art. 57(9) and (11) |
| Notifying DNSC of implementation, with evidence | within 5 days of the committed deadline | OUG, art. 57(10) |
How often
OUG 155/2024 does not set a single frequency. The conditions and frequency of the periodic audit are set by the DNSC order on risk-management measures, according to the entity’s risk level. Check the frequency that applies to your level with the auditor before you plan the budget.
How TRU helps
Audits are performed by DNSC-certified auditors who are TRU partners, under a contract signed directly with the auditor. The partner auditor also supports you in dealing with DNSC on the audit.
Before the audit, through CIO-as-a-Service, we prepare the documents and evidence. After the audit, we help with the remediation plan and the measures: PenTest, 24/7/365 SOC and Proton Workspace. The details are on the NIS2 audit and compliance page.
For the encryption NIS2 requires, Proton Workspace natively protects data in transit and at rest, with zero-access encryption. The details are in our guide to NIS2 encryption with Proton Workspace.
Sources
OUG 155/2024, consolidated version, art. 11, 46, 57 and 58 · DNSC: cybersecurity auditors · DNSC Order No. 1/2026 (all in Romanian).