OUG 155/2024 requires essential and important entities to undergo a cybersecurity audit. Only an auditor holding a valid DNSC certificate may perform it, independent of your security providers. After the report, the deadlines are short: 5 days for the results and 15 working days for the remediation plan.

Two types of audit

Periodic audit
Carried out regularly, under the conditions and at the frequency set by the DNSC order on risk-management measures, according to the entity’s risk level. Where a sector authority exists, the conditions are set by joint order.
Ad-hoc audit
Exceptional, requested by DNSC, which tells the entity the reasons and objectives. It can be ordered after a significant incident, after a change with a significant impact on networks and systems but no later than 180 days after it, or when there are serious indications that an essential entity is breaking the law.

A change with a significant impact means a new network or system involved in delivering the service, a new technology, a change in how the service is operated, or a move from important to essential entity.

DNSC may also ask at any time for the results of audits by a certified auditor and the evidence behind them.

Who can perform the audit

Only cybersecurity auditors holding a valid certificate issued by DNSC. The certificate is valid for 3 years. DNSC keeps a record of auditors and publishes the list of validly certified ones, separately for legal entities and individuals, on its cybersecurity auditors page (in Romanian).

The audit follows the applicable European and international standards and specifications, whose list DNSC approves. Institutions with responsibilities in defence, public order and national security are exempt.

Who may not audit you

The law puts the auditor’s independence first. The following may not perform the audit:

The auditor may have no financial, personal or professional conflict of interest and must protect the confidentiality of the information obtained during the audit.

In practice, the provider that runs your SOC or your PenTest cannot also be your auditor. That is why TRU does not perform audits. Audits are performed by DNSC-certified auditors who are TRU partners, and you sign the contract directly with them.

What the audit checks

The audit is a systematic assessment of all policies, procedures and protection measures implemented in networks and information systems. Its purpose is to identify malfunctions and vulnerabilities and to recommend remediation measures.

In practice, the auditor works against the controls of your assurance level in DNSC Order No. 1/2026: 34, 133 or 218, depending on your risk level. At the important and essential levels, the status of the management controls is checked at every audit.

How to choose the auditor

The audited entity has the right to choose its auditor. Before signing, check:

The certificate
The auditor appears on the DNSC list of validly certified auditors, and the certificate remains valid for the whole audit.
Independence
They do not provide you with security services, had no contract for the audited system in the last year and have not already carried out 3 consecutive audits at your organisation.
Experience
They have audited organisations in your sector and know the controls of your assurance level.
Scope and schedule
Which systems are in scope, how many days it takes, when you receive the report and how it fits your deadlines.
The report
Clear recommendations that you can turn into the remediation plan within 15 working days.
Confidentiality
How the documents and evidence you provide are protected.

How to prepare

The self-assessment steps are in our guide to the NIS2 self-assessment (in Romanian).

After the audit

How often

OUG 155/2024 does not set a single frequency. The conditions and frequency of the periodic audit are set by the DNSC order on risk-management measures, according to the entity’s risk level. Check the frequency that applies to your level with the auditor before you plan the budget.

How TRU helps

Audits are performed by DNSC-certified auditors who are TRU partners, under a contract signed directly with the auditor. The partner auditor also supports you in dealing with DNSC on the audit.

Before the audit, through CIO-as-a-Service, we prepare the documents and evidence. After the audit, we help with the remediation plan and the measures: PenTest, 24/7/365 SOC and Proton Workspace. The details are on the NIS2 audit and compliance page.

For the encryption NIS2 requires, Proton Workspace natively protects data in transit and at rest, with zero-access encryption. The details are in our guide to NIS2 encryption with Proton Workspace.

Sources

OUG 155/2024, consolidated version, art. 11, 46, 57 and 58 · DNSC: cybersecurity auditors · DNSC Order No. 1/2026 (all in Romanian).