NIS2 Third-Party Audit: Who Counts as a “Qualified Auditor” — and Why You Pay for the Regulator’s Audit
Two sentences in the NIS2 Directive decide most of what a third-party audit will cost you, and neither one is where people look for them. The first sits at the end of Article 32(2): “The costs of such targeted security audit carried out by an independent body shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise.” The second is the phrase in Article 32(2)(g) that lets an authority demand “the results of security audits carried out by a qualified auditor” — a term the Directive uses and never defines.
So the supervisor can send an independent body into your organisation and hand you the invoice — using a qualification standard the Directive declines to write down.
What the Directive actually says about third-party audits
In plain terms: NIS2 gives competent authorities five distinct audit-shaped powers. Only two of them involve an external body doing the auditing, and they work very differently — one is the regulator’s instrument, the other is evidence you volunteer.
| Power | Essential entities | Important entities | Who performs it |
|---|---|---|---|
| Regular and targeted security audits | Art. 32(2)(b) | Targeted only — Art. 33(2)(b) | “an independent body or a competent authority” |
| Ad hoc audits (e.g. after a significant incident) | Art. 32(2)(c) | No equivalent limb | Competent authority |
| Security scans | Art. 32(2)(d) | Art. 33(2)(c) | Competent authority, “where necessary with the cooperation of the entity” |
| On-site inspections and off-site supervision | Art. 32(2)(a) | Art. 33(2)(a) — ex post only | “trained professionals” |
| Requests for audit results as evidence | Art. 32(2)(g) | Art. 33(2)(f) | “a qualified auditor” |
Here is what makes this hard to plan around. We scraped all 46 operative articles of Directive (EU) 2022/2555 and counted the terms. “Qualified auditor” appears exactly twice — Article 32(2)(g) and Article 33(2)(f). “Independent body” appears four times — once in each of Articles 32(2)(b) and 33(2)(b), and once in each of the matching cost sub-paragraphs. The word “accredited”, in any form, appears zero times. [1][2][3]
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The two terms that decide who is allowed to audit you are therefore doing a great deal of work with no definition behind them. Article 6, which defines everything from “incident” to “broad remote access”, touches neither. That is the Directive deferring to national law — and it is the first thing to understand before you go shopping for an assessor.
One correction worth making early, because it appears in a lot of vendor material: Article 32(4) is not the audit power. Paragraph 4 is the enforcement ladder — warnings, binding instructions, cease-and-desist orders, monitoring officers, fines. Its only audit item is Article 32(4)(f), the power to “order the entities concerned to implement the recommendations provided as a result of a security audit within a reasonable deadline.” [1] The power to commission the audit lives in paragraph 2.
Can you actually be made to take one? Essential vs important
In plain terms: if you are an essential entity, an audit can arrive with no trigger at all. If you are an important entity, something has to have prompted it first.
The asymmetry that most guides describe — Article 32 is ex ante, Article 33 is ex post — is real, but the interesting version of it lives inside the audit powers themselves. Article 32(2)(b) gives authorities “regular and targeted security audits” over essential entities. Article 33(2)(b) gives them “targeted security audits” over important entities. The word regular is missing, and so is any ad hoc limb equivalent to Article 32(2)(c). [1][2]
For an important entity, every route to a third-party audit runs through Article 33(1)’s trigger: the authority must have been “provided with evidence, indication or information” of alleged non-compliance. [2] An incident report, a complaint, a supplier’s disclosure, or a peer entity naming you in its own supply-chain review can all be that indication. For an essential entity, no trigger is required — a periodic audit cycle is written into the power itself.
| Question | Essential entity | Important entity |
|---|---|---|
| Can an audit happen with no trigger? | Yes — Art. 32(2)(b) includes “regular” audits | No — Art. 33(1) requires evidence, indication or information |
| Post-incident ad hoc audit? | Yes — Art. 32(2)(c) | Only via the Art. 33(1) trigger |
| Who can carry it out? | Independent body or competent authority | Independent body or competent authority |
| Who pays? | The audited entity (default) | The audited entity (default) |
| Practical planning stance | Assume a cycle; keep an assessor relationship warm | Assume a trigger; manage what generates indications |
Our guide to what essential and important entities should expect from a first audit goes deeper on the supervision split itself.
Who pays for the audit the regulator orders
The cost sub-paragraph is identical in both articles: “The costs of such targeted security audit carried out by an independent body shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise.” [1][2] Ireland’s National Cyber Security Centre reproduces it verbatim in its own NIS2 FAQ, which is a useful signal of how a competent authority expects entities to read it. [6]
Read the grammar, because the drafting does the work. The default is that you pay, and the exception requires the authority to make a decision and substantiate it. There is no fee schedule, no cap, and no cost-recovery mechanism anywhere in the Directive.
That reframes the proactive-versus-reactive question. It is not a choice between spending money and not spending money — it is a choice about who controls the scope of the spend:
| Audit you commission | Targeted audit under Art. 32(2)(b) / 33(2)(b) | |
|---|---|---|
| Who sets the scope | You, within your own risk assessment | The authority, or your risk assessment, or “other risk-related available information” |
| Who picks the assessor | You | The authority, from bodies it recognises |
| Timing | Your calendar | Theirs |
| Who sees the report | You, unless you choose to share | The competent authority, by operation of Art. 32(2) |
| Who pays | You | You |
The bottom row is the point. You pay either way; the only variable is how much of the engagement you shape. A voluntary audit also produces something Article 32(2)(g) makes directly useful — results you can hand over as evidence, on your own terms, before anyone asks.
Three different “independent” standards — and which one you’re being asked for
In plain terms: NIS2 and its implementing regulation contain three separate independence requirements. They are constantly conflated, and treating one as satisfying another is the most common structural mistake in this area.
| Standard | Source | Independence bar | Who initiates it |
|---|---|---|---|
| Independent review of information and network security | CIR 2024/2690 Annex, point 2.3.2 | Reviewer “shall not be in the line of authority of the personnel of the area under review”; where size prevents that, “alternative measures to guarantee the impartiality” | You — it is your own obligation |
| “Qualified auditor” | Art. 32(2)(g) / 33(2)(f) | Undefined in the Directive | You commission it; the authority may request the results |
| “Independent body” | Art. 32(2)(b) / 33(2)(b) | Undefined in the Directive; set by national law | The competent authority |
The first one is worth dwelling on, because it is the only independence bar in the whole stack that is written down as a binding rule. CIR 2024/2690 Annex point 2.3.2 requires entities to run independent reviews “carried out by individuals with appropriate audit competence”, and where those individuals are your own staff, they “shall not be in the line of authority of the personnel of the area under review. If the size of the relevant entities does not allow such separation of line of authority, the relevant entities shall put in place alternative measures to guarantee the impartiality of the reviews.” [5]
Note what that does not say: it does not require an external reviewer. ENISA’s technical implementation guidance lists “external third-party review service provider” as one of three alternative measures, alongside “review personnel rotation” and “set up a review committee with members from different departments” — and that guidance is expressly non-binding. [5] A small essential entity that rotates reviewers and documents a conflict-of-interest declaration is meeting point 2.3.2. It is not thereby producing an Article 32(2)(b) third-party audit, and it should not be sold one as though it were. Our guide to running a NIS2 internal audit covers that internal layer.
So what does “qualified” mean? The closest thing to an EU-level answer is a bullet in ENISA’s guidance on evidence of reviewer competence: “professional experience and academic qualifications, certifications such as certified information systems auditor, certified information systems security professional, certified information security manager, etc.” [5] CISA, CISSP and CISM — named in guidance, listed as examples, binding on nobody. The accompanying competence list adds cybersecurity framework knowledge (ISO/IEC 27001, the NIST framework), industry knowledge, risk assessment skills, and regulatory knowledge covering NIS2, the GDPR and DORA. [5] Treat it as the best available benchmark, not a legal test.
Where the credential actually comes from: national accreditation
Because the Directive never says “accredited”, the answer to “who is a recognised independent body?” is always a national one. In EU cybersecurity conformity assessment generally, the credential comes from the accreditation architecture of Regulation (EC) No 765/2008 — the EUCC scheme, for example, requires that certification bodies and evaluation facilities “must be accredited in line with Regulation (EC) No 765/2008”. [7] Each Member State has a single national accreditation body, and that body decides what a given assessor is competent to assess.
Belgium is the clearest worked example, because it is furthest along. The Belgian NIS2 Act of 26 April 2024 and the Royal Decree of 9 June 2024 entered into force on 18 October 2024, with the Centre for Cybersecurity Belgium as supervisor; essential entities must submit evidence of compliance — “such as CyberFundamentals certification or ISO 27001 certification” — by 18 April 2026. [8] Underneath that, the assessment market is built on two different ISO conformity-assessment standards: Belgian practitioner reporting describes CyberFundamentals BASIC and IMPORTANT as verifications performed under ISO/IEC 17029, and the ESSENTIAL level as a certification performed under ISO/IEC 17021-1, with bodies accredited by BELAC and separately authorised by the CCB. As of early 2026 only two such bodies were reported as accredited. [9]
That 17029-versus-17021-1 split is the practical heart of assessor selection, and it generalises beyond Belgium. A verification is a point-in-time check that your self-assessment is substantively correct. A certification assesses whether a management system is structurally capable of sustaining the outcome. [9] An assessor accredited for one is not thereby competent — or permitted — to deliver the other.
Seven questions to ask any prospective assessor. None of them require you to be technical:
- Which national accreditation body accredits you, and under which standard — ISO/IEC 17029, ISO/IEC 17021-1, or something else?
- Are you separately authorised by our competent authority for NIS2 work, or only accredited? In Belgium these are two different steps. [9]
- What is the exact scope on your accreditation certificate, and does it cover our sector and our assurance level?
- Have you performed an audit that a competent authority accepted as an Article 32(2)(b) or 33(2)(b) targeted audit, or is your experience limited to voluntary engagements?
- Which individual auditors will be on the engagement, and what are their qualifications against ENISA’s competence list? [5]
- What is your conflict-of-interest position if you have previously advised us on the same controls?
- Will your report be structured so it can be made available to the competent authority as required by Article 32(2)?
One thing worth knowing about the certification route: Article 24 lets Member States require the use of ICT products, services and processes certified under European cybersecurity certification schemes, but it is a permissive power, not a standing obligation. [4] Certification is also not neutral at enforcement time — Article 32(7)(g) makes “any adherence to approved codes of conduct or approved certification mechanisms” a factor authorities must take due account of when deciding enforcement measures. [1] If you are weighing routes, our comparison of NIS2 against ISO 27001 and the overview of self-certification options both sit alongside this decision.
Scoping a third-party audit — and the three things it is not
Article 32(2)’s second sub-paragraph is the most under-used sentence in this part of the Directive: targeted security audits “shall be based on risk assessments conducted by the competent authority or the audited entity, or on other risk-related available information.” [1][2]
Your own risk assessment is a named, permitted basis for scoping the audit you will be paying for. That is scope leverage — and it is only available to entities whose risk assessment is current, documented, and defensible when someone else reads it. Arrive with a stale risk register and you hand scope definition to “other risk-related available information”, which in practice means incident history, sector threat intelligence, and whatever the authority already holds about you. Keeping the risk assessment in order is not just an Article 21 obligation; it is how you keep a say in what gets examined.
Three things a third-party audit under Article 32(2)(b) is not, and conflating them wastes budget:
- It is not your independent review. CIR 2024/2690 Annex 2.3 is your own continuing obligation, can be performed internally, and is reported to your management bodies — not to the regulator. [5]
- It is not your effectiveness assessment. Article 21(2)(f) and the corresponding Annex requirements ask whether your measures are effectively implemented and maintained. That is a measurement duty you own.
- It is not a security scan. Article 32(2)(d) treats scans as a separate power with its own conditions — objective, non-discriminatory, fair and transparent criteria, and “where necessary with the cooperation of the entity concerned”. [1] A penetration test is not an audit and will not answer an audit request.
| Role | Owns in a third-party audit |
|---|---|
| CISO / IT security manager | Control evidence, system access for the assessor, technical remediation planning against findings |
| Compliance officer / legal | The engagement contract, scope negotiation against the risk assessment, the record of what was made available to the authority |
| Management body / board | Approving the corrective action plan, and the Article 32(6) personal exposure that sits behind it |
| SME owner without a security function | Deciding the assurance level, budgeting for a cost you cannot invoice back, and documenting impartiality measures where separation of duties is not possible [5] |
After the audit: results, recommendations, and what makes it worse
Article 32(2) is unambiguous that “the results of any targeted security audit shall be made available to the competent authority.” [1] There is no confidentiality carve-out and no negotiation over disclosure of the outcome. Plan the engagement on the assumption the regulator reads the report.
What follows is a deadline. Article 32(4)(f) — and its mirror at Article 33(4)(f) — lets the authority “order the entities concerned to implement the recommendations provided as a result of a security audit within a reasonable deadline.” [1][2] An audit finding is therefore not advice you can weigh commercially; it is a candidate obligation with a clock attached.
Two provisions decide how badly this goes. Article 32(7)(a)(iv) makes “the obstruction of audits or monitoring activities ordered by the competent authority following the finding of an infringement” a serious infringement in any event — one of only five things the Directive labels that way without further assessment. [1] And Article 32(7)(c) makes “any relevant previous infringements by the entity concerned” an aggravating factor, so a poorly handled first audit prices the second one. Our NIS2 penalties guide sets out where that ladder ends.
One procedural protection is worth knowing. Article 32(8) requires authorities to set out detailed reasoning, to notify entities of their preliminary findings before adopting enforcement measures, and to “allow a reasonable time for those entities to submit observations”, except where immediate action is needed. [1] Article 33(5) extends that to important entities. [2] That window is where a factual correction to an audit finding belongs — not after the measure lands. Our 90-day audit preparation plan covers the evidence side of getting there.
Frequently asked questions
Does NIS2 require me to have a third-party audit?
No. The Directive gives competent authorities the power to subject entities to audits carried out by an independent body; it does not impose a standing audit obligation on entities. Several Member States have gone further in their national transposition — Belgium requires essential entities to submit evidence of compliance by 18 April 2026 [8] — so the honest answer is always “check your national law”, not “NIS2 says no”.
Can our existing ISO 27001 certification satisfy an audit request?
It can help substantially. Article 32(2)(g) invites the results of audits by a qualified auditor as evidence, and Article 32(7)(g) makes adherence to approved certification mechanisms a factor in enforcement decisions. [1] But scope matters: an ISO 27001 certificate covers the Statement of Applicability you defined, which may be narrower than the systems in scope for NIS2. Do not assume the two boundaries coincide.
Who chooses the independent body — us or the regulator?
For a targeted audit under Article 32(2)(b) or 33(2)(b), the authority is exercising the power, so the choice sits with it, from whatever pool national law recognises. You choose when you commission your own audit under the Article 32(2)(g) evidence route.
Can our internal auditor act as the “independent body”?
No. CIR 2024/2690 Annex 2.3.2 permits internal staff to conduct your own independent reviews, subject to the line-of-authority rule. [5] An “independent body” under Article 32(2)(b) is external to the entity and recognised for that purpose under national law.
Are important entities really never audited proactively?
Correct as a matter of the Directive’s structure: Article 33(1) requires evidence, indication or information of alleged non-compliance before ex post supervisory measures. [2] But Member States may supervise more intensively in national law, and the threshold for an “indication” is low — treat it as lower probability, not immunity. Belgium’s healthcare sector illustrates how national capacity shapes what actually happens.
How long does a third-party assessment take?
There is no figure in the Directive. As a planning guideline, Belgian practitioner reporting describes three to six months from self-assessment to a completed verification. [9] Treat that as a market observation from one jurisdiction, not an EU norm.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures in relation to essential entities
- Directive (EU) 2022/2555, Article 33 — Supervisory and enforcement measures in relation to important entities
- Directive (EU) 2022/2555 — full list of operative articles (term counts in this guide are our own count across all 46 articles)
- Directive (EU) 2022/2555, Article 24 — Use of European cybersecurity certification schemes
- ENISA, Technical Implementation Guidance on cybersecurity risk-management measures, version 1.0 (June 2025) — reproduces the CIR 2024/2690 Annex verbatim; the guidance commentary is expressly non-binding
- National Cyber Security Centre (Ireland), NIS2 FAQ
- EUR-Lex, European common criteria-based cybersecurity certification scheme (EUCC) — legislative summary
- Eversheds Sutherland, EU NIS2 Directive — Belgium
- Cyberplan, NIS2 conformity assessment: deadline 18 April 2026 approaches (Belgian practitioner commentary)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
