Completing a Romanian cybersecurity-auditor course does not automatically grant the legal right to perform regulated cybersecurity audits. The training provider issues a specialisation certificate after the course and examination; DNSC auditor attestation is a separate regulatory status with its own applicable requirements.
This difference is more important than the certificate’s visual design. A candidate should verify the issuer, exact programme name, authorisation basis, examination result, and the next attestation step before paying for the course or presenting the qualification to an employer.
What APSAP Currently States
The provider’s current Auditor de Securitate Cibernetică course page describes an online programme authorised by the National Cyber Security Directorate (DNSC). It states that participants who pass the examination obtain a certificate of specialisation for the Cybersecurity Auditor training programme, issued under the applicable DNSC regulations.
The same page makes two limitations explicit:
- the cybersecurity course is authorised by DNSC, not accredited through the ordinary ANC course framework;
- the specialisation certificate can be used in the procedure for auditor attestation, but does not itself make the graduate a DNSC-attested auditor.
APSAP also states that the right to perform cybersecurity audits belongs to auditors holding a valid attestation issued by DNSC. Therefore, “course authorised by DNSC,” “certificate issued after passing,” and “auditor attested by DNSC” are related but not interchangeable claims.
What the Certificate Should Establish
The provider does not publish a complete, high-resolution sample showing every field and security feature on the current certificate. Without that evidence, it would be irresponsible to invent its layout, colour, seals, signatures, registration numbering, or reverse-side content.
A genuine final document should be checked for the information that makes it verifiable:
- graduate’s identity as it appears in official records;
- exact programme title;
- issuing organisation;
- legal or regulatory basis stated by the issuer;
- examination or completion date;
- series, number, registration, or verification mechanism where applicable;
- signatures and issuer validation elements;
- any annex describing competencies or training duration.
Ask APSAP for a redacted specimen from the current authorisation series. A specimen from another course, an old ANC template, or a marketing “diploma” graphic is not reliable evidence of what this programme now issues.
Entry and Examination Documents
As checked on August 8, 2026, APSAP lists a bachelor’s diploma or valid temporary graduation certificate as the required study evidence. For examination participation, it lists copies of the degree evidence, identity document, birth certificate, marriage certificate when a name changed, and proof of payment.
The page describes five live Zoom sessions, an e-learning period, theory and practice resources, quizzes, and an examination date for each cohort. Dates, price, duration, and document requirements are commercial and administrative details that can change. Preserve the offer and written confirmation applicable to the actual cohort.
Before enrolling, ask in writing:
- What is the provider’s current DNSC authorisation identifier and validity period?
- What exact certificate title is printed after a passing result?
- Who signs and registers the certificate?
- Is an appendix of competencies or hours supplied?
- What examination format, passing threshold, retake policy, and identity checks apply?
- Which current DNSC attestation requirements does the certificate satisfy?
- Are additional experience, education, independence, insurance, or documentation requirements necessary for attestation?
Certificate, Attestation, and Audit Engagement
These three stages prove different things:
| Stage | What it demonstrates |
|---|---|
| Course certificate | The holder completed the named training and passed its assessment under the stated programme rules |
| DNSC attestation | The competent authority recognised the person under the applicable auditor-attestation procedure and validity conditions |
| Audit engagement | A specific entity appointed an eligible, independent auditor for a defined scope under a contract or legal process |
An attested auditor can still have a conflict of interest or lack the specialist competence for a particular industrial, cloud, or operational-technology environment. An organisation selecting an auditor should verify both formal status and relevant experience.
How Employers Should Verify It
Do not accept a screenshot alone. Inspect the original or a verifiable electronic document, match identity and programme title, contact the issuer through independently obtained details, and check the person’s current DNSC status through the authority’s applicable mechanism. Record the verification date because attestations and regulatory conditions can change.
For international use, APSAP states that Romanian certificates may be apostilled or legalised depending on the destination state. That process authenticates document origin; it does not force a foreign regulator or employer to treat the qualification as an equivalent professional licence.
What the Course Should Prepare a Candidate to Do
A useful programme should go beyond legislation summaries. A graduate should be able to define audit scope and criteria, preserve independence, plan evidence collection, sample controls, interview personnel, evaluate technical and organisational measures, distinguish findings from observations, rate risk consistently, maintain working papers, and produce defensible remediation recommendations.
The document received at graduation matters, but professional credibility comes from a traceable chain: authorised training, successful assessment, valid DNSC attestation where required, appropriate competence, independence, and evidence-based audit work. Verify every link rather than relying on the word “accredited” in advertising.