Join our Newsletter — 33% off our NHI Course

Who is responsible for submitting and publishing the final audit reports under the DSA?

The audited provider bears the reporting responsibility. After receiving the final audit report from the external auditor, the provider must submit it to the European Commission and the relevant Digital Services Coordinator within one month. The provider must also publish an audit implementation report within three months, making accountability part of the compliance lifecycle.

Who carries the DSA reporting duty?

The reporting duty sits with the audited provider, because the provider is the regulated entity that must turn the external auditor’s findings into formal submissions and public disclosure. That makes the provider accountable for moving the report from assurance output to regulatory filing, rather than leaving the obligation with the auditor who prepared it.

The distinction matters operationally: the auditor produces the independent assessment, but the provider owns the compliance lifecycle. Under the DSA, that means the provider must receive the final audit report, submit it to the European Commission and the relevant Digital Services Coordinator, and then publish the audit implementation report on the required timeline.

For practitioners, this is a governance control as much as a filing requirement. The accountable team needs a clear handoff from audit completion to submission, publication, and evidence retention, because missed deadlines or unclear ownership can turn a completed audit into a compliance failure.

What the provider must do after the audit closes

Once the external auditor issues the final report, the provider is responsible for the next steps in sequence: internal review, formal submission, and publication of implementation status. The provider should treat the final report as the trigger for a tightly controlled workflow, not as a document that can simply be archived after receipt.

That workflow usually needs named owners for legal, compliance, security, and public reporting, because the submission and publication obligations are different actions with different audiences. The first goes to regulators, while the second creates a public or externally visible accountability record of how the provider is addressing the findings.

If the audit identifies material gaps, the implementation report should reflect real remediation progress rather than generic assurances. The DSA reporting model is designed to show that identified issues are being tracked to closure, so the provider’s evidence should support status, timing, and accountable ownership.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA and NIS2 define the regulatory obligations.

Framework Control / Reference Relevance
DORA Art. 13 — Operational resilience testing and reporting DSA audit follow-through is a regulated reporting obligation with clear accountability.
Recommendation — Assign a named owner to submit audit outputs and retain evidence of timely reporting.
NIS2 Art. 20 — Management accountability The answer turns on provider accountability for compliance actions after assurance results.
Recommendation — Make senior management responsible for filing and publishing compliance follow-up on time.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Provider-led submission and publication require governed compliance ownership and tracking.
Recommendation — Define a governance process that tracks audit findings through submission, publication, and closure.
CIS Controls v8 5.3 — Documentation of Controlled Assets and Compliance Processes The provider must document and evidence the reporting workflow and deadlines.
Recommendation — Document the audit-report workflow and retain proof of submission and publication.

Practitioner Guidance

What to verify: Confirm that one function owns the end-to-end DSA audit workflow, including receipt of the final report, submission to the European Commission, submission to the relevant Digital Services Coordinator, and publication of the implementation report. If those steps sit in different teams, the handoff points should be documented and time-bound.

Decision rule: If the audit report has been received, the provider should immediately move into filing and publication tracking, with deadline monitoring anchored to the report receipt date. If ownership is unclear, treat that as a compliance risk before the reporting window starts to close.

Practitioner takeaway: The key control is not who authored the audit, but whether the provider can prove it owned the regulatory follow-through, on time and with traceable accountability.