🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
NIS2 Directive

Does NIS2 Require Penetration Testing? What Article 21 Actually Says

Quick Answer

No — NIS2 never uses the words "penetration testing". Article 21(2)(f) requires in-scope entities to have policies and procedures to assess the effectiveness of their cybersecurity risk-management measures. A penetration test is the most common practical way to document that assessment, not a named legal requirement. NIS2 is also a Directive, not a Regulation — it takes effect through each EU member state's own implementing law, so specifics vary by jurisdiction.

The Short Answer

Directive (EU) 2022/2555 sets out ten minimum risk-management measures in Article 21. None of them is named "penetration testing." What Article 21(2)(f) actually requires is policies and procedures to assess the effectiveness of cybersecurity risk-management measures. A penetration test is one practical, widely used way to produce that assessment — auditors and regulators generally accept it as strong evidence, but the Directive itself doesn't mandate that specific method or any fixed testing frequency.

This distinction matters because most pages on this topic blur it. Saying "NIS2 requires a pentest" is inaccurate and easy to disprove by reading the text. Saying "NIS2 requires you to be able to demonstrate your security measures work, and a pentest is how most in-scope entities do that" is accurate — and it's the answer that holds up under scrutiny from a compliance officer or a language model checking sources.

The Ten Measures in Article 21

Two of the ten touch on testing directly; the rest cover other operational and organisational controls.

MeasureTesting-related?
Risk analysis and information system security policies
Incident handling
Business continuity, backup management, disaster recovery, crisis management
Supply chain security
Security in acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure Yes
Policies and procedures to assess the effectiveness of cybersecurity risk-management measures (Art. 21(2)(f)) Yes
Basic cyber hygiene practices and cybersecurity training
Policies and procedures regarding the use of cryptography and encryption
Human resources security, access control policies and asset management
Use of multi-factor authentication or continuous authentication solutions

Article 21(2)(f): The Clause That Matters

Article 21(2)(f) requires "policies and procedures to assess the effectiveness of cybersecurity risk-management measures." Read plainly, this is an outcome requirement, not a method requirement: you must be able to show your controls actually work, but the Directive leaves the how to you. A penetration test — performed by an independent tester, scoped in writing, with findings tracked to remediation — is the most defensible, auditable way most organisations satisfy this in practice. Self-assessment questionnaires and automated scans alone are weaker evidence because they lack independent verification.

Am I in Scope? Essential vs Important Entities

CategoryExample sectorsMaximum fine
Essential entitiesEnergy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management (B2B), public administration, spaceUp to €10,000,000 or 2% of worldwide annual turnover, whichever is higher
Important entitiesPostal and courier services, waste management, chemicals, food, manufacturing, digital providers (incl. cloud and search engines), researchUp to €7,000,000 or 1.4% of worldwide annual turnover, whichever is higher

NIS2 Is a Directive, Not a Regulation

Country-specific status current as of: 2 August 2026

Unlike GDPR (a Regulation, directly applicable in every member state), NIS2 is a Directive: it sets the outcome, and each EU member state transposes it into its own national law. The formal transposition deadline was 17 October 2024, but transposition and active enforcement have proceeded at different speeds across member states since then. If you operate in multiple EU jurisdictions, the practical question isn't "does NIS2 apply to us" — it's "which national law, with which specific requirements and enforcement posture, applies in each country we operate in." We do not publish a full country-by-country status table here, because it changes and stale country claims are worse than no claim — check your relevant member state's official transposing legislation or its national NIS2 competent authority directly for current status.

What Evidence Auditors Actually Ask For

A written, agreed scope document defining what was tested and what was explicitly out of scope
Signed Rules of Engagement authorising the test
A named, independent tester or firm — not solely an internal team
Findings with a severity classification (CVSS v3.1 or equivalent)
A named remediation owner for each finding
Evidence of retesting after remediation
A summary suitable for presentation to management / the board

If you don't have this evidence yet, the fastest way to start building it is a fixed-price test with a signed Attestation Letter.

NIS2 vs DORA vs CRA vs ISO 27001

FrameworkApplies toTesting obligationDo we offer it?
NIS2Essential and important entities across 18 EU sectorsNo named testing requirement — Art. 21(2)(f) requires effectiveness-assessment policies; testing is a practical means, not a mandateYes — Vulnerability Assessment through Enterprise SaaS Pentest
DORAEU financial entities (banks, insurers, investment firms, etc.)Explicit: digital operational resilience testing for all in-scope entities; Threat-Led Penetration Testing (TLPT), TIBER-EU aligned, for entities designated 'significant'Standard testing: yes. TLPT: no — we do not perform DORA Art. 26-27 TLPT engagements
CRAManufacturers of products with digital elements placed on the EU marketNo named testing requirement — Art. 21 effectiveness-assessment obligation (see our CRA readiness page); reporting obligations for exploited vulnerabilities from 11 Sept 2026Yes — via our CRA Readiness Assessment and pentest tiers
ISO/IEC 27001Any organisation seeking certificationAnnex A.8.29 — security testing in development and acceptance; not a fixed frequencyYes — pentest reports are structured to satisfy A.8.29 evidence expectations

See our Cyber Resilience Act Readiness page for the CRA-specific breakdown, and ISO 27001 services for certification support.

Penalties Under Article 34

Entity typeMaximum fine
Essential entities€10,000,000 or 2% of total worldwide annual turnover, whichever is higher
Important entities€7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher

Frequently Asked Questions

Does NIS2 require penetration testing?+
Not literally. The Directive never uses the words "penetration testing". Article 21(2)(f) requires in-scope entities to have policies and procedures to assess the effectiveness of their cybersecurity risk-management measures. A penetration test is the most common practical way to document that assessment — but it is a means of compliance, not a named legal obligation.
How often should we test under NIS2?+
There is no universal mandatory testing frequency set out in the Directive. Common practice among in-scope entities is annual testing plus retesting after significant changes to the system — but that is industry practice, not a Directive requirement. Your national implementing law or sector regulator may set a more specific expectation; check locally.
We're already ISO 27001 certified — is that enough for NIS2?+
ISO 27001 certification demonstrates a mature ISMS and typically covers much of the same ground as Article 21's ten measures, but NIS2 compliance and ISO 27001 certification are legally distinct. Certification is strong supporting evidence for your Article 21(2)(f) effectiveness assessment, but it does not automatically constitute NIS2 compliance on its own.
Is my company an essential or an important entity?+
It depends on your sector and size, set out in NIS2 Annexes I and II. Essential-entity sectors include energy, transport, banking, health, and digital infrastructure; important-entity sectors include postal services, manufacturing, chemicals, and digital providers such as cloud and search services. Size thresholds also apply (generally medium and large enterprises, with some sector-specific exceptions regardless of size).
What are the fines?+
Up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and up to €7 million or 1.4% of total worldwide annual turnover (whichever is higher) for important entities, under Article 34.
What's the difference between NIS2 and DORA testing?+
NIS2 sets no named testing method and no fixed frequency. DORA is explicit: all in-scope financial entities must perform digital operational resilience testing, and entities designated "significant" must additionally undergo Threat-Led Penetration Testing (TLPT), a TIBER-EU-aligned, intelligence-led red-team exercise performed by accredited testers with results reported to the regulator. It is a materially different, heavier engagement than a standard pentest.
Do you perform TLPT?+
No. We do not perform DORA Article 26–27 Threat-Led Penetration Testing engagements. If your organisation has been notified by its regulator of a TLPT obligation, you need a TIBER-EU-accredited testing provider — we can help with the standard testing components DORA also requires, but not the TLPT engagement itself.
Which national law applies to us?+
NIS2 is a Directive, not a Regulation — it takes legal effect through each EU member state's own implementing legislation, and transposition and enforcement timelines have diverged since the 17 October 2024 transposition deadline. Check your specific member state's implementing law for the exact obligations and timeline that apply to you; we keep general EU-level facts current but do not track every national variant in real time.

Document Your Article 21(2)(f) Effectiveness Assessment

€539 · 5 business days · Signed Attestation Letter