Does NIS2 Require Penetration Testing? What Article 21 Actually Says
Quick Answer
No — NIS2 never uses the words "penetration testing". Article 21(2)(f) requires in-scope entities to have policies and procedures to assess the effectiveness of their cybersecurity risk-management measures. A penetration test is the most common practical way to document that assessment, not a named legal requirement. NIS2 is also a Directive, not a Regulation — it takes effect through each EU member state's own implementing law, so specifics vary by jurisdiction.
The Short Answer
Directive (EU) 2022/2555 sets out ten minimum risk-management measures in Article 21. None of them is named "penetration testing." What Article 21(2)(f) actually requires is policies and procedures to assess the effectiveness of cybersecurity risk-management measures. A penetration test is one practical, widely used way to produce that assessment — auditors and regulators generally accept it as strong evidence, but the Directive itself doesn't mandate that specific method or any fixed testing frequency.
This distinction matters because most pages on this topic blur it. Saying "NIS2 requires a pentest" is inaccurate and easy to disprove by reading the text. Saying "NIS2 requires you to be able to demonstrate your security measures work, and a pentest is how most in-scope entities do that" is accurate — and it's the answer that holds up under scrutiny from a compliance officer or a language model checking sources.
The Ten Measures in Article 21
Two of the ten touch on testing directly; the rest cover other operational and organisational controls.
| Measure | Testing-related? |
|---|---|
| Risk analysis and information system security policies | — |
| Incident handling | — |
| Business continuity, backup management, disaster recovery, crisis management | — |
| Supply chain security | — |
| Security in acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure | Yes |
| Policies and procedures to assess the effectiveness of cybersecurity risk-management measures (Art. 21(2)(f)) | Yes |
| Basic cyber hygiene practices and cybersecurity training | — |
| Policies and procedures regarding the use of cryptography and encryption | — |
| Human resources security, access control policies and asset management | — |
| Use of multi-factor authentication or continuous authentication solutions | — |
Article 21(2)(f): The Clause That Matters
Article 21(2)(f) requires "policies and procedures to assess the effectiveness of cybersecurity risk-management measures." Read plainly, this is an outcome requirement, not a method requirement: you must be able to show your controls actually work, but the Directive leaves the how to you. A penetration test — performed by an independent tester, scoped in writing, with findings tracked to remediation — is the most defensible, auditable way most organisations satisfy this in practice. Self-assessment questionnaires and automated scans alone are weaker evidence because they lack independent verification.
Am I in Scope? Essential vs Important Entities
| Category | Example sectors | Maximum fine |
|---|---|---|
| Essential entities | Energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management (B2B), public administration, space | Up to €10,000,000 or 2% of worldwide annual turnover, whichever is higher |
| Important entities | Postal and courier services, waste management, chemicals, food, manufacturing, digital providers (incl. cloud and search engines), research | Up to €7,000,000 or 1.4% of worldwide annual turnover, whichever is higher |
NIS2 Is a Directive, Not a Regulation
Country-specific status current as of: 2 August 2026
Unlike GDPR (a Regulation, directly applicable in every member state), NIS2 is a Directive: it sets the outcome, and each EU member state transposes it into its own national law. The formal transposition deadline was 17 October 2024, but transposition and active enforcement have proceeded at different speeds across member states since then. If you operate in multiple EU jurisdictions, the practical question isn't "does NIS2 apply to us" — it's "which national law, with which specific requirements and enforcement posture, applies in each country we operate in." We do not publish a full country-by-country status table here, because it changes and stale country claims are worse than no claim — check your relevant member state's official transposing legislation or its national NIS2 competent authority directly for current status.
What Evidence Auditors Actually Ask For
If you don't have this evidence yet, the fastest way to start building it is a fixed-price test with a signed Attestation Letter.
NIS2 vs DORA vs CRA vs ISO 27001
| Framework | Applies to | Testing obligation | Do we offer it? |
|---|---|---|---|
| NIS2 | Essential and important entities across 18 EU sectors | No named testing requirement — Art. 21(2)(f) requires effectiveness-assessment policies; testing is a practical means, not a mandate | Yes — Vulnerability Assessment through Enterprise SaaS Pentest |
| DORA | EU financial entities (banks, insurers, investment firms, etc.) | Explicit: digital operational resilience testing for all in-scope entities; Threat-Led Penetration Testing (TLPT), TIBER-EU aligned, for entities designated 'significant' | Standard testing: yes. TLPT: no — we do not perform DORA Art. 26-27 TLPT engagements |
| CRA | Manufacturers of products with digital elements placed on the EU market | No named testing requirement — Art. 21 effectiveness-assessment obligation (see our CRA readiness page); reporting obligations for exploited vulnerabilities from 11 Sept 2026 | Yes — via our CRA Readiness Assessment and pentest tiers |
| ISO/IEC 27001 | Any organisation seeking certification | Annex A.8.29 — security testing in development and acceptance; not a fixed frequency | Yes — pentest reports are structured to satisfy A.8.29 evidence expectations |
See our Cyber Resilience Act Readiness page for the CRA-specific breakdown, and ISO 27001 services for certification support.
Penalties Under Article 34
| Entity type | Maximum fine |
|---|---|
| Essential entities | €10,000,000 or 2% of total worldwide annual turnover, whichever is higher |
| Important entities | €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
Frequently Asked Questions
Does NIS2 require penetration testing?+
How often should we test under NIS2?+
We're already ISO 27001 certified — is that enough for NIS2?+
Is my company an essential or an important entity?+
What are the fines?+
What's the difference between NIS2 and DORA testing?+
Do you perform TLPT?+
Which national law applies to us?+
Document Your Article 21(2)(f) Effectiveness Assessment
€539 · 5 business days · Signed Attestation Letter
