NIS2 penetration testing: what Article 21 actually requires
NIS2 (Directive (EU) 2022/2555) never uses the words "penetration test." Article 21 requires essential and important entities to manage cybersecurity risk with measures proportionate to their exposure, and to assess whether those measures work - which is where a pentest fits, as evidence rather than a checkbox requirement.
Does NIS2 require a penetration test?
Not by name. Directive (EU) 2022/2555 does not use the phrase "penetration test" anywhere in its text. Article 21 requires essential and important entities to take "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risk, and Article 21(2)(f) specifically requires "policies and procedures to assess the effectiveness of cybersecurity risk-management measures." In practice, testing - including penetration testing - is the standard way entities evidence that obligation.
If you are in scope for NIS2, you need to be able to show your controls actually work. A pentest is the most common way essential and important entities do that, even though the directive never names it.
A vendor page that flatly states "NIS2 requires a pentest" is inaccurate, and it is the kind of overclaim that answer engines increasingly discount. The accurate answer is the useful one: no named mandate, but a risk-management obligation that security testing is the standard way to evidence.
Who NIS2 applies to (essential vs important entities)
NIS2 covers entities in the Annex I sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space) and Annex II sectors (postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research), once they clear a size threshold: at least medium-sized under the EU SME definition (Commission Recommendation 2003/361/EC) - broadly, 50 or more staff, or annual turnover and/or balance sheet total of EUR 10 million or more.
Under Article 3, large enterprises (250 or more staff, or annual turnover above EUR 50 million and balance-sheet total above EUR 43 million) in Annex I sectors are generally classified as essential entities; medium-sized enterprises in Annex I, and medium or large enterprises in Annex II, are generally classified as important entities. Some providers - DNS services, TLD registries, and qualified trust service providers among them - are essential regardless of size. Member States were required to compile a national register of in-scope entities by 17 April 2025.
The Article 21 risk-management measures
Article 21(2) lists ten categories of measures every essential and important entity must implement, proportionate to its size, exposure, and the cost of implementation. Two map directly onto security testing: point (e), security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; and point (f), policies and procedures to assess the effectiveness of cybersecurity risk-management measures. The mapping below shows what a pentest evidences for each.
Incident reporting timelines
Article 23 sets a three-stage reporting clock that starts the moment an entity becomes aware of a "significant incident" - one causing severe operational disruption, financial loss, or considerable damage to others.
| Stage | Deadline |
|---|---|
| Early warning | Within 24 hours of becoming aware |
| Incident notification | Within 72 hours of becoming aware (updates the early warning with an initial severity and impact assessment) |
| Final report | Within 1 month of submitting the incident notification |
Reports go to the entity's national CSIRT or competent authority, and where an incident has cross-border impact, your national CSIRT or competent authority informs the other affected Member States. NIS2's obligations apply from 18 October 2024, though several Member States transposed into national law later (the Article 41 transposition deadline for Member States was 17 October 2024), so these clocks are live across most of the EU.
Penalties
Article 34 sets the minimum maximum fines Member States must be able to impose for infringements of Article 21 or 23. For essential entities, up to EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. For important entities, up to EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher. These are floors set by the directive - Member States may set higher national caps.
How Intrudify helps
Intrudify runs a full web and API pentest and produces a report that maps each finding to the relevant Article 21(2) measures, with reproducible proof for high and critical findings and developer-ready remediation. It supports your NIS2 risk-management evidence; Intrudify does not itself determine your essential/important classification or certify you against the directive.
- Findings mapped to the relevant Article 21(2) risk-management measures
- Reproducible proof-of-exploit for high and critical findings
- Developer-ready remediation and a re-test window
- Delivered in hours, validated by OSCE3-certified testers
How a pentest maps to controls
| Control | What a pentest evidences |
|---|---|
| Art. 21(2)(e) | Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure. |
| Art. 21(2)(f) | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures. |
Need audit-ready evidence for NIS2?
Book a scoping callFrequently asked questions
Does NIS2 require a penetration test?
Not by name - Directive (EU) 2022/2555 never uses the phrase. But Article 21(2)(f) requires policies to assess the effectiveness of your risk-management measures, and testing, including penetration testing, is the standard way essential and important entities evidence that in practice.
Who does NIS2 apply to - essential vs important entities?
Entities in Annex I or II sectors that are at least medium-sized (50+ staff or EUR 10 million+ turnover). Under Article 3, large Annex I entities are generally essential; medium Annex I entities and most Annex II entities are generally important. Some providers, like DNS operators, are essential regardless of size.
What are NIS2's incident reporting deadlines?
Article 23 sets three stages: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within 1 month of the notification.
What are the fines for NIS2 non-compliance?
Article 34 sets maximum fines of EUR 10,000,000 or 2% of worldwide annual turnover (whichever is higher) for essential entities, and EUR 7,000,000 or 1.4% (whichever is higher) for important entities, for infringements of Article 21 or 23.
Which Article 21 measures does a penetration test support?
Most directly, Article 21(2)(e) (security in system acquisition, development, and maintenance, including vulnerability handling) and Article 21(2)(f) (policies to assess the effectiveness of risk-management measures). Your competent authority confirms the exact mapping for your entity.
When did NIS2 become enforceable?
Member States had to transpose NIS2 into national law by 17 October 2024 (Article 41) and apply those measures from 18 October 2024, though several Member States transposed into national law later. The directive's obligations are live across most of the EU.