NIS2 penetration testing: what Article 21 actually requires

NIS2 (Directive (EU) 2022/2555) never uses the words "penetration test." Article 21 requires essential and important entities to manage cybersecurity risk with measures proportionate to their exposure, and to assess whether those measures work - which is where a pentest fits, as evidence rather than a checkbox requirement.

Does NIS2 require a penetration test?

Not by name. Directive (EU) 2022/2555 never uses the phrase "penetration test." Article 21(2)(f) requires essential and important entities to prove their risk-management measures actually work, and testing, including penetration testing, is the standard way they do it.

Not by name. Directive (EU) 2022/2555 does not use the phrase "penetration test" anywhere in its text. Article 21 requires essential and important entities to take "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risk, and Article 21(2)(f) specifically requires "policies and procedures to assess the effectiveness of cybersecurity risk-management measures." In practice, testing - including penetration testing - is the standard way entities evidence that obligation.

If you are in scope for NIS2, you need to be able to show your controls actually work. A pentest is the most common way essential and important entities do that, even though the directive never names it.

A vendor page that flatly states "NIS2 requires a pentest" is inaccurate, and it is the kind of overclaim that answer engines increasingly discount. The accurate answer is the useful one: no named mandate, but a risk-management obligation that security testing is the standard way to evidence.

Who NIS2 applies to (essential vs important entities)

NIS2 covers Annex I and Annex II sectors once an organisation clears a size threshold: broadly 50 or more staff, or EUR 10 million or more in turnover. Large Annex I entities are generally classified as essential; medium Annex I entities and most Annex II entities are generally classified as important. A few providers, DNS operators among them, are essential regardless of size.

The full Annex I/II sector list and how the essential/important thresholds work

NIS2 covers entities in the Annex I sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space) and Annex II sectors (postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research), once they clear a size threshold: at least medium-sized under the EU SME definition (Commission Recommendation 2003/361/EC) - broadly, 50 or more staff, or annual turnover and/or balance sheet total of EUR 10 million or more.

Under Article 3, large enterprises (250 or more staff, or annual turnover above EUR 50 million and balance-sheet total above EUR 43 million) in Annex I sectors are generally classified as essential entities; medium-sized enterprises in Annex I, and medium or large enterprises in Annex II, are generally classified as important entities. Some providers - DNS services, TLD registries, and qualified trust service providers among them - are essential regardless of size. Member States were required to compile a national register of in-scope entities by 17 April 2025.

The Article 21 risk-management measures

Article 21(2) lists ten categories of measures every essential and important entity must implement, proportionate to size and exposure. Two map directly onto testing: point (e), security in system acquisition and maintenance, and point (f), assessing whether those measures actually work.

Article 21(2) lists ten categories of measures every essential and important entity must implement, proportionate to its size, exposure, and the cost of implementation. Two map directly onto security testing: point (e), security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; and point (f), policies and procedures to assess the effectiveness of cybersecurity risk-management measures. The mapping below shows what a pentest evidences for each.

Incident reporting timelines

Article 23 sets a three-stage reporting clock once an entity becomes aware of a significant incident: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.

StageDeadline
Early warningWithin 24 hours of becoming aware
Incident notificationWithin 72 hours of becoming aware (updates the early warning with an initial severity and impact assessment)
Final reportWithin 1 month of submitting the incident notification
Who you report to, cross-border rules, and why these clocks are already running

Article 23 sets a three-stage reporting clock that starts the moment an entity becomes aware of a "significant incident" - one causing severe operational disruption, financial loss, or considerable damage to others.

Reports go to the entity's national CSIRT or competent authority, and where an incident has cross-border impact, your national CSIRT or competent authority informs the other affected Member States. NIS2's obligations apply from 18 October 2024, though several Member States transposed into national law later (the Article 41 transposition deadline for Member States was 17 October 2024), so these clocks are live across most of the EU.

Penalties

Article 34 sets fines of up to EUR 10,000,000 or 2% of total worldwide annual turnover for essential entities, and up to EUR 7,000,000 or 1.4% for important entities, whichever is higher. These are EU-wide floors; your actual exposure depends on how your country transposed Article 34.

How the EUR 10M/7M floors and national top-ups actually work

Article 34 sets the minimum maximum fines Member States must be able to impose for infringements of Article 21 or 23. For essential entities, up to EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. For important entities, up to EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher. These are floors set by the directive - Member States may set higher national caps, and your actual exposure depends on how your specific country transposed Article 34, not on the EU-wide floor alone.

NIS2 vs DORA vs ISO 27001 - which applies to you

NIS2, DORA, and ISO 27001 overlap in substance but differ in legal status. NIS2 is an EU directive needing national transposition; DORA is an EU regulation that applies directly to the financial sector; ISO 27001 is a voluntary certification standard, not a law.

CriterionNIS2DORAISO 27001
Legal statusEU directive, national transposition requiredEU regulation, applies directlyVoluntary certification standard
Who it coversEssential and important entities in Annex I/II sectorsEU financial entities and their critical ICT providersAny organization that chooses to certify
Names a penetration test?No - Art. 21(2)(f) requires testing effectivenessYes - Art. 25 names penetration testing directlyNo - Annex A.8.8 and A.8.29
Full comparison: legal status, scope, and which directive actually names a pentest

NIS2, DORA, and ISO 27001 get bundled together in vendor content because they overlap in substance, not because they are interchangeable. Each has a different legal status, and knowing which one actually governs you changes what "compliant" means in practice.

NIS2 is an EU directive: it needed national transposition, and that transposition is still incomplete in several member states (see the next section). DORA is an EU regulation that applies directly, with no transposition step, and it is scoped specifically to the financial sector - banks, insurers, investment firms, and their critical ICT providers. If you are a financial entity, DORA is the more specific framework for the same risk-management ground NIS2 covers elsewhere; see DORA penetration testing rather than budgeting for both in parallel. ISO 27001 is neither a law nor a directive - it is a voluntary certification standard. Certifying against it does not by itself satisfy NIS2, and NIS2 compliance does not certify you against ISO 27001, but a mature Information Security Management System built for ISO 27001 covers much of the same ground Article 21 asks for.

Is NIS2 in force in your country yet

NIS2 does not switch on for the whole EU on one date. Some member states, like Belgium and Italy, met the 17 October 2024 deadline; others transposed more than a year late; and as of August 2026, France, Spain, and Ireland had still not completed transposition and were referred to the Court of Justice of the European Union on 8 July 2026.

See the full country-by-country picture on the NIS2 transposition status page.

Explore the NIS2 hub

Not sure you are even in scope? Start with the free check below. Two focused guides go deeper on the two questions buyers ask most after that.

How Intrudify helps

Intrudify runs a full web and API pentest and produces a report that maps each finding to the relevant Article 21(2) measures, with reproducible proof for high and critical findings and developer-ready remediation. It supports your NIS2 risk-management evidence; Intrudify does not itself determine your essential/important classification or certify you against the directive. See the full penetration testing service this pentest is delivered through.

  • Findings mapped to the relevant Article 21(2) risk-management measures
  • Reproducible proof-of-exploit for high and critical findings
  • Developer-ready remediation and a re-test window
  • Delivered in hours, validated by OSCE3-certified testers

Need audit-ready evidence for NIS2?

Book a scoping call

Frequently asked questions

Does NIS2 require a penetration test?

Not by name - Directive (EU) 2022/2555 never uses the phrase. But Article 21(2)(f) requires policies to assess the effectiveness of your risk-management measures, and testing, including penetration testing, is the standard way essential and important entities evidence that in practice.

Who does NIS2 apply to - essential vs important entities?

Entities in Annex I or II sectors that are at least medium-sized (50+ staff or EUR 10 million+ turnover). Under Article 3, large Annex I entities are generally essential; medium Annex I entities and most Annex II entities are generally important. Some providers, like DNS operators, are essential regardless of size.

What are NIS2's incident reporting deadlines?

Article 23 sets three stages: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within 1 month of the notification.

What are the fines for NIS2 non-compliance?

Article 34 sets maximum fines of EUR 10,000,000 or 2% of worldwide annual turnover (whichever is higher) for essential entities, and EUR 7,000,000 or 1.4% (whichever is higher) for important entities, for infringements of Article 21 or 23. These are EU-wide floors - your national exposure depends on how your specific member state transposed Article 34, and some states set higher caps or add their own penalty structures on top.

Which Article 21 measures does a penetration test support?

Most directly, Article 21(2)(e) (security in system acquisition, development, and maintenance, including vulnerability handling) and Article 21(2)(f) (policies to assess the effectiveness of risk-management measures). Your competent authority confirms the exact mapping for your entity.

Is NIS2 vs DORA vs ISO 27001 a choice you have to make?

No - they usually stack rather than compete. DORA is the more specific framework if you are a financial entity; ISO 27001 is a voluntary certification that overlaps with, but does not replace, NIS2's legal obligations. See the comparison above.

When did NIS2 become enforceable?

Member States had to transpose NIS2 into national law by 17 October 2024 (Article 41) and apply those measures from 18 October 2024, though several Member States transposed into national law later - some are still not transposed as of August 2026. See the transposition status page for the country-by-country picture.

Sources
Related frameworks
ISO 27001 Not named in Annex A, but certification auditors expect a pentest as evidence. DORA General testing (incl. penetration testing) is required under Art. 24-25; a separate, human-led TLPT is required only for entities identified under Art. 26-27, and no automated test substitutes for it. GDPR GDPR does not name pentesting, but Article 32(1)(d) requires regularly testing the effectiveness of security measures. CRA The CRA requires manufacturers to security-test products with digital elements and handle vulnerabilities; not a named pentest.
All compliance frameworks