As an organisation in scope for the NIS2 Directive, Fru treated the requirements as an opportunity to formalise what the team was already doing. One of them stood out for its timeline: an independent penetration test, with documented results and follow-up, that could be presented as evidence of ongoing security testing.
With a tight compliance deadline, Fru needed a partner who could move at their pace without giving up rigour.
A full test, scoped and delivered in a day
Scope was agreed and testing began the same day. Intrudify mapped the external attack surface and the authenticated application flows, then ran a full penetration test covering authentication, authorisation, input handling, session management and business logic.
Every result was validated before it reached the report, and documented with reproduction steps, impact and a recommended fix. The final document included an executive summary written for auditors and non-technical stakeholders.
Evidence that closes rather than opens questions
Fru's team completed the follow-up work over the following days. Intrudify re-tested it and issued a closure confirmation for the compliance file, so the evidence trail ran from finding to fix to independent verification without a gap in the middle.
The report, remediation summary and closure confirmation were accepted as evidence for the NIS2 security testing requirement without follow-up questions.
The pentest was the part of NIS2 I was working on. We kicked it off in the morning and had the report by the afternoon.
The outcome
With independent testing and a documented vulnerability-handling process in place, Fru meets the directive’s expectations for security testing and vulnerability management, and has a repeatable process for the next cycle rather than a one-off exercise.