European Union · Directive (EU) 2022/2555 (NIS2)
Does NIS2 require a penetration test?
NIS2 is the European Union's cybersecurity directive for essential and important entities. Unlike a regulation it is transposed into national law by each member state, so the specifics vary by country.
The short answer
NIS2 does not name penetration testing. Article 21(2) requires risk management measures including policies on assessing the effectiveness of cybersecurity risk management measures, and security in network and information systems acquisition, development and maintenance including vulnerability handling and disclosure. National transposition can add specifics.
Who it applies to
Entities in the sectors listed in the directive's annexes, above defined size thresholds, operating in the EU. Digital infrastructure and ICT service management are in scope, which catches many technology companies.
In detail
Article 21 lists ten categories of measure that in-scope entities must take, covering risk analysis, incident handling, business continuity, supply chain security, vulnerability handling and disclosure, effectiveness assessment, cyber hygiene, cryptography, access control and multi-factor authentication.
Because NIS2 is a directive, the binding text for any given company is its member state's implementing law, and those laws differ in scope, deadlines and penalties. Anyone assessing NIS2 exposure needs to look at the national transposition rather than the directive alone.
Management liability is the change that gets attention. The directive requires management bodies to approve and oversee risk management measures and makes them accountable for failures, which moves cybersecurity into the board conversation in a way the original NIS directive did not.
What to have in scope
- Network and information systems supporting the in-scope service
- Supply chain and third party interfaces, which Article 21 calls out directly
- Evidence of the effectiveness assessment required by Article 21(2)(f)
Questions people ask
Does NIS2 require penetration testing?
Not explicitly. Article 21(2) requires policies and procedures to assess the effectiveness of cybersecurity risk management measures, along with vulnerability handling and disclosure. Penetration testing is a common way to meet the effectiveness assessment obligation, and national implementing laws may be more specific.
Does NIS2 apply to companies outside the EU?
It can. Entities established outside the EU that provide in-scope services within it may fall under the directive and may be required to designate a representative in the EU. The national transposition governs the detail.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.