NIS2 DIRECTIVE

NIS2 penetration testing

NIS2 obliges essential and important entities to take appropriate technical measures and to assess whether those measures are effective. A penetration test is the standard way to produce that evidence.

We test your systems the way an attacker would, then hand you a report structured so a supervisory authority or an auditor can read it as proof.

THEY TRUST US

Raiffeisen Processing Centre Logo
Penta Hospitals Logo
Pixel Federation Logo
Ministry Of Finance - Slovakia Logo
DanubePay Logo
Alison Logo
Ditec Logo
Sanaclis Logo
Piano Logo
Ultima Payments Logo
Amerge Logo
Digital Systems Logo

NIS2 DIRECTIVE

What NIS2 actually asks for

Directive (EU) 2022/2555 — NIS2 — replaced the original NIS Directive and widened both the sectors in scope and the obligations placed on them. Two of the risk-management measures in Article 21(2) are the ones a penetration test speaks to directly:

NIS2 is a directive, not a regulation, so what binds you is your own country's transposition. The obligations, deadlines and supervisory authority differ by member state — the table below summarises the three markets we work in most.

Article 21(2) requirement → what we deliver

NIS2 requirementWhat Haxoris delivers
Art. 21(2)(e) — security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosureApplication, API and infrastructure penetration testing against OWASP Top 10:2025, ASVS and WSTG, with every finding rated, evidenced and mapped to a concrete remediation.
Art. 21(2)(f) — policies and procedures to assess the effectiveness of cybersecurity risk-management measuresAn independent test that measures whether the controls you already paid for actually stop an attacker, plus a free retest confirming the fixes hold.
Art. 21(2)(d) — supply chain securityTesting of the integrations, APIs and third-party components your service depends on, including cloud configuration and identity boundaries.
Art. 23 — incident reportingFindings that would constitute a reportable incident if exploited are flagged as such, so your reporting process is rehearsed before it is needed.

How NIS2 applies in your country

CountryTranspositionSupervisory authority
SlovakiaAct No. 366/2024 Coll., amending the Act on Cybersecurity No. 69/2018 Coll., in force since 1 January 2025National Security Authority (NBÚ)
Czech RepublicAct No. 264/2025 Coll., the new Cybersecurity Act (nZKB), with a self-identification duty for regulated entitiesNÚKIB
GermanyNIS2UmsuCG, amending the BSI Act (BSIG)BSI

Transposition timetables and entity thresholds change. Confirm your own classification and deadlines with your national authority — we scope the test around whatever classification applies to you.

The evidence chain an auditor expects

A test report on its own is rarely enough. What satisfies an assessor is a closed loop, and we produce every link in it:

1

Scope and authorisation

A written scope, rules of engagement and signed authorisation, so the test itself is documented and lawful.

2

Test report

Findings with severity, business impact, reproduction steps and evidence — readable by both your engineers and your auditor.

3

Remediation plan

Each finding mapped to a concrete fix and an owner, so the report becomes a work list rather than a document.

4

Retest and sign-off

We retest the fixes free of charge and issue a statement of what was resolved — the artefact that closes the loop.

Who is in scope

NIS2 covers essential and important entities across eighteen sectors. If you operate in any of these and exceed the size thresholds, you are very likely in scope:

Energy

Digital infrastructure and providers

Banking and financial market infrastructure

Healthcare

Transport

Manufacturing

Water supply and waste management

Public administration

TESTIMONIALS

What our clients say about us

NIS2 and penetration testing — common questions

01 Does NIS2 explicitly require a penetration test?

Not by name. NIS2 requires appropriate technical measures and, in Article 21(2)(f), policies and procedures to assess whether those measures are effective. A penetration test is the established way to produce that assessment, and it is what auditors and supervisory authorities in practice ask to see.

02 How often do we need to test?

Most regulated entities test at least annually, and again after any significant change to the system or its architecture. We can also run a lighter re-scope mid-year for fast-moving environments.

03 Are we in scope?

That depends on your sector and size, and on how your country transposed the directive. Tell us what you operate and we will walk through the classification with you on a free call — we would rather scope it correctly than sell you a test you do not need.

04 How much does a NIS2 penetration test cost?

It depends on scope. A basic web application test starts from around €2,000; larger networks, cloud estates or multi-system scopes cost more. A typical engagement runs 5 to 15 person-days and we quote a fixed price after a short scoping call.

05 Will testing disrupt production?

No. We agree rules of engagement in writing before we start, isolate anything potentially disruptive to an agreed window, and keep an open line to your DevOps team throughout.

06 Do you provide documentation we can hand to an auditor?

Yes. The report, the remediation record and the retest statement are written to be read by an assessor, not just an engineer. That combination is what closes the evidence chain.

Find out whether you are NIS2 ready

A short call is enough to establish your likely classification, what needs testing and what it will cost. No obligation, no sales script. ISO 27001 penetration testing · Vulnerability assessment · Red teaming

Book a free NIS2 scoping call