NIS2 DIRECTIVE
NIS2 penetration testing
NIS2 obliges essential and important entities to take appropriate technical measures and to assess whether those measures are effective. A penetration test is the standard way to produce that evidence.
We test your systems the way an attacker would, then hand you a report structured so a supervisory authority or an auditor can read it as proof.
THEY TRUST US
NIS2 DIRECTIVE
What NIS2 actually asks for
Directive (EU) 2022/2555 — NIS2 — replaced the original NIS Directive and widened both the sectors in scope and the obligations placed on them. Two of the risk-management measures in Article 21(2) are the ones a penetration test speaks to directly:
NIS2 is a directive, not a regulation, so what binds you is your own country's transposition. The obligations, deadlines and supervisory authority differ by member state — the table below summarises the three markets we work in most.
Article 21(2) requirement → what we deliver
| NIS2 requirement | What Haxoris delivers |
|---|---|
| Art. 21(2)(e) — security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure | Application, API and infrastructure penetration testing against OWASP Top 10:2025, ASVS and WSTG, with every finding rated, evidenced and mapped to a concrete remediation. |
| Art. 21(2)(f) — policies and procedures to assess the effectiveness of cybersecurity risk-management measures | An independent test that measures whether the controls you already paid for actually stop an attacker, plus a free retest confirming the fixes hold. |
| Art. 21(2)(d) — supply chain security | Testing of the integrations, APIs and third-party components your service depends on, including cloud configuration and identity boundaries. |
| Art. 23 — incident reporting | Findings that would constitute a reportable incident if exploited are flagged as such, so your reporting process is rehearsed before it is needed. |
How NIS2 applies in your country
| Country | Transposition | Supervisory authority |
|---|---|---|
| Slovakia | Act No. 366/2024 Coll., amending the Act on Cybersecurity No. 69/2018 Coll., in force since 1 January 2025 | National Security Authority (NBÚ) |
| Czech Republic | Act No. 264/2025 Coll., the new Cybersecurity Act (nZKB), with a self-identification duty for regulated entities | NÚKIB |
| Germany | NIS2UmsuCG, amending the BSI Act (BSIG) | BSI |
Transposition timetables and entity thresholds change. Confirm your own classification and deadlines with your national authority — we scope the test around whatever classification applies to you.
The evidence chain an auditor expects
A test report on its own is rarely enough. What satisfies an assessor is a closed loop, and we produce every link in it:
Scope and authorisation
A written scope, rules of engagement and signed authorisation, so the test itself is documented and lawful.
Test report
Findings with severity, business impact, reproduction steps and evidence — readable by both your engineers and your auditor.
Remediation plan
Each finding mapped to a concrete fix and an owner, so the report becomes a work list rather than a document.
Retest and sign-off
We retest the fixes free of charge and issue a statement of what was resolved — the artefact that closes the loop.
Who is in scope
NIS2 covers essential and important entities across eighteen sectors. If you operate in any of these and exceed the size thresholds, you are very likely in scope:
Energy
Digital infrastructure and providers
Banking and financial market infrastructure
Healthcare
Transport
Manufacturing
Water supply and waste management
Public administration
TESTIMONIALS
What our clients say about us
NIS2 and penetration testing — common questions
01 Does NIS2 explicitly require a penetration test?
Not by name. NIS2 requires appropriate technical measures and, in Article 21(2)(f), policies and procedures to assess whether those measures are effective. A penetration test is the established way to produce that assessment, and it is what auditors and supervisory authorities in practice ask to see.
02 How often do we need to test?
Most regulated entities test at least annually, and again after any significant change to the system or its architecture. We can also run a lighter re-scope mid-year for fast-moving environments.
03 Are we in scope?
That depends on your sector and size, and on how your country transposed the directive. Tell us what you operate and we will walk through the classification with you on a free call — we would rather scope it correctly than sell you a test you do not need.
04 How much does a NIS2 penetration test cost?
It depends on scope. A basic web application test starts from around €2,000; larger networks, cloud estates or multi-system scopes cost more. A typical engagement runs 5 to 15 person-days and we quote a fixed price after a short scoping call.
05 Will testing disrupt production?
No. We agree rules of engagement in writing before we start, isolate anything potentially disruptive to an agreed window, and keep an open line to your DevOps team throughout.
06 Do you provide documentation we can hand to an auditor?
Yes. The report, the remediation record and the retest statement are written to be read by an assessor, not just an engineer. That combination is what closes the evidence chain.
Find out whether you are NIS2 ready
A short call is enough to establish your likely classification, what needs testing and what it will cost. No obligation, no sales script. ISO 27001 penetration testing · Vulnerability assessment · Red teaming
Book a free NIS2 scoping call