AI Pentest
If an AI feature is part of what you deliver to a customer in scope, test what it reads, says and does, and how far it reaches into the systems behind it.
Compliance / NIS2 / Cyberbeveiligingswet
NIS2 does not name penetration testing. Among the NIS2 requirements, Article 21 asks for policies and procedures to assess whether your cybersecurity measures are effective, and a recent pentest report is one of the most direct ways to show that they are. In the Netherlands, the Cyberbeveiligingswet has applied since 15 August 2026.
Not in so many words. Article 21 lists the cybersecurity risk-management measures that essential and important entities must take, and none of its ten points names penetration testing.Note 7 Point (f) is the one that matters here: policies and procedures to assess the effectiveness of those measures.Note 8
That is a duty to check, not only to have. An access review, a patch policy or a secure development process is a measure. A test that tries to get past them is an assessment of whether they work. A penetration test is one of the most direct forms of that assessment, because it reports what an attacker could actually do, with evidence, rather than what a configuration says should happen.
The Dutch Cyberbeveiligingswet copies the same duty into its article 21(3)(f).Note 9 Neither text prescribes a method, so the choice of assessment is yours, as long as it answers the question the law asks: do the measures work?
The Cbw has applied since 15 August 2026.Note 10 It covers 18 sectors: 11 in its first annex, such as energy, transport, banking, health care, digital infrastructure and business-to-business ICT service management, and 7 in its second, such as postal and courier services, manufacturing, digital providers and research.Note 11
Being in a sector is not enough on its own. The law applies from medium-sized enterprises upwards, plus some entity types at any size, such as trust service providers and providers of public electronic communications networks.Note 12 The NCSC puts the number of Dutch organisations with duties under the Cbw at more than 8,000.Note 13
Banks and insurers follow DORA instead for ICT risk and testing. The Digital Operational Resilience Act has applied since 17 January 2025, and for financial entities NIS2 would cover it is the sector-specific act that takes precedence.Note 14 Article 25 lists penetration tests among the tests a financial entity runs, and that is the work we do, the chatbot and its AI layer included; it can sit next to a TLPT provider's work.Note 15 Threat-led penetration testing (TLPT) under Article 26 is a separate regime, every three years for the entities their supervisor names, and we are not a TLPT provider yet: Article 27 asks those testers for the highest suitability and reputability, proven expertise in threat intelligence and red teaming, certification or a formal code of conduct, an independent audit of how they manage the test's risks, and indemnity insurance, and a firm as young as ours cannot show all of that.Note 16
Whether your organisation is essential, important or out of scope is a legal question. We test; classification is for your counsel.
Article 21 also asks for supply chain security, including the security of the relationship between an entity and its direct suppliers and service providers.Note 17 Entities must take into account the vulnerabilities specific to each direct supplier and the overall quality of its products and cybersecurity practices, including its secure development procedures.Note 18
So if you sell software to a hospital, a bank or a logistics company, their duty tends to arrive as your security questionnaire. That is an inference, not a line in the law, but it is the practical effect: the customers in scope have to weigh you, and a recent pentest report with its scope, dates, findings and retest status is the most direct answer you can attach.
Because the law asks about effectiveness, the useful report ties each finding to a measure. We write ours so that every part answers a question an auditor or a customer's security team will ask.
Management bodies must approve these measures, oversee them and can be held liable when they fall short.Note 20 A report written for engineers, with a summary its board can read, serves both readers.
Test the layer your customers rely on. If they rely on both, test both in one scope.
If an AI feature is part of what you deliver to a customer in scope, test what it reads, says and does, and how far it reaches into the systems behind it.
Web applications, APIs and cloud: the access, authentication and configuration measures Article 21 asks for, tested the way an attacker would try to get past them.
A SaaS platform and its AI feature in one scope and one report, including the paths that only show up when both layers are tested together.
The directive sets no frequency for a pentest. It asks for measures proportionate to your risk and for procedures that assess them, so test when the risk changes: before a major release, after an architecture change, and at least once a year for the systems your customers rely on. That rhythm is our advice, not a legal deadline.
A scan is a useful measure, and NIS2 lists vulnerability handling among its points. It is weaker evidence of effectiveness, because it lists possible weaknesses without showing which ones an attacker can use or chain. We suggest running scans continuously and a pentest at the moments that matter.
No single test does. NIS2 asks for a set of measures, from incident handling to access control and cryptography, and for procedures that check them. A pentest gives evidence for the checking and finds gaps in the rest. We never sell a test as a compliance certificate.
Yes. DORA has applied since 17 January 2025 and is the act financial entities follow for ICT risk and testing, in place of NIS2. Article 25 testing, the chatbot and AI layer included, is what we do. Threat-led testing under Article 26 is not ours yet: Article 27 sets tester requirements a firm as young as ours cannot meet.
Because your customers may be in scope. Entities in scope must manage the security of their direct suppliers and weigh each supplier's practices, so their questionnaires reach you. A recent report with scope, dates and retest status is the quickest way through them.
Scope, method, findings, retest status and the one-page attestation letter.
Written authorization first, staging first, and a stop procedure.
What Article 15 of the EU AI Act asks of high-risk AI systems, and when.