Compliance / NIS2 / Cyberbeveiligingswet

NIS2 penetration testing: what Article 21 asks you to prove.

NIS2 does not name penetration testing. Among the NIS2 requirements, Article 21 asks for policies and procedures to assess whether your cybersecurity measures are effective, and a recent pentest report is one of the most direct ways to show that they are. In the Netherlands, the Cyberbeveiligingswet has applied since 15 August 2026.

Updated
Sources
06

NIS2 in the Netherlands, in one table.

FIG. 1 / NIS2 AT A GLANCE
The directive
Directive (EU) 2022/2555 (NIS2), Official Journal L 333 of 27 December 2022Note 1
Dutch law
Cyberbeveiligingswet (Cbw), Staatsblad 2026, 187Note 2
Applies since
15 August 2026Note 3
Who
Medium-sized and larger entities in 18 sectors, plus some types at any sizeNote 4
The article
Article 21(2)(f) NIS2, article 21(3)(f) Cbw: assess whether your measures are effectiveNote 5
Names a pentest
No. It asks for an assessment; a pentest is one way to make it.
Incidents
Early warning within 24 hours, notification within 72 hoursNote 6
FIG. 2 / FROM DIRECTIVE TO DUTCH LAW
  1. NIS2 published in the Official Journal
  2. Deadline for member states to adopt their NIS2 law
  3. The Cyberbeveiligingswet applies in the Netherlands

Does NIS2 require a penetration test?

Not in so many words. Article 21 lists the cybersecurity risk-management measures that essential and important entities must take, and none of its ten points names penetration testing.Note 7 Point (f) is the one that matters here: policies and procedures to assess the effectiveness of those measures.Note 8

That is a duty to check, not only to have. An access review, a patch policy or a secure development process is a measure. A test that tries to get past them is an assessment of whether they work. A penetration test is one of the most direct forms of that assessment, because it reports what an attacker could actually do, with evidence, rather than what a configuration says should happen.

The Dutch Cyberbeveiligingswet copies the same duty into its article 21(3)(f).Note 9 Neither text prescribes a method, so the choice of assessment is yours, as long as it answers the question the law asks: do the measures work?

Who does the Cyberbeveiligingswet cover?

The Cbw has applied since 15 August 2026.Note 10 It covers 18 sectors: 11 in its first annex, such as energy, transport, banking, health care, digital infrastructure and business-to-business ICT service management, and 7 in its second, such as postal and courier services, manufacturing, digital providers and research.Note 11

Being in a sector is not enough on its own. The law applies from medium-sized enterprises upwards, plus some entity types at any size, such as trust service providers and providers of public electronic communications networks.Note 12 The NCSC puts the number of Dutch organisations with duties under the Cbw at more than 8,000.Note 13

Banks and insurers follow DORA instead for ICT risk and testing. The Digital Operational Resilience Act has applied since 17 January 2025, and for financial entities NIS2 would cover it is the sector-specific act that takes precedence.Note 14 Article 25 lists penetration tests among the tests a financial entity runs, and that is the work we do, the chatbot and its AI layer included; it can sit next to a TLPT provider's work.Note 15 Threat-led penetration testing (TLPT) under Article 26 is a separate regime, every three years for the entities their supervisor names, and we are not a TLPT provider yet: Article 27 asks those testers for the highest suitability and reputability, proven expertise in threat intelligence and red teaming, certification or a formal code of conduct, an independent audit of how they manage the test's risks, and indemnity insurance, and a firm as young as ours cannot show all of that.Note 16

Whether your organisation is essential, important or out of scope is a legal question. We test; classification is for your counsel.

Why NIS2 reaches suppliers that are not in scope.

Article 21 also asks for supply chain security, including the security of the relationship between an entity and its direct suppliers and service providers.Note 17 Entities must take into account the vulnerabilities specific to each direct supplier and the overall quality of its products and cybersecurity practices, including its secure development procedures.Note 18

So if you sell software to a hospital, a bank or a logistics company, their duty tends to arrive as your security questionnaire. That is an inference, not a line in the law, but it is the practical effect: the customers in scope have to weigh you, and a recent pentest report with its scope, dates, findings and retest status is the most direct answer you can attach.

What a pentest report should show for NIS2.

Because the law asks about effectiveness, the useful report ties each finding to a measure. We write ours so that every part answers a question an auditor or a customer's security team will ask.

Scope and dates
Which systems, which accounts, which window. An assessment is only as wide as its scope, so the report says what was out of it.
Method
The standard each test maps to: the OWASP Web Security Testing Guide and the OWASP API Security Top 10 for the stack, the OWASP Top 10 for LLM Applications and MITRE ATLAS for AI features.
Findings
What an attacker could do, with evidence and a severity in CVSS v4.0, so the risk can be weighed against the measure that should have stopped it.Note 19
Retest status
Which findings were fixed and confirmed fixed, with dates. This is the part that shows a measure works now.
Attestation letter
One page with scope, dates and outcome, so you can answer a customer without sharing the findings.

Management bodies must approve these measures, oversee them and can be held liable when they fall short.Note 20 A report written for engineers, with a summary its board can read, serves both readers.

Two tests can produce the evidence.

Test the layer your customers rely on. If they rely on both, test both in one scope.

01 / Model layer

AI Pentest

If an AI feature is part of what you deliver to a customer in scope, test what it reads, says and does, and how far it reaches into the systems behind it.

02 / Stack layer

Stack Pentest

Web applications, APIs and cloud: the access, authentication and configuration measures Article 21 asks for, tested the way an attacker would try to get past them.

03 / Clearance

Launch Clearance

A SaaS platform and its AI feature in one scope and one report, including the paths that only show up when both layers are tested together.

NIS2 questions we hear before a test.

How often should we run a penetration test under NIS2?

The directive sets no frequency for a pentest. It asks for measures proportionate to your risk and for procedures that assess them, so test when the risk changes: before a major release, after an architecture change, and at least once a year for the systems your customers rely on. That rhythm is our advice, not a legal deadline.

Is a vulnerability scan enough for the NIS2 requirements?

A scan is a useful measure, and NIS2 lists vulnerability handling among its points. It is weaker evidence of effectiveness, because it lists possible weaknesses without showing which ones an attacker can use or chain. We suggest running scans continuously and a pentest at the moments that matter.

Does a penetration test make us NIS2 compliant?

No single test does. NIS2 asks for a set of measures, from incident handling to access control and cryptography, and for procedures that check them. A pentest gives evidence for the checking and finds gaps in the rest. We never sell a test as a compliance certificate.

We are a bank or an insurer. Does DORA change the test?

Yes. DORA has applied since 17 January 2025 and is the act financial entities follow for ICT risk and testing, in place of NIS2. Article 25 testing, the chatbot and AI layer included, is what we do. Threat-led testing under Article 26 is not ours yet: Article 27 sets tester requirements a firm as young as ours cannot meet.

We are not in scope of the Cbw. Why would NIS2 matter to us?

Because your customers may be in scope. Entities in scope must manage the security of their direct suppliers and weigh each supplier's practices, so their questionnaires reach you. A recent report with scope, dates and retest status is the quickest way through them.

Read next