NIS2 Penetration Testing
NIS2 penetration testing that proves your Article 21 measures work, with findings mapped for your supervisor. Manual, evidence-based. Get a quote.
NIS2 penetration testing gives essential and important entities the technical evidence that the security measures required by the directive are actually working, not just written down in a policy. We test your systems the way an attacker would, then hand you a report your management body can sign off against Article 21 and your national supervisor can accept.
What NIS2 penetration testing actually covers
The NIS2 Directive, Directive (EU) 2022/2555, does not name a specific test in the way PCI DSS does. What it does require, in Article 21, is that entities take appropriate and proportionate technical measures to manage cyber risk, and that management is accountable for them. A penetration test is the most direct way to show those measures hold under a real attack. We scope the test to the systems that support your essential or important service and probe them for the weaknesses an intruder would use.
SafetyBis works with organizations across Europe that fall under national NIS2 transpositions, from energy and transport to healthcare, digital infrastructure and managed service providers. The test is manual and evidence-based; you get proof of exploitability, not a scanner’s guess.
How the directive frames security testing
Reading Article 21 closely helps you scope the right test. The directive lists measures every entity must have, and several of them are exactly what a pentest evaluates.
Article 21 risk-management measures
Article 21(2) sets out the minimum: policies on risk analysis, incident handling, business continuity, supply-chain security, security in acquisition and development, policies to assess the effectiveness of measures, basic cyber hygiene, cryptography, access control and asset management, and the use of multi-factor authentication. Point (f) matters most here, because assessing the effectiveness of your risk-management measures is precisely what a penetration test does. We test whether the controls behind those bullet points actually stop an attacker.
Article 23 incident reporting
NIS2 sets tight reporting deadlines: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. A pentest that reaches a critical system is a useful rehearsal for whether your detection would even give you the clock to start. Where you want it, we run the test loud enough at the end to check your monitoring fires.
Management accountability under Article 20
Article 20 puts responsibility on the management body and exposes it to liability. Independent testing gives your board defensible evidence that it exercised oversight, which is the record you want if a supervisor or an insurer ever asks.
How we test, phase by phase
The method is the same disciplined process we run on any serious engagement, tuned to the systems that carry regulatory weight for you.
Scoping and reconnaissance
We identify the assets that support your essential or important service, map the external attack surface with tooling like nmap and passive reconnaissance, and agree the rules of engagement. Nothing intrusive runs before this is signed.
Testing and exploitation
The bulk of the work is manual. We use Burp Suite for web and API testing, custom tooling for network and service exploitation, and hands-on business-logic testing that no scanner performs. When we find a weakness, we prove it by exploiting it safely, then chain findings to show the realistic path an attacker would take from the internet to your crown jewels.
Authenticated and unauthenticated views
We test both from the outside with no credentials and from inside a low-privilege account, because the two tell you different things. An unauthenticated view shows what a stranger reaches. An authenticated view shows how far a phished employee or a malicious insider gets once past the front door, which for NIS2 estates is usually the more dangerous story.
Reporting and retest
You get an executive summary and a technical report, each finding carrying a CVSS score, reproduction steps and a prioritized fix. After your team remediates, we retest at no extra cost and confirm the holes are closed.
Vulnerability classes we find most often
Across NIS2-scope estates, the same handful of issues keep opening the door. None of them are exotic, which is exactly why attackers rely on them.
Weak or missing multi-factor authentication
The directive calls for MFA, yet we routinely find remote access, admin panels and legacy VPNs where a single stolen password is enough. We test whether phishing one credential actually gets an attacker in.
Flat networks and poor segmentation
When a compromised workstation can reach a control system or a patient database directly, one foothold becomes a full breach. We test how far lateral movement gets before something stops it.
Unpatched and exposed services
Forgotten internet-facing services carrying known CVEs are still the fastest way in. We verify exploitability rather than just flagging a version number.
Supply-chain and remote-access footholds
NIS2 makes supplier security an explicit obligation. We look at the access your vendors and managed service providers hold and what an attacker could reach through it.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you receive
The deliverables are written to two audiences. Leadership needs a clear statement of business risk and regulatory exposure; engineers need enough detail to reproduce and fix each issue.
Executive and technical report
A short summary for the management body, then a full technical report with every finding, its impact, CVSS score, evidence and a concrete remediation step. Findings are cross-referenced to the relevant Article 21 measures so a supervisor sees the connection immediately.
Attestation and retest
An attestation letter you can show clients, insurers and your competent authority, plus a free retest confirming the fixes hold. That retest letter is often what closes the loop for audit.
Why manual testing beats a scanner for NIS2
A vulnerability scanner produces a long list of maybes and misses the things that actually matter under the directive: a business-logic flaw that lets one user act as another, an authentication bypass a scanner cannot recognize, a chain of three low findings that together reach a critical system. Article 21(2)(f) asks you to assess whether your measures are effective. A scanner cannot tell you that; it only tells you what version software is running. A human who has broken into estates like yours can, and will show you the exact path with evidence a regulator accepts.
Which organizations fall under NIS2
NIS2 widened the net considerably compared to the original NIS Directive. If you were not in scope before, you may well be now, and the practical trigger is usually your sector combined with your headcount and turnover.
Essential entities
These include operators in energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure such as data centers and DNS providers, ICT service management, public administration, and space. Larger firms in these sectors generally land here and face the fuller supervisory regime.
Important entities
This category adds sectors like postal services, waste management, chemicals, food, manufacturing of certain products, digital providers such as online marketplaces and search engines, and research. Medium-sized firms in the essential sectors often sit here too. The measures are the same; the supervision is lighter-touch until something goes wrong.
The size and sector test
National transpositions differ in the detail, so the safe move is to check your specific situation against your country’s law. In practice, if you provide one of the listed services and you are medium-sized or larger, you should assume you are in scope and plan your testing accordingly.
When to run a NIS2 test
Timing matters more than firms expect. A test six months before an audit gives you time to fix what it finds; a test the week before does not. There are a few natural triggers.
Before your first supervisory review
Get the technical evidence in place ahead of any interaction with your competent authority, so you are presenting a remediated estate and a clean retest letter rather than a fresh list of open holes.
After significant change
A new customer-facing platform, a cloud migration, a merged business unit or a new critical supplier all change your attack surface. Retesting after material change is part of keeping Article 21 measures effective rather than stale.
On a recurring cycle
An annual test, with a lighter check after major releases, keeps your assurance current and gives the management body a steady record of oversight rather than a one-off snapshot.
Pricing
NIS2 testing is priced by the size of the estate that supports your essential or important service: how many hosts and applications are in scope, whether testing is authenticated, and how much supply-chain surface you want examined. Every engagement is fixed-price after a scoping call.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Focused service test | One essential service: external network plus its web application, OWASP coverage, report and free retest | 4–6 working days | from €3,000 |
| Standard NIS2 test | External and internal network, key applications and APIs, access-control and MFA review, Article 21 mapping | 6–10 working days | €5,000–€12,000 |
| Extended estate | Multiple services or sites, segmentation testing, supply-chain and remote-access exposure, attack-chaining | 10–15 working days | €12,000–€25,000 |
| Attestation package | Article 21 gap mapping and an attestation letter for your supervisor, added to any tier | with any tier | from €900 |
| Custom / multi-entity | Group or cross-border operator, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with the attestation and a retest included. Get a fixed quote
FAQ
How much does a NIS2 penetration test cost?
Does NIS2 actually require a penetration test?
Are you an essential or important entity too, and can you advise which we are?
How long does a NIS2 security test take?
What do we get for our auditors and supervisor?
Will the test affect the availability of our service?
Do you also test our incident detection?
Are the findings kept confidential?
Related services
Operators of essential and important services across Europe, in sectors such as energy, transport, banking, health, water, digital infrastructure and managed services, that need technical proof their Article 21 measures work and defensible evidence for the management body and their national supervisor.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.