Home/Services/NIS2 Penetration Testing
security service

NIS2 Penetration Testing

NIS2 penetration testing that proves your Article 21 measures work, with findings mapped for your supervisor. Manual, evidence-based. Get a quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

NIS2 penetration testing gives essential and important entities the technical evidence that the security measures required by the directive are actually working, not just written down in a policy. We test your systems the way an attacker would, then hand you a report your management body can sign off against Article 21 and your national supervisor can accept.

What NIS2 penetration testing actually covers

The NIS2 Directive, Directive (EU) 2022/2555, does not name a specific test in the way PCI DSS does. What it does require, in Article 21, is that entities take appropriate and proportionate technical measures to manage cyber risk, and that management is accountable for them. A penetration test is the most direct way to show those measures hold under a real attack. We scope the test to the systems that support your essential or important service and probe them for the weaknesses an intruder would use.

SafetyBis works with organizations across Europe that fall under national NIS2 transpositions, from energy and transport to healthcare, digital infrastructure and managed service providers. The test is manual and evidence-based; you get proof of exploitability, not a scanner’s guess.

External and internal network testing of the systems behind your essential service
Web application and API testing where your service is delivered online
Review of access control, segmentation and multi-factor authentication
Supply-chain and remote-access exposure, since NIS2 makes both your problem
Findings mapped to the Article 21 measures so gaps are easy to defend
An attestation letter and a free retest after you remediate

How the directive frames security testing

Reading Article 21 closely helps you scope the right test. The directive lists measures every entity must have, and several of them are exactly what a pentest evaluates.

Article 21 risk-management measures

Article 21(2) sets out the minimum: policies on risk analysis, incident handling, business continuity, supply-chain security, security in acquisition and development, policies to assess the effectiveness of measures, basic cyber hygiene, cryptography, access control and asset management, and the use of multi-factor authentication. Point (f) matters most here, because assessing the effectiveness of your risk-management measures is precisely what a penetration test does. We test whether the controls behind those bullet points actually stop an attacker.

Article 23 incident reporting

NIS2 sets tight reporting deadlines: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. A pentest that reaches a critical system is a useful rehearsal for whether your detection would even give you the clock to start. Where you want it, we run the test loud enough at the end to check your monitoring fires.

Management accountability under Article 20

Article 20 puts responsibility on the management body and exposes it to liability. Independent testing gives your board defensible evidence that it exercised oversight, which is the record you want if a supervisor or an insurer ever asks.

How we test, phase by phase

The method is the same disciplined process we run on any serious engagement, tuned to the systems that carry regulatory weight for you.

Scoping and reconnaissance

We identify the assets that support your essential or important service, map the external attack surface with tooling like nmap and passive reconnaissance, and agree the rules of engagement. Nothing intrusive runs before this is signed.

Testing and exploitation

The bulk of the work is manual. We use Burp Suite for web and API testing, custom tooling for network and service exploitation, and hands-on business-logic testing that no scanner performs. When we find a weakness, we prove it by exploiting it safely, then chain findings to show the realistic path an attacker would take from the internet to your crown jewels.

Authenticated and unauthenticated views

We test both from the outside with no credentials and from inside a low-privilege account, because the two tell you different things. An unauthenticated view shows what a stranger reaches. An authenticated view shows how far a phished employee or a malicious insider gets once past the front door, which for NIS2 estates is usually the more dangerous story.

Reporting and retest

You get an executive summary and a technical report, each finding carrying a CVSS score, reproduction steps and a prioritized fix. After your team remediates, we retest at no extra cost and confirm the holes are closed.

5–8
working days for a typical NIS2 test
48h
to first critical findings, not month-end
Free
retest once your fixes are in

Vulnerability classes we find most often

Across NIS2-scope estates, the same handful of issues keep opening the door. None of them are exotic, which is exactly why attackers rely on them.

Weak or missing multi-factor authentication

The directive calls for MFA, yet we routinely find remote access, admin panels and legacy VPNs where a single stolen password is enough. We test whether phishing one credential actually gets an attacker in.

Flat networks and poor segmentation

When a compromised workstation can reach a control system or a patient database directly, one foothold becomes a full breach. We test how far lateral movement gets before something stops it.

Unpatched and exposed services

Forgotten internet-facing services carrying known CVEs are still the fastest way in. We verify exploitability rather than just flagging a version number.

Supply-chain and remote-access footholds

NIS2 makes supplier security an explicit obligation. We look at the access your vendors and managed service providers hold and what an attacker could reach through it.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you receive

The deliverables are written to two audiences. Leadership needs a clear statement of business risk and regulatory exposure; engineers need enough detail to reproduce and fix each issue.

Executive and technical report

A short summary for the management body, then a full technical report with every finding, its impact, CVSS score, evidence and a concrete remediation step. Findings are cross-referenced to the relevant Article 21 measures so a supervisor sees the connection immediately.

Attestation and retest

An attestation letter you can show clients, insurers and your competent authority, plus a free retest confirming the fixes hold. That retest letter is often what closes the loop for audit.

Why manual testing beats a scanner for NIS2

A vulnerability scanner produces a long list of maybes and misses the things that actually matter under the directive: a business-logic flaw that lets one user act as another, an authentication bypass a scanner cannot recognize, a chain of three low findings that together reach a critical system. Article 21(2)(f) asks you to assess whether your measures are effective. A scanner cannot tell you that; it only tells you what version software is running. A human who has broken into estates like yours can, and will show you the exact path with evidence a regulator accepts.

Which organizations fall under NIS2

NIS2 widened the net considerably compared to the original NIS Directive. If you were not in scope before, you may well be now, and the practical trigger is usually your sector combined with your headcount and turnover.

Essential entities

These include operators in energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure such as data centers and DNS providers, ICT service management, public administration, and space. Larger firms in these sectors generally land here and face the fuller supervisory regime.

Important entities

This category adds sectors like postal services, waste management, chemicals, food, manufacturing of certain products, digital providers such as online marketplaces and search engines, and research. Medium-sized firms in the essential sectors often sit here too. The measures are the same; the supervision is lighter-touch until something goes wrong.

The size and sector test

National transpositions differ in the detail, so the safe move is to check your specific situation against your country’s law. In practice, if you provide one of the listed services and you are medium-sized or larger, you should assume you are in scope and plan your testing accordingly.

When to run a NIS2 test

Timing matters more than firms expect. A test six months before an audit gives you time to fix what it finds; a test the week before does not. There are a few natural triggers.

Before your first supervisory review

Get the technical evidence in place ahead of any interaction with your competent authority, so you are presenting a remediated estate and a clean retest letter rather than a fresh list of open holes.

After significant change

A new customer-facing platform, a cloud migration, a merged business unit or a new critical supplier all change your attack surface. Retesting after material change is part of keeping Article 21 measures effective rather than stale.

On a recurring cycle

An annual test, with a lighter check after major releases, keeps your assurance current and gives the management body a steady record of oversight rather than a one-off snapshot.

Pricing

NIS2 testing is priced by the size of the estate that supports your essential or important service: how many hosts and applications are in scope, whether testing is authenticated, and how much supply-chain surface you want examined. Every engagement is fixed-price after a scoping call.

Engagement What’s included Timeline Price
Focused service test One essential service: external network plus its web application, OWASP coverage, report and free retest 4–6 working days from €3,000
Standard NIS2 test External and internal network, key applications and APIs, access-control and MFA review, Article 21 mapping 6–10 working days €5,000–€12,000
Extended estate Multiple services or sites, segmentation testing, supply-chain and remote-access exposure, attack-chaining 10–15 working days €12,000–€25,000
Attestation package Article 21 gap mapping and an attestation letter for your supervisor, added to any tier with any tier from €900
Custom / multi-entity Group or cross-border operator, scoped after a free call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with the attestation and a retest included. Get a fixed quote

FAQ

How much does a NIS2 penetration test cost?
A focused test of one essential service starts from €3,000, with a standard NIS2 pen test typically running €5,000 to €12,000 depending on how many hosts and applications support your service. You get a fixed quote after a free scoping call.
Does NIS2 actually require a penetration test?
The directive does not name a specific test, but Article 21(2)(f) requires you to assess the effectiveness of your risk-management measures, and independent penetration testing is the standard way to do that. It is also the evidence a supervisor and the management body expect under Articles 20 and 21.
Are you an essential or important entity too, and can you advise which we are?
Classification depends on your sector and size under your national transposition of NIS2. We help you scope the test to the systems behind the service that puts you in scope, whether you are classed as essential or important.
How long does a NIS2 security test take?
A typical NIS2 pen test runs 5 to 8 working days plus the report. If we reach something critical, you hear about it within 48 hours rather than at the end.
What do we get for our auditors and supervisor?
An executive summary, a full technical report with CVSS-scored findings mapped to the Article 21 measures, an attestation letter, and a free retest report once you have fixed the issues.
Will the test affect the availability of our service?
No. We agree any noisy or intrusive checks in advance and can run them out of hours. For operators of critical infrastructure we take extra care, because keeping your essential service running is the whole point.
Do you also test our incident detection?
If you want it, yes. Because NIS2 sets 24-hour and 72-hour reporting deadlines under Article 23, we can run the final stage loudly to check whether your monitoring would actually give you the clock to report in time.
Are the findings kept confidential?
Yes. We work under NDA and handle all evidence and the report through secure channels, sharing results only with the people you nominate.

Related services

Who needs this

Operators of essential and important services across Europe, in sectors such as energy, transport, banking, health, water, digital infrastructure and managed services, that need technical proof their Article 21 measures work and defensible evidence for the management body and their national supervisor.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "NIS2 Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.