Short answer: Not by name. NIS2 Article 21(2)(f) asks for policies and procedures to assess whether your cybersecurity measures work. Implementing Regulation (EU) 2024/2690 requires cloud, managed-service and other digital providers to run documented security tests and fix critical findings. A penetration test is a common way to show that. Source: EUR-Lex, checked 2026-09-26.
A customer's security questionnaire lands with a new line: "Describe how you test the effectiveness of your security measures under NIS2." Or the board wants to know if the company is now in scope. Behind both sits one question. Does the law make you run a pentest, and what do you have to keep?
Applies 2026
- National NIS2 laws are in force in Sweden (since 2026-01-15), Germany (promulgated 2025-12-05), the Netherlands (since 2026-08-15), Finland (since 2025-04-08) and Denmark (since 2025-07-01). France's law is still pending.
- Implementing Regulation (EU) 2024/2690 has set the technical rules for cloud, managed-service and other digital providers since 2024.
- Sweden's rules on security measures, MCFFS 2026:11, apply from 2026-10-01.
Checked on 2026-09-26. Sources are listed at the end of the page.
What does NIS2 actually say about testing?
Directive (EU) 2022/2555, known as NIS2, lists ten minimum risk-management measures in Article 21(2). Three of them decide what you test and show:
- 21(2)(f): "policies and procedures to assess the effectiveness of cybersecurity risk-management measures".
- 21(2)(e): security in how you acquire, develop and maintain systems, including vulnerability handling and disclosure.
- 21(2)(d): supply chain security, including your relationships with direct suppliers and service providers.
No article of NIS2 names penetration testing. The term only shows up in the recitals, for example where managed security service providers are described as offering it. Recitals explain a law. They don't create duties.
So NIS2 asks you to check that your measures work and to prove it. How you check is up to you and your risk assessment. Source: NIS2 on EUR-Lex, checked 2026-09-26.
What does Implementing Regulation 2024/2690 require?
For some digital providers the EU wrote the details down. Implementing Regulation (EU) 2024/2690 applies to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms and trust service providers. Its Annex is binding. ENISA's guidance on it is not.
| Annex point (binding) | What it says | What ENISA's guidance adds (not binding) | Evidence to keep |
|---|---|---|---|
| 6.5.1 | Establish, implement and apply a policy and procedures for security testing | Examples of what a testing policy covers | A written security testing policy |
| 6.5.2(a) | Set the need, scope, frequency and type of security tests, based on your risk assessment | Consider a range of tests, for example vulnerability assessments, penetration testing and code review | The risk assessment and the test plan that follows from it |
| 6.5.2(b) | Run tests under a documented test methodology, covering the components relevant for secure operation | Continuous testing, especially where you ship through CI/CD | The named methodology and the scope of each test |
| 6.5.2(c) | Document the type, scope, time and results of each test, including criticality and mitigating actions for each finding | Test reports, pentest reports among them, as examples of evidence | Dated reports with findings, severity and planned fixes |
| 6.5.2(d) | Apply mitigating actions for critical findings | Fix records and a retest that shows the finding is closed | |
| 6.5.3 | Review the testing policy at planned intervals and update it where needed | Review dates and changes to the policy | |
| 6.10.2(b) | Where appropriate, run vulnerability scans at planned intervals and record the results | Scan history | |
| 7.1 | A policy and procedures to assess whether your risk-management measures are effectively implemented and maintained (Art. 21(2)(f)) | Lists penetration testing among the assessment methods | Assessment results and what you changed because of them |
Annex wording from EUR-Lex, guidance from ENISA's Technical Implementation Guidance v1.0 (June 2025). Both checked 2026-09-26.
One detail the table can't show: recital 15 of the Regulation says security tests "may include automated or manual tests, penetration tests, vulnerability scanning, static and dynamic application security tests, configuration tests or security audits". That's the only place the Regulation mentions pentests, and a recital isn't a duty. The Annex asks for a documented method and documented results, and leaves the type of test to your risk assessment.
Is my SaaS company in scope?
Possibly. It turns on your size, your sector and your country's registration rules. SaaS is named in recital 33 of NIS2 as one of the cloud computing service models (with IaaS, PaaS and NaaS), and cloud computing service providers sit in the digital infrastructure sector of Annex I. Whether your product counts as a cloud computing service is a call for you and your national authority.
| Question | If yes | Source |
|---|---|---|
| Are you at least a medium-sized enterprise? That means 50 or more staff, or annual turnover and balance sheet both above €10M. Partner and linked companies count together | Size doesn't exclude you. Most covered sectors only include medium and larger companies. Some providers, such as DNS service providers, TLD registries and qualified trust service providers, are covered whatever their size | NIS2 Art. 2 and recital 7, Recommendation 2003/361/EC |
| Is your service a cloud computing service, B2B ICT service management (managed services) or a digital provider (marketplace, search engine, social network)? | You're likely in scope directly, and the detailed rules in Implementing Regulation 2024/2690 apply to you | NIS2 Annex I and II, recital 33, Reg. 2024/2690 Art. 1 |
| Do you sell to banks, hospitals, energy firms, public bodies or other covered entities? | You're in scope through your customers, even if you're below the size threshold. They must secure their supply chain and will ask you for evidence | NIS2 Art. 21(2)(d) and 21(3) |
| None of the above? | Probably out of scope, but expect the questionnaire anyway once your customers grow |
Register with your national authority if you think you're covered, and ask them when in doubt. Sources checked 2026-09-26.
Your customers' NIS2 duty becomes your questionnaire
Article 21(2)(d) makes supply chain security one of the minimum measures. Article 21(3) tells covered entities to take into account the vulnerabilities of each direct supplier, the quality of their products and their cybersecurity practices, including secure development. In practice that reaches a SaaS supplier as a security questionnaire, a contract clause, or a request for a recent test report. What to send back is covered in your customer asked for a pentest report.
Sweden writes it down more plainly than most. From 2026-10-01, MCFFS 2026:11 (4 kap. 1 §) says a covered entity must make sure its suppliers meet the rule's security requirements, check that they can do so for the whole contract term, and supplement contracts signed before that date. See the Sweden section below.
Where your data is processed is part of that review. For Barrion itself: customer data is stored and hosted in Sweden, and AI processing runs in the EU. The full subprocessor list is on the trust page.
How often do you need to test under NIS2?
NIS2 and 2024/2690 set no number. The frequency comes from your risk assessment (6.5.2(a)). Recital 15 of the Regulation suggests testing at set-up, after upgrades or changes you deem significant, and after maintenance. ENISA recommends continuous testing for teams that ship through CI/CD. Some national rules add a floor: in Sweden, sector-critical systems need follow-up at least once a year (MCFFS 2026:11, 3 kap. 19 §). For how NIS2 compares with PCI DSS, DORA and SOC 2, see how often to pentest.
NIS2 by country
Each member state writes NIS2 into its own law, with its own authority and registration rules.
| Country | Law | Status | Authority | Source |
|---|---|---|---|---|
| Sweden | Cybersäkerhetslag (2025:1506) and cybersäkerhetsförordning (2025:1507) | In force since 2026-01-15 | Sector authorities, PTS for digital infrastructure and ICT services. FRA's NCSC writes the rules since 2026-07-01 | SFS 2025:1506 |
| Germany | NIS2 implementation act (NIS2UmsuCG), BGBl. 2025 I Nr. 301 | Promulgated 2025-12-05 | BSI | Bundesgesetzblatt |
| Netherlands | Cyberbeveiligingswet (Cbw) | In force since 2026-08-15 | Registration with NCSC-NL, sector supervisors | Rijksoverheid |
| Finland | Kyberturvallisuuslaki (124/2025) | In force since 2025-04-08 | Traficom and sector authorities | Finlex |
| Denmark | NIS 2-loven | In force since 2025-07-01 | Styrelsen for Samfundssikkerhed and sector authorities | Styrelsen for Samfundssikkerhed |
| France | Projet de loi résilience (transposes NIS2, CER and DORA) | Not yet adopted | ANSSI | ANSSI, MonEspaceNIS2 |
Every row checked 2026-09-26.
Sweden
Sweden's Cybersäkerhetslag (2025:1506) has applied since 2026-01-15. Chapter 2, section 3 asks for appropriate and proportionate measures, including procedures to assess how effective they are, which mirrors Article 21(2)(f).
The detailed rules are in MCFFS 2026:11, which applies from 2026-10-01. Its 4 kap. 27 § on security tests and reviews says tests must check that systems run the latest approved version, that published vulnerabilities are handled, and that the chosen configuration is in place. The general advice adds that an established test methodology should be used for both automated and manual security tests. None of this uses the word penetration test.
There's a carve-out that matters for SaaS. Entities that only work in digital infrastructure, digital providers or B2B ICT service management follow Implementing Regulation 2024/2690 under PTS instead. For them, MCFFS 2026:11 only covers management training (1 kap. 1 §). Sources: SFS 2025:1506, MCFFS 2026:11, checked 2026-09-26.
What NIS2 fines apply?
Article 34 sets a floor for the maximum fine. For essential entities the cap must be at least €10M or 2% of worldwide annual turnover, whichever is higher. For important entities it's at least €7M or 1.4%. National laws set the exact figures. Article 20 makes management bodies approve the risk-management measures, oversee them and answer for failures.
Fines target failures to put the Article 21 measures in place and to govern them. There's no fine for a missing pentest as such. What an authority looks for is a testing policy, tests run to a method, and a record of what you fixed.
How Barrion produces evidence that supports Article 21(2)(f)
Barrion's AI agents test web apps and APIs the way an attacker would, across 8 testing areas mapped to all 97 OWASP WSTG v4.2 test cases. The result is documented test evidence that supports the 6.5.2(b) requirement to test to a documented method. You approve the scope before any traffic is sent, and runs are rate-limited and non-destructive. You can point them at staging instead of production.
Each report lists findings with severity. Findings are checked against the live app before they're reported: confirmed ones come with the request and response, and unconfirmed ones are kept as lower-confidence leads. That covers the type, scope, time and results 6.5.2(c) asks you to document. Retests of the issues a pentest found are free, and the report then shows the fix, which is the evidence for 6.5.2(d). From Standard level up a security engineer reviews the findings.
Pentests can rerun on a schedule, and each run labels earlier findings new, still open, resolved or regressed. Change detection watches the start page's links and scripts, so a backend-only release can slip past it. Keep at least one schedule that runs every time.
What Barrion doesn't cover. Barrion tests web apps and APIs only. NIS2 also asks for incident handling, business continuity, cryptography policy, access control, staff training and more. Barrion doesn't test internal networks, Active Directory, mobile apps, physical security or people. Barrion isn't a NIS2 certification or an audit.
Related reading: what a pentest costs, pentesting for growing SaaS companies, ISO 27001 evidence (ISO 27001 is a common route teams use to organise NIS2 work), audit-ready security and what continuous pentesting is.