NIS2 compliance

Does NIS2 require penetration testing?

Short answer: Not by name. NIS2 Article 21(2)(f) asks for policies and procedures to assess whether your cybersecurity measures work. Implementing Regulation (EU) 2024/2690 requires cloud, managed-service and other digital providers to run documented security tests and fix critical findings. A penetration test is a common way to show that. Source: EUR-Lex, checked 2026-09-26.

A customer's security questionnaire lands with a new line: "Describe how you test the effectiveness of your security measures under NIS2." Or the board wants to know if the company is now in scope. Behind both sits one question. Does the law make you run a pentest, and what do you have to keep?

Applies 2026

  • National NIS2 laws are in force in Sweden (since 2026-01-15), Germany (promulgated 2025-12-05), the Netherlands (since 2026-08-15), Finland (since 2025-04-08) and Denmark (since 2025-07-01). France's law is still pending.
  • Implementing Regulation (EU) 2024/2690 has set the technical rules for cloud, managed-service and other digital providers since 2024.
  • Sweden's rules on security measures, MCFFS 2026:11, apply from 2026-10-01.

Checked on 2026-09-26. Sources are listed at the end of the page.

What does NIS2 actually say about testing?

Directive (EU) 2022/2555, known as NIS2, lists ten minimum risk-management measures in Article 21(2). Three of them decide what you test and show:

  • 21(2)(f): "policies and procedures to assess the effectiveness of cybersecurity risk-management measures".
  • 21(2)(e): security in how you acquire, develop and maintain systems, including vulnerability handling and disclosure.
  • 21(2)(d): supply chain security, including your relationships with direct suppliers and service providers.

No article of NIS2 names penetration testing. The term only shows up in the recitals, for example where managed security service providers are described as offering it. Recitals explain a law. They don't create duties.

So NIS2 asks you to check that your measures work and to prove it. How you check is up to you and your risk assessment. Source: NIS2 on EUR-Lex, checked 2026-09-26.

What does Implementing Regulation 2024/2690 require?

For some digital providers the EU wrote the details down. Implementing Regulation (EU) 2024/2690 applies to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms and trust service providers. Its Annex is binding. ENISA's guidance on it is not.

Annex point (binding)What it saysWhat ENISA's guidance adds (not binding)Evidence to keep
6.5.1Establish, implement and apply a policy and procedures for security testingExamples of what a testing policy coversA written security testing policy
6.5.2(a)Set the need, scope, frequency and type of security tests, based on your risk assessmentConsider a range of tests, for example vulnerability assessments, penetration testing and code reviewThe risk assessment and the test plan that follows from it
6.5.2(b)Run tests under a documented test methodology, covering the components relevant for secure operationContinuous testing, especially where you ship through CI/CDThe named methodology and the scope of each test
6.5.2(c)Document the type, scope, time and results of each test, including criticality and mitigating actions for each findingTest reports, pentest reports among them, as examples of evidenceDated reports with findings, severity and planned fixes
6.5.2(d)Apply mitigating actions for critical findingsFix records and a retest that shows the finding is closed
6.5.3Review the testing policy at planned intervals and update it where neededReview dates and changes to the policy
6.10.2(b)Where appropriate, run vulnerability scans at planned intervals and record the resultsScan history
7.1A policy and procedures to assess whether your risk-management measures are effectively implemented and maintained (Art. 21(2)(f))Lists penetration testing among the assessment methodsAssessment results and what you changed because of them

Annex wording from EUR-Lex, guidance from ENISA's Technical Implementation Guidance v1.0 (June 2025). Both checked 2026-09-26.

One detail the table can't show: recital 15 of the Regulation says security tests "may include automated or manual tests, penetration tests, vulnerability scanning, static and dynamic application security tests, configuration tests or security audits". That's the only place the Regulation mentions pentests, and a recital isn't a duty. The Annex asks for a documented method and documented results, and leaves the type of test to your risk assessment.

Is my SaaS company in scope?

Possibly. It turns on your size, your sector and your country's registration rules. SaaS is named in recital 33 of NIS2 as one of the cloud computing service models (with IaaS, PaaS and NaaS), and cloud computing service providers sit in the digital infrastructure sector of Annex I. Whether your product counts as a cloud computing service is a call for you and your national authority.

QuestionIf yesSource
Are you at least a medium-sized enterprise? That means 50 or more staff, or annual turnover and balance sheet both above €10M. Partner and linked companies count togetherSize doesn't exclude you. Most covered sectors only include medium and larger companies. Some providers, such as DNS service providers, TLD registries and qualified trust service providers, are covered whatever their sizeNIS2 Art. 2 and recital 7, Recommendation 2003/361/EC
Is your service a cloud computing service, B2B ICT service management (managed services) or a digital provider (marketplace, search engine, social network)?You're likely in scope directly, and the detailed rules in Implementing Regulation 2024/2690 apply to youNIS2 Annex I and II, recital 33, Reg. 2024/2690 Art. 1
Do you sell to banks, hospitals, energy firms, public bodies or other covered entities?You're in scope through your customers, even if you're below the size threshold. They must secure their supply chain and will ask you for evidenceNIS2 Art. 21(2)(d) and 21(3)
None of the above?Probably out of scope, but expect the questionnaire anyway once your customers grow

Register with your national authority if you think you're covered, and ask them when in doubt. Sources checked 2026-09-26.

Your customers' NIS2 duty becomes your questionnaire

Article 21(2)(d) makes supply chain security one of the minimum measures. Article 21(3) tells covered entities to take into account the vulnerabilities of each direct supplier, the quality of their products and their cybersecurity practices, including secure development. In practice that reaches a SaaS supplier as a security questionnaire, a contract clause, or a request for a recent test report. What to send back is covered in your customer asked for a pentest report.

Sweden writes it down more plainly than most. From 2026-10-01, MCFFS 2026:11 (4 kap. 1 §) says a covered entity must make sure its suppliers meet the rule's security requirements, check that they can do so for the whole contract term, and supplement contracts signed before that date. See the Sweden section below.

Where your data is processed is part of that review. For Barrion itself: customer data is stored and hosted in Sweden, and AI processing runs in the EU. The full subprocessor list is on the trust page.

How often do you need to test under NIS2?

NIS2 and 2024/2690 set no number. The frequency comes from your risk assessment (6.5.2(a)). Recital 15 of the Regulation suggests testing at set-up, after upgrades or changes you deem significant, and after maintenance. ENISA recommends continuous testing for teams that ship through CI/CD. Some national rules add a floor: in Sweden, sector-critical systems need follow-up at least once a year (MCFFS 2026:11, 3 kap. 19 §). For how NIS2 compares with PCI DSS, DORA and SOC 2, see how often to pentest.

NIS2 by country

Each member state writes NIS2 into its own law, with its own authority and registration rules.

CountryLawStatusAuthoritySource
SwedenCybersäkerhetslag (2025:1506) and cybersäkerhetsförordning (2025:1507)In force since 2026-01-15Sector authorities, PTS for digital infrastructure and ICT services. FRA's NCSC writes the rules since 2026-07-01SFS 2025:1506
GermanyNIS2 implementation act (NIS2UmsuCG), BGBl. 2025 I Nr. 301Promulgated 2025-12-05BSIBundesgesetzblatt
NetherlandsCyberbeveiligingswet (Cbw)In force since 2026-08-15Registration with NCSC-NL, sector supervisorsRijksoverheid
FinlandKyberturvallisuuslaki (124/2025)In force since 2025-04-08Traficom and sector authoritiesFinlex
DenmarkNIS 2-lovenIn force since 2025-07-01Styrelsen for Samfundssikkerhed and sector authoritiesStyrelsen for Samfundssikkerhed
FranceProjet de loi résilience (transposes NIS2, CER and DORA)Not yet adoptedANSSIANSSI, MonEspaceNIS2

Every row checked 2026-09-26.

Sweden

Sweden's Cybersäkerhetslag (2025:1506) has applied since 2026-01-15. Chapter 2, section 3 asks for appropriate and proportionate measures, including procedures to assess how effective they are, which mirrors Article 21(2)(f).

The detailed rules are in MCFFS 2026:11, which applies from 2026-10-01. Its 4 kap. 27 § on security tests and reviews says tests must check that systems run the latest approved version, that published vulnerabilities are handled, and that the chosen configuration is in place. The general advice adds that an established test methodology should be used for both automated and manual security tests. None of this uses the word penetration test.

There's a carve-out that matters for SaaS. Entities that only work in digital infrastructure, digital providers or B2B ICT service management follow Implementing Regulation 2024/2690 under PTS instead. For them, MCFFS 2026:11 only covers management training (1 kap. 1 §). Sources: SFS 2025:1506, MCFFS 2026:11, checked 2026-09-26.

What NIS2 fines apply?

Article 34 sets a floor for the maximum fine. For essential entities the cap must be at least €10M or 2% of worldwide annual turnover, whichever is higher. For important entities it's at least €7M or 1.4%. National laws set the exact figures. Article 20 makes management bodies approve the risk-management measures, oversee them and answer for failures.

Fines target failures to put the Article 21 measures in place and to govern them. There's no fine for a missing pentest as such. What an authority looks for is a testing policy, tests run to a method, and a record of what you fixed.

How Barrion produces evidence that supports Article 21(2)(f)

Barrion's AI agents test web apps and APIs the way an attacker would, across 8 testing areas mapped to all 97 OWASP WSTG v4.2 test cases. The result is documented test evidence that supports the 6.5.2(b) requirement to test to a documented method. You approve the scope before any traffic is sent, and runs are rate-limited and non-destructive. You can point them at staging instead of production.

Each report lists findings with severity. Findings are checked against the live app before they're reported: confirmed ones come with the request and response, and unconfirmed ones are kept as lower-confidence leads. That covers the type, scope, time and results 6.5.2(c) asks you to document. Retests of the issues a pentest found are free, and the report then shows the fix, which is the evidence for 6.5.2(d). From Standard level up a security engineer reviews the findings.

Pentests can rerun on a schedule, and each run labels earlier findings new, still open, resolved or regressed. Change detection watches the start page's links and scripts, so a backend-only release can slip past it. Keep at least one schedule that runs every time.

What Barrion doesn't cover. Barrion tests web apps and APIs only. NIS2 also asks for incident handling, business continuity, cryptography policy, access control, staff training and more. Barrion doesn't test internal networks, Active Directory, mobile apps, physical security or people. Barrion isn't a NIS2 certification or an audit.

Related reading: what a pentest costs, pentesting for growing SaaS companies, ISO 27001 evidence (ISO 27001 is a common route teams use to organise NIS2 work), audit-ready security and what continuous pentesting is.

Pentest evidence

Testing evidence for NIS2.

Annex 6.5.2 of Regulation 2024/2690 asks for tests run to a documented method, dated results with criticality, and fixes for critical findings. A pentest report with a retest is a common way to show all of that.

Report

Mapped to OWASP WSTG

Each AI pentest report comes as PDF, XLSX and JSON with an OWASP WSTG coverage matrix. Your auditor sees what was tested, not only what was found.
Review

A security engineer reviews

From Standard up a security engineer reviews the findings. Deeper tests come with a report signed off by that engineer.
Retest

Free retests show the fix

Retesting the issues a pentest found costs nothing. The evidence then shows the finding and the fix, which is the part auditors ask about next.
Continuous

Testing that keeps running

The pentest reruns on a schedule or on demand. Each run labels earlier findings as new, still open, resolved or regressed.

Findings are checked against your live app before they're reported. Confirmed ones come with the request and response, and unconfirmed ones are kept as lower-confidence leads. It's evidence that supports your NIS2 work, not a certification.

Sources

All sources checked 2026-09-26. Next review by 2026-12-26.

FAQ

NIS2 testing, answered.

Does NIS2 require a penetration test?
Not by name. No NIS2 article mentions penetration testing. Article 21(2)(f) asks for procedures to assess whether your security measures work, and for digital providers Implementing Regulation 2024/2690 (Annex 6.5) requires documented security tests with results and fixes. A pentest is a common way to meet that testing requirement.
Is a SaaS company covered by NIS2?
Possibly. Recital 33 of NIS2 names SaaS as a cloud computing service model, and cloud computing service providers are in the digital infrastructure sector. Most sectors only cover medium-sized and larger companies: 50 or more staff, or turnover and balance sheet both above €10M. Check your country's registration rules and ask your national authority.
How often does NIS2 require security testing?
No fixed interval. Implementing Regulation 2024/2690 asks you to set the frequency from your risk assessment, and its recital 15 suggests testing after changes you deem significant. ENISA recommends continuous testing where you ship through CI/CD. Sweden's MCFFS 2026:11 (3 kap. 19 §) sets follow-up at least once a year for sector-critical systems.
Is an automated or AI pentest enough for NIS2?
The Annex asks for a documented test methodology and documented results, not a type of test. Recital 15 of Regulation 2024/2690 lists automated and manual tests and penetration tests as options. Your risk assessment decides what's enough, and your authority or auditor makes the call. Barrion's reports follow OWASP WSTG v4.2 and, from Standard up, a security engineer reviews the findings.
We're below the size threshold. Why are customers asking about NIS2?
Because they have to secure their supply chain. Article 21(2)(d) and 21(3) make covered entities look at their direct suppliers' security practices. In Sweden, MCFFS 2026:11 (4 kap. 1 §) goes further from 2026-10-01: covered entities must make sure suppliers meet the rule's requirements and supplement older contracts.
What should a NIS2 test report contain?
Annex 6.5.2(c) of Regulation 2024/2690 lists it: the type, scope, time and results of the test, with an assessment of criticality and the mitigating action for each finding. Add the methodology you used and a retest that shows critical findings were fixed, since 6.5.2(d) asks you to act on them.
What are the NIS2 fines?
Article 34 sets a floor for the maximum fine. For essential entities the cap must be at least €10M or 2% of worldwide annual turnover, whichever is higher. For important entities it's at least €7M or 1.4%. National laws set the exact figures, and under Article 20 management bodies can be held liable.

Build a NIS2 testing program.

Tell us your apps, APIs and release pace. We'll scope a pentest program on the Business plan that keeps your test evidence current, and price it for your setup.