Search the full text of Directive (EU) 2022/2555 for "red team" and you get zero hits. Search it for "penetration testing" and you get exactly two. Recital 86 describes managed security service providers as a market entities should select carefully. Recital 87 says competent authorities "may also benefit from cybersecurity services such as security audits, penetration testing or incident responses" in their own supervisory work. Neither imposes a duty on an entity.
So when a consultant, a broker or a customer tells you NIS2 mandates an annual penetration test, they are selling against a control that does not exist. We sell penetration testing, and that is the honest answer. What NIS2 requires is a risk-management system and evidence it works.
The short answer, and the sentence that keeps getting misquoted
Question | Answer | Source |
|---|---|---|
Does NIS2 name penetration testing as a duty? | No | Directive 2022/2555 |
Does NIS2 require red teaming? | No, the phrase never appears | Directive 2022/2555 |
Does NIS2 set a testing frequency? | No | Article 21(2) |
Is security testing ever binding? | Yes, for eleven digital entity types | Reg. 2024/2690, Annex 6.5 |
Does that regulation mandate a pentest? | No, you choose the type | Annex 6.5.2(a) |
Which EU law mandates threat-led testing? | DORA, for identified financial entities | Reg. 2022/2554, Art. 26 |
The misquoted clause is Article 21(2)(f): "policies and procedures to assess the effectiveness of cybersecurity risk-management measures". Vendors read that as "pentest annually". It says you must know whether your controls work, and leaves the method to you.
What Article 21(2) actually says, clause by clause
Article 21(1) requires "appropriate and proportionate technical, operational and organisational measures", judged against the state of the art, cost, the entity's exposure to risk, its size, and the likelihood and severity of incidents. Article 21(2) then says those measures "shall include at least the following":
Point | Requirement | Testing hook |
|---|---|---|
(a) | Risk analysis and information system security policies | Risk basis for scope |
(b) | Incident handling | Exercises |
(c) | Business continuity, backup, disaster recovery, crisis management | Recovery testing |
(d) | Supply chain security | Supplier assurance |
(e) | Security in acquisition, development and maintenance, with vulnerability handling and disclosure | Yes, application testing |
(f) | Procedures to assess effectiveness of measures | Yes, effectiveness evidence |
(g) | Basic cyber hygiene practices and training | No |
(h) | Cryptography and, where appropriate, encryption | No |
(i) | HR security, access control, asset management | Access control |
(j) | MFA or continuous authentication, secured communications | MFA coverage |
Points (e) and (f) are where testing lives; neither names a technique or an interval. Article 21(4) adds that an entity finding itself non-compliant must correct "without undue delay", which makes your findings actionable against you.
Where testing does become binding: Implementing Regulation (EU) 2024/2690
Article 21(5) obliged the Commission to specify technical requirements for a defined set of digital entity types. It did so in Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, in force twenty days after its publication on 18 October 2024.
Article 1 covers DNS providers, TLD name registries, cloud, data centre and content delivery network providers, managed service and managed security service providers, online marketplaces, search engines and social networking platforms, and trust service providers. If you are a hospital, a utility or a manufacturer, it does not apply to you: your obligations come from Article 21 as transposed by your member state.
For covered entities, Annex point 6.5 is binding law:
6.5.1: a security testing policy and procedures.
6.5.2(a): the entity establishes, from its risk assessment, "the need, scope, frequency and type of security tests".
6.5.2(b): a documented methodology "covering the components identified as relevant for secure operation in a risk analysis".
6.5.2(c) and (d): documented type, scope, time and results with criticality per finding, and mitigation of critical ones.
6.5.3: periodic review of the policy.
Point 6.5.2(a) is the crux: the regulation makes testing mandatory, then hands you the pen on need, scope, frequency and type. The word "penetration" appears exactly once in the whole instrument, in recital 15, saying tests "may include automated or manual tests, penetration tests, vulnerability scanning" and other methods. That is a menu in a recital, not a mandate in an annex.
ENISA's technical implementation guidance (June 2025, v1.0) agrees, telling entities to "consider a range of security tests" including penetration testing, bug bounty programmes and red teaming, and "select the most appropriate one (or more)". Its closest thing to a cadence is an indicative suggestion to assess overall effectiveness annually, subordinate to the risk assessment, and the guidance binds nobody.
National transposition divergence: what member states actually added
The market story is that member states bolted testing duties onto NIS2. Checking three transpositions directly, that is not what happened: what they added is conformity assessment, registration and documentation duties.
Member state | Instrument | In force | What it added |
|---|---|---|---|
Belgium | NIS2 Law of 26 April 2024, Royal Decree of 9 June 2024 | 18 October 2024 | Registration by 18 March 2025; conformity assessment against the CCB's CyberFundamentals (CyFun) or ISO/IEC 27001, via accredited bodies |
Germany | NIS-2-Umsetzungsgesetz, amending the BSIG | 6 December 2025 | About 29 500 entities against roughly 4 500 before; registration, BSI incident reporting |
Netherlands | Cyberbeveiligingswet (Cbw) | 15 August 2026 | Around 8 000 organisations; duty of care, incident reporting, NCSC registration |
Belgium is the instructive case. Article 22, §1 of the Royal Decree of 9 June 2024 gives essential entities that chose the certification route 18 months from the NIS2 law entering into force, or from the date they are identified, to obtain a verification at basic or important level of the reference framework the national cybersecurity authority publishes, which is CyFun, or, on the ISO/IEC 27001 route, to file the scope and the statement of applicability. Article 22, §2 then gives them 30 months to hold the certification itself. For an entity in scope since 18 October 2024, that is 18 April 2026 and 18 April 2027. Article 15, §1 requires the assessing body to hold accreditation from a national accreditation body before the authority approves it. That is a real, dated, externally verified obligation, and an audit duty rather than a penetration testing one.
Transposition is still incomplete: on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposing measures, asking for a lump sum and daily penalties; the deadline was 17 October 2024. Your obligation is therefore a per-country question. See our guides for the Netherlands and Germany.
Essential vs important entities: the difference is supervision, not testing
Both classes owe the same Article 21 measures. What changes is how hard the state can push, and how early.
Essential (Article 32) | Important (Article 33) | |
|---|---|---|
Supervision model | Ex ante and ex post | Ex post only, on evidence of non-compliance |
Security audits | "Regular and targeted" | "Targeted" only |
Ad hoc audits | Yes, explicitly | Not listed |
Security scans | Yes | Yes |
Who pays for a targeted audit | The audited entity, unless the authority decides otherwise | Same |
Suspend certification | Yes, Article 32(5)(a) | Not available |
Ban the CEO from managerial functions | Yes, Article 32(5)(b) | Not available |
Maximum fine (Article 34) | At least EUR 10 000 000 or 2 % of worldwide turnover | At least EUR 7 000 000 or 1,4 % |
Two rows should change how you budget. Article 32(2)(b) lets an authority order a targeted security audit carried out by an independent body, and Article 32(2) makes the cost payable by the audited entity, "except in duly substantiated cases when the competent authority decides otherwise". Those targeted audits must rest on a risk assessment, and the article accepts one "conducted by the competent authority or the audited entity", so your own documented risk work is what keeps the scope recognisable rather than imposed. And Article 32(5)(b) lets an authority have a chief executive or legal representative temporarily barred from managerial functions, a power NIS2 reserves for essential entities alone.
Management liability under Article 20, and why leadership cares
Article 20(1) requires member states to ensure management bodies approve the cybersecurity risk-management measures, oversee implementation, and can be held liable for the entity's Article 21 infringements. Article 20(2) requires those members to follow training so they can identify risks and assess cybersecurity practices.
A director signing off an Article 21 programme is signing off a claim about effectiveness, and Article 21(2)(f) says that claim must be backed by procedures that test it. Article 35 adds that where an Article 21 infringement can entail a personal data breach, the authority must inform the GDPR supervisory authority: one weak control, two regulators.
NIS2 vs DORA: which one actually mandates threat-led testing
If you have been told NIS2 requires red teaming, the requirement you are thinking of is in DORA, Regulation (EU) 2022/2554, and it binds financial entities only.
NIS2 (2022/2555) | DORA (2022/2554) | |
|---|---|---|
Names penetration testing as a duty | No | Yes, Article 25(1) |
Names red team testing | No | Yes, Article 27(1)(b) |
General testing cadence | None | Article 24(6): at least yearly on systems supporting critical functions |
Threat-led cadence | None | Article 26(1): TLPT at least every 3 years |
Who is bound by TLPT | Nobody | Only entities identified under Article 26(8) |
Test environment | Not specified | Article 26(2): live production |
Regulator sign-off | No | Article 26(7): attestation, mutually recognised |
Two details matter. Article 26(8) has competent authorities identify which entities must perform TLPT, based on impact, financial stability and ICT risk profile, so DORA scope is not TLPT scope. And Article 27(1)(c) requires testers "certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks", which is where firm-level accreditation earns its keep.
More in DORA threat-led penetration testing, TIBER, CBEST and DORA TLPT compared, the global TLPT frameworks reference, and does CMMC require penetration testing for the US equivalent.
What to buy: a defensible testing programme for a NIS2 entity
Because the law is risk-based, the defensible position is a documented decision, not a receipt. Write five things into your policy.
The risk basis. Point to the Article 21(2)(a) risk assessment and name the systems whose compromise would produce a significant incident.
Test type per asset class. Internet-facing web applications and APIs earn manual testing, because authorization and business logic are not reachable by scanners. Incident handling earns exercises, which ENISA treats at 3.1.3.
Frequency, and its justification. You are choosing it: rate of change, exposure, incident history, criticality. Release-gated testing is easiest to defend for weekly-shipping systems.
The remediation loop. Annex 6.5.2(c) and (d) require criticality and mitigating actions per finding, and Article 21(4) requires correction without undue delay. A report with no retest closes nothing.
The effectiveness link. Recital 15 says findings "should inform" the effectiveness assessment, so route them into your Article 21(2)(f) file.
Stingrai is a CREST-accredited penetration testing service provider at firm level, and our testers hold CREST CRT. On the application layer, Snipe, our autonomous web application agent, runs black-box dynamic testing and white-box source review, hunts complex classes such as IDOR, broken authorization and business logic flaws, and produces AutoFix pull requests and pull-request gating, so remediation and retest evidence accumulate continuously. Hybrid engagements add human validation of every finding. Autonomous starts at US$3,000 one-time or US$450 per month, hybrid at US$6,800 or US$1,275 per month on a twelve-month engagement; see pricing. Both carry our "No High or Critical Finding = Don't Pay" guarantee. Network, cloud and social engineering sits with our human team.
Evidence pack: what a national supervisory authority will ask to see
Answer Article 32(2)(e), (f) and (g) directly.
Artefact | Maps to | Why it is asked for |
|---|---|---|
Security testing policy and procedures | Annex 6.5.1 | Must exist in writing |
Risk assessment linking assets to scope | Annex 6.5.2(a) | Scope derived, not guessed |
Documented test methodology | Annex 6.5.2(b) | Separates a test from a scan |
Reports with dates, scope, criticality | Annex 6.5.2(c) | Article 32(2)(g) evidence |
Remediation and retest records | Annex 6.5.2(d), Article 21(4) | Shows the loop closed |
Effectiveness policy, KPIs and results | Article 21(2)(f), Annex 7 | Most cited, least evidenced |
Management approval and training records | Article 20(1), 20(2) | Directors in scope |
Record the scope statement of every test, including what was not tested and why: a supervisor comparing your asset inventory against your test scope will find the gap anyway. And keep the raw artefacts: Article 32(2)(g) asks for "the respective underlying evidence", not the summary. See also pentest evidence auditors accept and compliance-driven testing.
Frequently Asked Questions
Does NIS2 require an annual penetration test?
No. Directive (EU) 2022/2555 sets no testing frequency, and "penetration testing" appears only in recitals 86 and 87: recital 86 describes managed security service providers, and recital 87 describes services competent authorities may themselves use in supervision, neither imposing a duty on an entity. For the eleven digital entity types covered by Commission Implementing Regulation (EU) 2024/2690, security testing is binding, but Annex point 6.5.2(a) has the entity itself set the need, scope, frequency and type of tests from its own risk assessment.
What does NIS2 Article 21 require?
Article 21(1) requires appropriate and proportionate technical, operational and organisational measures, judged against the state of the art, cost, exposure, entity size, and the likelihood and severity of incidents. Article 21(2) then lists ten minimum categories, points (a) through (j), from risk analysis policies and incident handling through supply chain security and secure development to multi-factor authentication. None of the ten names a test type or a frequency.
Does NIS2 require red teaming?
No. The phrase "red team" appears nowhere in Directive (EU) 2022/2555, nor in Commission Implementing Regulation (EU) 2024/2690. ENISA's non-binding guidance of June 2025 mentions red teaming as one option among many an entity may consider. Mandatory threat-led red teaming in EU law comes from DORA Article 26, not NIS2.
What is the difference between NIS2 and DORA testing requirements?
NIS2 names no test type and sets no cadence. DORA does both: Article 24(6) requires at least yearly testing of ICT systems supporting critical or important functions, and Article 26(1) requires threat-led penetration testing at least every three years on live production. Article 26(8) has competent authorities identify which financial entities must perform TLPT, so DORA scope does not equal TLPT scope.
Are essential entities required to do more testing than important entities?
No, both owe identical Article 21 measures. The difference is supervision: Article 32 allows ex ante supervision of essential entities including regular, targeted and ad hoc security audits, while Article 33 limits important entities to ex post supervision on evidence of non-compliance. Article 32(5) also reserves powers for essential entities alone, including suspending a certification and barring a chief executive from managerial functions.
What evidence do NIS2 supervisors ask for?
Article 32(2)(g) allows requests for "evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence", alongside documented policies under 32(2)(e). In practice: the testing policy, the risk assessment that set scope, the methodology, dated reports with criticality per finding, remediation records, and management approval records.
Which countries have transposed NIS2 with explicit testing requirements?
Checking Belgium, Germany and the Netherlands directly, none of the three added an explicit penetration testing mandate. Belgium added a conformity assessment regime instead: Article 22, §1 of its Royal Decree of 9 June 2024 gives essential entities on the certification route 18 months from the law entering into force to obtain a verification at basic or important level of the CyFun framework, which is 18 April 2026 for entities in scope since 18 October 2024, with certification due at 30 months. Germany's NIS-2-Umsetzungsgesetz took effect on 6 December 2025, and the Dutch Cyberbeveiligingswet takes effect on 15 August 2026.
Can directors be held personally liable under NIS2?
Yes. Article 20(1) requires member states to ensure that management bodies of essential and important entities approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity's infringements of Article 21. Article 20(2) requires those members to follow training so they can identify risks and assess cybersecurity practices. For essential entities, Article 32(5)(b) additionally lets authorities request a temporary ban on a chief executive or legal representative from exercising managerial functions.
References
Directive (EU) 2022/2555 (NIS2), EUR-Lex. Articles 20, 21, 32 to 35; recitals 86, 87.
Commission Implementing Regulation (EU) 2024/2690, EUR-Lex. Article 1, Annex 6.5 and 7, recital 15.
ENISA Technical Implementation Guidance, June 2025, v1.0. Non-binding.
Regulation (EU) 2022/2554 (DORA), EUR-Lex. Articles 24 to 27.
Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice, 8 July 2026, and NIS2 transposition in EU countries, European Commission.
NIS-2-Umsetzungsgesetz in Kraft, BSI, 5 December 2025.
Cyberbeveiligingswet vanaf 15 augustus 2026, Rijksoverheid, 7 July 2026.
Royal Decree of 9 June 2024 implementing the Belgian NIS2 Law of 26 April 2024, Justel, Belgian Official Journal. Articles 4, 5, 15 and 22.



