main logo icon

Published on

August 7, 2026

|

12 min read

Does NIS2 Require Penetration Testing or Red Teaming? What Article 21 Actually Says

NIS2 never mandates a penetration test or red teaming. What Article 21(2) requires, where Implementing Regulation (EU) 2024/2690 makes security testing binding, how Belgium, Germany and the Netherlands transposed it, and what supervisors ask to see.

Arafat Afzalzada

Arafat Afzalzada

Founder

AdvisoriesNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The phrase "red team" appears zero times in Directive (EU) 2022/2555, and "penetration testing" appears only twice: recital 86 describes managed security service providers, and recital 87 describes services competent authorities may themselves use, never as a duty owed by an entity. Article 21(2) lists ten categories of measure, points (a) through (j), and not one of them names a test type or sets a testing frequency. Commission Implementing Regulation (EU) 2024/2690 does make security testing binding, but only for eleven digital entity types, and Annex point 6.5.2(a) leaves the need, scope, frequency and type of tests to the entity's own risk assessment. The word "penetration" appears exactly once in that Implementing Regulation, in recital 15, inside a permissive list of test types entities may choose from. Essential and important entities owe identical Article 21 measures; the real difference is supervision, since Article 32 allows regular ex ante audits of essential entities while Article 33 limits important entities to ex post supervision. Article 34 sets maximum fines of at least EUR 10 000 000 or 2 % of worldwide annual turnover for essential entities, and at least EUR 7 000 000 or 1,4 % for important entities, whichever is higher. Threat-led penetration testing is a DORA obligation rather than a NIS2 one: DORA Article 26 requires TLPT at least every three years, and only for financial entities that competent authorities identify under Article 26(8).

Search the full text of Directive (EU) 2022/2555 for "red team" and you get zero hits. Search it for "penetration testing" and you get exactly two. Recital 86 describes managed security service providers as a market entities should select carefully. Recital 87 says competent authorities "may also benefit from cybersecurity services such as security audits, penetration testing or incident responses" in their own supervisory work. Neither imposes a duty on an entity.

So when a consultant, a broker or a customer tells you NIS2 mandates an annual penetration test, they are selling against a control that does not exist. We sell penetration testing, and that is the honest answer. What NIS2 requires is a risk-management system and evidence it works.

The short answer, and the sentence that keeps getting misquoted

Question

Answer

Source

Does NIS2 name penetration testing as a duty?

No

Directive 2022/2555

Does NIS2 require red teaming?

No, the phrase never appears

Directive 2022/2555

Does NIS2 set a testing frequency?

No

Article 21(2)

Is security testing ever binding?

Yes, for eleven digital entity types

Reg. 2024/2690, Annex 6.5

Does that regulation mandate a pentest?

No, you choose the type

Annex 6.5.2(a)

Which EU law mandates threat-led testing?

DORA, for identified financial entities

Reg. 2022/2554, Art. 26

The misquoted clause is Article 21(2)(f): "policies and procedures to assess the effectiveness of cybersecurity risk-management measures". Vendors read that as "pentest annually". It says you must know whether your controls work, and leaves the method to you.

What Article 21(2) actually says, clause by clause

Article 21(1) requires "appropriate and proportionate technical, operational and organisational measures", judged against the state of the art, cost, the entity's exposure to risk, its size, and the likelihood and severity of incidents. Article 21(2) then says those measures "shall include at least the following":

Point

Requirement

Testing hook

(a)

Risk analysis and information system security policies

Risk basis for scope

(b)

Incident handling

Exercises

(c)

Business continuity, backup, disaster recovery, crisis management

Recovery testing

(d)

Supply chain security

Supplier assurance

(e)

Security in acquisition, development and maintenance, with vulnerability handling and disclosure

Yes, application testing

(f)

Procedures to assess effectiveness of measures

Yes, effectiveness evidence

(g)

Basic cyber hygiene practices and training

No

(h)

Cryptography and, where appropriate, encryption

No

(i)

HR security, access control, asset management

Access control

(j)

MFA or continuous authentication, secured communications

MFA coverage

Points (e) and (f) are where testing lives; neither names a technique or an interval. Article 21(4) adds that an entity finding itself non-compliant must correct "without undue delay", which makes your findings actionable against you.

Where testing does become binding: Implementing Regulation (EU) 2024/2690

Article 21(5) obliged the Commission to specify technical requirements for a defined set of digital entity types. It did so in Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, in force twenty days after its publication on 18 October 2024.

Article 1 covers DNS providers, TLD name registries, cloud, data centre and content delivery network providers, managed service and managed security service providers, online marketplaces, search engines and social networking platforms, and trust service providers. If you are a hospital, a utility or a manufacturer, it does not apply to you: your obligations come from Article 21 as transposed by your member state.

For covered entities, Annex point 6.5 is binding law:

  • 6.5.1: a security testing policy and procedures.

  • 6.5.2(a): the entity establishes, from its risk assessment, "the need, scope, frequency and type of security tests".

  • 6.5.2(b): a documented methodology "covering the components identified as relevant for secure operation in a risk analysis".

  • 6.5.2(c) and (d): documented type, scope, time and results with criticality per finding, and mitigation of critical ones.

  • 6.5.3: periodic review of the policy.

Point 6.5.2(a) is the crux: the regulation makes testing mandatory, then hands you the pen on need, scope, frequency and type. The word "penetration" appears exactly once in the whole instrument, in recital 15, saying tests "may include automated or manual tests, penetration tests, vulnerability scanning" and other methods. That is a menu in a recital, not a mandate in an annex.

ENISA's technical implementation guidance (June 2025, v1.0) agrees, telling entities to "consider a range of security tests" including penetration testing, bug bounty programmes and red teaming, and "select the most appropriate one (or more)". Its closest thing to a cadence is an indicative suggestion to assess overall effectiveness annually, subordinate to the risk assessment, and the guidance binds nobody.

National transposition divergence: what member states actually added

The market story is that member states bolted testing duties onto NIS2. Checking three transpositions directly, that is not what happened: what they added is conformity assessment, registration and documentation duties.

Member state

Instrument

In force

What it added

Belgium

NIS2 Law of 26 April 2024, Royal Decree of 9 June 2024

18 October 2024

Registration by 18 March 2025; conformity assessment against the CCB's CyberFundamentals (CyFun) or ISO/IEC 27001, via accredited bodies

Germany

NIS-2-Umsetzungsgesetz, amending the BSIG

6 December 2025

About 29 500 entities against roughly 4 500 before; registration, BSI incident reporting

Netherlands

Cyberbeveiligingswet (Cbw)

15 August 2026

Around 8 000 organisations; duty of care, incident reporting, NCSC registration

Belgium is the instructive case. Article 22, §1 of the Royal Decree of 9 June 2024 gives essential entities that chose the certification route 18 months from the NIS2 law entering into force, or from the date they are identified, to obtain a verification at basic or important level of the reference framework the national cybersecurity authority publishes, which is CyFun, or, on the ISO/IEC 27001 route, to file the scope and the statement of applicability. Article 22, §2 then gives them 30 months to hold the certification itself. For an entity in scope since 18 October 2024, that is 18 April 2026 and 18 April 2027. Article 15, §1 requires the assessing body to hold accreditation from a national accreditation body before the authority approves it. That is a real, dated, externally verified obligation, and an audit duty rather than a penetration testing one.

Transposition is still incomplete: on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposing measures, asking for a lump sum and daily penalties; the deadline was 17 October 2024. Your obligation is therefore a per-country question. See our guides for the Netherlands and Germany.

Essential vs important entities: the difference is supervision, not testing

Both classes owe the same Article 21 measures. What changes is how hard the state can push, and how early.

Essential (Article 32)

Important (Article 33)

Supervision model

Ex ante and ex post

Ex post only, on evidence of non-compliance

Security audits

"Regular and targeted"

"Targeted" only

Ad hoc audits

Yes, explicitly

Not listed

Security scans

Yes

Yes

Who pays for a targeted audit

The audited entity, unless the authority decides otherwise

Same

Suspend certification

Yes, Article 32(5)(a)

Not available

Ban the CEO from managerial functions

Yes, Article 32(5)(b)

Not available

Maximum fine (Article 34)

At least EUR 10 000 000 or 2 % of worldwide turnover

At least EUR 7 000 000 or 1,4 %

Two rows should change how you budget. Article 32(2)(b) lets an authority order a targeted security audit carried out by an independent body, and Article 32(2) makes the cost payable by the audited entity, "except in duly substantiated cases when the competent authority decides otherwise". Those targeted audits must rest on a risk assessment, and the article accepts one "conducted by the competent authority or the audited entity", so your own documented risk work is what keeps the scope recognisable rather than imposed. And Article 32(5)(b) lets an authority have a chief executive or legal representative temporarily barred from managerial functions, a power NIS2 reserves for essential entities alone.

Management liability under Article 20, and why leadership cares

Article 20(1) requires member states to ensure management bodies approve the cybersecurity risk-management measures, oversee implementation, and can be held liable for the entity's Article 21 infringements. Article 20(2) requires those members to follow training so they can identify risks and assess cybersecurity practices.

A director signing off an Article 21 programme is signing off a claim about effectiveness, and Article 21(2)(f) says that claim must be backed by procedures that test it. Article 35 adds that where an Article 21 infringement can entail a personal data breach, the authority must inform the GDPR supervisory authority: one weak control, two regulators.

NIS2 vs DORA: which one actually mandates threat-led testing

If you have been told NIS2 requires red teaming, the requirement you are thinking of is in DORA, Regulation (EU) 2022/2554, and it binds financial entities only.

NIS2 (2022/2555)

DORA (2022/2554)

Names penetration testing as a duty

No

Yes, Article 25(1)

Names red team testing

No

Yes, Article 27(1)(b)

General testing cadence

None

Article 24(6): at least yearly on systems supporting critical functions

Threat-led cadence

None

Article 26(1): TLPT at least every 3 years

Who is bound by TLPT

Nobody

Only entities identified under Article 26(8)

Test environment

Not specified

Article 26(2): live production

Regulator sign-off

No

Article 26(7): attestation, mutually recognised

Two details matter. Article 26(8) has competent authorities identify which entities must perform TLPT, based on impact, financial stability and ICT risk profile, so DORA scope is not TLPT scope. And Article 27(1)(c) requires testers "certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks", which is where firm-level accreditation earns its keep.

More in DORA threat-led penetration testing, TIBER, CBEST and DORA TLPT compared, the global TLPT frameworks reference, and does CMMC require penetration testing for the US equivalent.

What to buy: a defensible testing programme for a NIS2 entity

Because the law is risk-based, the defensible position is a documented decision, not a receipt. Write five things into your policy.

  1. The risk basis. Point to the Article 21(2)(a) risk assessment and name the systems whose compromise would produce a significant incident.

  2. Test type per asset class. Internet-facing web applications and APIs earn manual testing, because authorization and business logic are not reachable by scanners. Incident handling earns exercises, which ENISA treats at 3.1.3.

  3. Frequency, and its justification. You are choosing it: rate of change, exposure, incident history, criticality. Release-gated testing is easiest to defend for weekly-shipping systems.

  4. The remediation loop. Annex 6.5.2(c) and (d) require criticality and mitigating actions per finding, and Article 21(4) requires correction without undue delay. A report with no retest closes nothing.

  5. The effectiveness link. Recital 15 says findings "should inform" the effectiveness assessment, so route them into your Article 21(2)(f) file.

Stingrai is a CREST-accredited penetration testing service provider at firm level, and our testers hold CREST CRT. On the application layer, Snipe, our autonomous web application agent, runs black-box dynamic testing and white-box source review, hunts complex classes such as IDOR, broken authorization and business logic flaws, and produces AutoFix pull requests and pull-request gating, so remediation and retest evidence accumulate continuously. Hybrid engagements add human validation of every finding. Autonomous starts at US$3,000 one-time or US$450 per month, hybrid at US$6,800 or US$1,275 per month on a twelve-month engagement; see pricing. Both carry our "No High or Critical Finding = Don't Pay" guarantee. Network, cloud and social engineering sits with our human team.

Evidence pack: what a national supervisory authority will ask to see

Answer Article 32(2)(e), (f) and (g) directly.

Artefact

Maps to

Why it is asked for

Security testing policy and procedures

Annex 6.5.1

Must exist in writing

Risk assessment linking assets to scope

Annex 6.5.2(a)

Scope derived, not guessed

Documented test methodology

Annex 6.5.2(b)

Separates a test from a scan

Reports with dates, scope, criticality

Annex 6.5.2(c)

Article 32(2)(g) evidence

Remediation and retest records

Annex 6.5.2(d), Article 21(4)

Shows the loop closed

Effectiveness policy, KPIs and results

Article 21(2)(f), Annex 7

Most cited, least evidenced

Management approval and training records

Article 20(1), 20(2)

Directors in scope

Record the scope statement of every test, including what was not tested and why: a supervisor comparing your asset inventory against your test scope will find the gap anyway. And keep the raw artefacts: Article 32(2)(g) asks for "the respective underlying evidence", not the summary. See also pentest evidence auditors accept and compliance-driven testing.

Frequently Asked Questions

Does NIS2 require an annual penetration test?

No. Directive (EU) 2022/2555 sets no testing frequency, and "penetration testing" appears only in recitals 86 and 87: recital 86 describes managed security service providers, and recital 87 describes services competent authorities may themselves use in supervision, neither imposing a duty on an entity. For the eleven digital entity types covered by Commission Implementing Regulation (EU) 2024/2690, security testing is binding, but Annex point 6.5.2(a) has the entity itself set the need, scope, frequency and type of tests from its own risk assessment.

What does NIS2 Article 21 require?

Article 21(1) requires appropriate and proportionate technical, operational and organisational measures, judged against the state of the art, cost, exposure, entity size, and the likelihood and severity of incidents. Article 21(2) then lists ten minimum categories, points (a) through (j), from risk analysis policies and incident handling through supply chain security and secure development to multi-factor authentication. None of the ten names a test type or a frequency.

Does NIS2 require red teaming?

No. The phrase "red team" appears nowhere in Directive (EU) 2022/2555, nor in Commission Implementing Regulation (EU) 2024/2690. ENISA's non-binding guidance of June 2025 mentions red teaming as one option among many an entity may consider. Mandatory threat-led red teaming in EU law comes from DORA Article 26, not NIS2.

What is the difference between NIS2 and DORA testing requirements?

NIS2 names no test type and sets no cadence. DORA does both: Article 24(6) requires at least yearly testing of ICT systems supporting critical or important functions, and Article 26(1) requires threat-led penetration testing at least every three years on live production. Article 26(8) has competent authorities identify which financial entities must perform TLPT, so DORA scope does not equal TLPT scope.

Are essential entities required to do more testing than important entities?

No, both owe identical Article 21 measures. The difference is supervision: Article 32 allows ex ante supervision of essential entities including regular, targeted and ad hoc security audits, while Article 33 limits important entities to ex post supervision on evidence of non-compliance. Article 32(5) also reserves powers for essential entities alone, including suspending a certification and barring a chief executive from managerial functions.

What evidence do NIS2 supervisors ask for?

Article 32(2)(g) allows requests for "evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence", alongside documented policies under 32(2)(e). In practice: the testing policy, the risk assessment that set scope, the methodology, dated reports with criticality per finding, remediation records, and management approval records.

Which countries have transposed NIS2 with explicit testing requirements?

Checking Belgium, Germany and the Netherlands directly, none of the three added an explicit penetration testing mandate. Belgium added a conformity assessment regime instead: Article 22, §1 of its Royal Decree of 9 June 2024 gives essential entities on the certification route 18 months from the law entering into force to obtain a verification at basic or important level of the CyFun framework, which is 18 April 2026 for entities in scope since 18 October 2024, with certification due at 30 months. Germany's NIS-2-Umsetzungsgesetz took effect on 6 December 2025, and the Dutch Cyberbeveiligingswet takes effect on 15 August 2026.

Can directors be held personally liable under NIS2?

Yes. Article 20(1) requires member states to ensure that management bodies of essential and important entities approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity's infringements of Article 21. Article 20(2) requires those members to follow training so they can identify risks and assess cybersecurity practices. For essential entities, Article 32(5)(b) additionally lets authorities request a temporary ban on a chief executive or legal representative from exercising managerial functions.

References

0 views

0

X

Related reading

Does CMMC Require a Penetration Test? Level 1, 2 and 3 (2026)
AdvisoriesNetwork Security

Does CMMC Require a Penetration Test? Level 1, 2 and 3 (2026)

CMMC Levels 1 and 2 require no penetration test. Only Level 3 does, via CA.L3-3.12.1e. Here is what 32 CFR part 170 and NIST actually say in 2026.

16 min read

Redis RCE in 2026: Five Patched CVEs and the 27-Minute AI Discovery Defenders Should Note
AdvisoriesNetwork Security

Redis RCE in 2026: Five Patched CVEs and the 27-Minute AI Discovery Defenders Should Note

The five patched Redis RCE CVEs, the July 23 2026 releases that supersede the May fixed builds, the correct NVD severities, and the separate AI discovery claim.

14 min read

How XBOW Found Exim's 9.8 Dead.Letter RCE (CVE-2026-45185), and What Mail Operators Do Now
AdvisoriesNetwork Security

How XBOW Found Exim's 9.8 Dead.Letter RCE (CVE-2026-45185), and What Mail Operators Do Now

CVE-2026-45185 (Dead.Letter) is a 9.8 unauthenticated RCE in Exim GnuTLS builds. Check if you are affected, patch to 4.99.3, and lock down SMTP exposure.

14 min read

Contents

X