Pentest for NIS2 Compliance
The NIS2 directive (Network and Information Security Directive 2) was transposed into Dutch law as of 2025 through the Cybersecurity Act (Cyberbeveiligingswet). Organisations in essential and important sectors must take demonstrable measures — including regular security testing.
Who is subject to NIS2?
NIS2 applies to medium and large organisations in these sectors:
- Energy, water and digital infrastructure
- Transport and logistics
- Financial services and banking
- Healthcare
- Government and public services
- IT service providers and cloud providers
- Manufacturing of critical products
Smaller organisations in the supply chain of essential providers can also fall indirectly under NIS2 through supplier management requirements.
What security testing does NIS2 require?
NIS2 requires organisations to adopt a risk management approach that includes, among other things:
- Regular assessment of technical vulnerabilities
- Penetration tests as part of risk identification
- Testing of business continuity measures
- Supply chain security assessment
What does MonkeysICT do for NIS2?
- Penetration testing of internet-facing systems and applications
- Vulnerability scanning across the full attack surface
- A report with risk classification aligned to NIS2 articles
- Advice on remediation priorities and residual risk
FAQ
Am I required to have a pentest carried out for NIS2?
NIS2 requires demonstrable risk management and technical security measures. A penetration test is the most direct way to identify and document vulnerabilities for the regulator. In the event of an incident without evidence of tests carried out, you risk board-level liability.
What are the fines for NIS2 non-compliance?
For essential entities: up to €10 million or 2% of global annual turnover. For important entities: up to €7 million or 1.4% of turnover.
How do I know if my organisation falls under NIS2?
This depends on your sector and company size. Not sure? Get in touch for a no-obligation conversation — we’ll help you determine whether and how NIS2 applies to you.
How quickly do we need to become NIS2-compliant?
The Dutch Cybersecurity Act is in effect. Enforcement is being phased in during 2025–2026. Starting testing now gives you time to remediate before regulators actively enforce.
Also see: security assessment for SMEs | ISO 27001 pentest | request a quote
