Is a Penetration Test Mandatory? Laws and Regulations in the Netherlands
More and more organisations are asking themselves: are we actually required to have a pentest carried out? The answer depends on your sector, the systems you manage, and the regulations you must comply with. This article gives a clear overview.
When is a pentest legally required or strongly recommended?
1. DigiD connection (NIBAD)
Organisations that use DigiD — such as municipalities, health insurers and educational institutions — are required to have an annual IT security assessment carried out in accordance with the NIBAD standard. This assessment requires a penetration test of the web application and associated infrastructure. Without an approved assessment, Logius can revoke the DigiD connection.
→ More information: DigiD pentest & IT security assessment
2. The NIS2 directive
The NIS2 directive (implemented in the Netherlands as the Cybersecurity Act) requires organisations in essential and important sectors to take appropriate technical measures. This includes periodic testing of security measures — in practice via penetration tests and vulnerability scans. Sectors covered by NIS2 include: energy, transport, finance, healthcare, water, digital infrastructure and more.
→ More information: NIS2 pentest
3. PCI DSS
Organisations that process card payments (credit cards, Mastercard, Visa) fall under the PCI DSS standard. Requirement 11.4 explicitly requires an annual penetration test and a test after significant changes. This isn’t a recommendation — it’s a hard requirement. Without compliance, you risk losing your processing licence.
→ More information: PCI DSS pentest
4. ISO 27001
ISO 27001 certification requires technical security testing as part of the Information Security Management System (ISMS). While penetration tests aren’t named literally, there’s a clear expectation that organisations actively test their security measures. In practice, auditors expect periodic pentests as evidence.
→ More information: ISO 27001 pentest
5. BIO (Baseline Information Security for Dutch Government)
All Dutch government organisations must comply with the BIO. The BIO is based on ISO 27001/27002 and sets comparable requirements for technical security testing. Municipalities, provinces, water boards and central government agencies fall under this.
→ More information: Pentest for government & the public sector
6. NEN 7510 (healthcare)
Healthcare institutions that process patient data must comply with NEN 7510. This includes periodic technical vulnerability analyses and penetration tests of systems with access to electronic health records.
→ More information: Pentest for the healthcare sector
And if none of these regulations apply to me?
Then a pentest isn’t legally mandatory — but it’s still strongly recommended. The GDPR requires organisations to take “appropriate technical measures” to protect personal data. The Dutch Data Protection Authority can ask, after a data breach, what measures were in place. A demonstrable pentest history is a strong defence.
Summary: are you required to?
| Regulation | Applies to | Pentest mandatory? |
|---|---|---|
| NIBAD / DigiD | Organisations with a DigiD connection | Yes, annually |
| NIS2 | Essential & important sectors | Yes, periodically |
| PCI DSS | Payment card processors | Yes, annually + after changes |
| ISO 27001 | ISO-certified organisations | Yes, expected by auditors |
| BIO | Government organisations | Yes, periodically |
| NEN 7510 | Healthcare institutions | Yes, periodically |
| GDPR | All organisations with personal data | Strongly recommended |
FAQ
Can I be fined if I don’t have a pentest carried out?
For NIS2 and GDPR violations, the regulator can impose a fine — especially if it turns out after an incident that basic security tests were missing. For PCI DSS and DigiD, you risk losing your processing licence or DigiD connection respectively.
How often do I need to have a pentest carried out?
Under most regulations, annually is the minimum, supplemented with a test after significant system changes. Some frameworks also require quarterly scans in addition to the annual pentest.
Does a vulnerability scan also count as a pentest?
No. A vulnerability scan is automated and only finds known weaknesses. Most regulations require an actual penetration test, in which a human tester actively attempts to break in. See also: vulnerability scan vs. pentest.
