The Network and Information Security Directive 2 (NIS2) came into force across EU member states in October 2024, replacing the original NIS Directive with substantially expanded scope and significantly tougher enforcement. Where NIS1 covered a limited set of operators of essential services, NIS2 extends to an estimated 160,000 entities across 18 critical sectors — including energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration, and space.

Security teams at organisations newly brought into scope by NIS2 are discovering that their existing penetration testing programmes — typically annual assessments conducted by external consultants — do not satisfy what NIS2 actually requires. This article explains the gap and sets out a practical path to compliance.

What NIS2 Actually Requires (Article 21)

NIS2 Article 21 requires essential and important entities to implement appropriate and proportionate technical, operational, and organisational measures to manage cybersecurity risks. Specifically it mandates: policies on risk analysis and information system security; incident handling; business continuity and crisis management; supply chain security; network security; policies and procedures to assess the effectiveness of cybersecurity risk management measures; and the use of cryptography and encryption.

Crucially, NIS2 requires organisations to "assess the effectiveness" of their security measures. This is the requirement that breaks traditional annual penetration testing programmes — and the requirement that most compliance teams underestimate.

The Problem with Annual Penetration Testing

A traditional annual penetration test is a point-in-time snapshot. It tells you whether your defences could withstand attack on the specific day your consultants conducted the test, against the specific scope you agreed in the statement of work, using the specific methodology your consultant's team happened to apply. Within weeks of the report being delivered, your environment has changed — new systems deployed, new vulnerabilities published, new configurations applied — and the test is already out of date.

NIS2 regulators are increasingly explicit that "assessing the effectiveness" of cybersecurity measures is not a once-a-year event. ENISA guidance on NIS2 implementation makes clear that continuous monitoring and regular testing are expected. National competent authorities in Germany (BSI), France (ANSSI), and the Netherlands (NCSC-NL) have all published implementation guidance emphasising ongoing assurance over periodic testing.

The financial exposure makes this consequential. NIS2 allows national authorities to impose fines of up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% of global annual turnover for important entities. Personal liability for management is also introduced — directors can be held personally responsible for failure to comply.

What NIS2-Compliant Testing Looks Like

An effective NIS2 testing programme has three components that traditional annual penetration testing lacks:

Continuous vulnerability assessment. Every change to your environment creates a potential new attack surface. Continuous automated scanning ensures that new exposures are identified within hours of introduction, not discovered during next year's annual test.

Adversarial validation, not just scanning. NIS2 requires assessment of effectiveness — which means you need to know not just that vulnerabilities exist, but whether they are actually exploitable in your specific environment. Proof-of-concept validation, the kind provided by tools that actively confirm exploitability rather than simply flagging CVE matches, is what produces defensible evidence of due diligence.

Structured compliance evidence output. During a NIS2 supervisory examination, your competent authority will expect to see documented evidence of your risk assessment methodology, your testing programme outputs, and your remediation tracking. Ad hoc penetration test reports in PDF format are not audit-ready evidence. Structured, continuously updated compliance evidence packages are.

Mapping Your Testing Programme to NIS2 Article 21

✓ Continuous automated vulnerability assessment covering all in-scope systems

✓ Active exploitation validation — distinguishing theoretical from confirmed vulnerabilities

✓ MITRE ATT&CK-mapped attack chain analysis demonstrating realistic adversary paths

✓ Automated compliance evidence mapped to NIS2 Article 21 control requirements

✓ Remediation tracking with timestamped verification re-testing

✓ Supply chain security assessment for critical ICT providers

✓ Incident response plan tested at least annually against realistic attack scenarios

The Reporting and Notification Obligation

NIS2 also introduces a significant incident reporting obligation. Significant incidents must be reported to the national CSIRT or competent authority within 24 hours of awareness (early warning), within 72 hours with a fuller incident notification, and within one month with a final report. Security teams need pre-approved notification templates, clear internal escalation paths, and documented criteria for what constitutes a "significant incident" under their national implementation of NIS2.

Port Cyber Defense provides NIS2-aligned continuous adversary simulation for EU essential and important entities. Contact [email protected] for a NIS2 readiness assessment.