NIS2 Penetration Testing

Penetration Testing for NIS2 Compliance

The new NIS2 directive requires companies to elevate their IT security to a high level.

Your company must comply with the NIS2 directive? Effective vulnerability management, including vulnerability scans and penetration tests, is an important part. We help you meet the requirements.

EU
Directive
Critical
Infra
Compliance
Ready
Penetration Testing
NIS2
Compliant
Secure
Verified
Damian Strobel - CEO DSecured

Damian Strobel

CEO

My recommendation

Verifiable security for NIS2

NIS2 demands more than checkboxes - auditors want to see verifiable tests and risk assessments. We structure your pentests so that you cleanly meet regulatory requirements and management reporting.
NIS2 Compliance

Everything Important About NIS2 Penetration Testing

Understanding and implementing compliance requirements

Fundamentals

What is NIS2?

NIS2 stands for "Network and Information Systems Security Directive 2" and is an EU directive designed to improve the security of network and information systems in the EU. With its second iteration, the directive is making big waves as it affects many companies. The directive forces companies to assess and improve their IT security where necessary. Risk management and vulnerability management are key issues here. Cybersecurity incidents must be reported within 24 hours. Another new feature is that management can be held personally liable for negligent breaches. In general, companies can be forced to pay fines in the millions based on this directive.

Requirements

Are penetration tests mandatory under NIS2?

Article 21 of the NIS2 directive is particularly relevant here (see here). It states that companies must implement "risk management measures in the area of cybersecurity". More specifically, "technical, operational and organizational measures" are required to minimize the "impact of security incidents on the recipients of their services". Vulnerability management is explicitly mentioned here, which typically includes penetration testing. However, "penetration testing" as a term is not mentioned in the directive, so it can be assumed that many companies will opt for vulnerability scans instead. Legally this should be acceptable, but in terms of effectiveness it is questionable. A penetration test is generally much more effective than a vulnerability scan, finds more security vulnerabilities and can assess them better.

Affected Entities

Who is affected by NIS2?

Affected Sectors:

Energy, transport, banking, financial market infrastructures, healthcare, water management, digital infrastructures, public administration, space, postal services, waste management, chemicals, food, manufacturing in general, digital services, research.

Size Criteria:
Large Companies

> 250 employees
> €50M revenue

Medium Companies

> 50 employees
> €10M revenue

Don't let it come to that and protect your systems from cyber attacks.

Request a Quote

How can DSecured help you implement NIS2?

Vulnerability Scans

Vulnerability Scans

Although vulnerability scans cannot be compared with penetration tests in terms of effectiveness and depth, they are a good start to finding initial vulnerabilities.

Penetration Testing

Penetration Testing

We can check your critical systems and applications for vulnerabilities and help you to close them.

Documentation

Documentation

We provide you with a comprehensive report containing all the vulnerabilities found and possible solutions.

Employee Awareness

Employee Awareness

Our phishing services help to raise your employees' awareness of the dangers of phishing - the number 1 attack vector.

Current/Target Analysis

Current/Target Analysis

Article 21 of NIS2 defines minimum requirements - we help you meet them.

Risk Analysis

Risk Analysis

We help you identify and assess the risks for your company.

Pricing

How much does a NIS2 penetration test cost?

Cost Factors Overview

A pentest within the scope of NIS2 is typically an extensive manual penetration test against a specific application or a composition of various applications and digital systems. Accordingly, the costs of a NIS2 pentest depend on the size of the scope, the testing depth and the complexity of the applications and systems to be tested.

Scope Size

Extent of systems to be tested

Complexity

Technical requirements

Testing Depth

Level of analysis detail

In general, a NIS2 pentest is a "normal" penetration test that is carried out, for example, as a web app pentest or external infrastructure pentest. The costs for a NIS2 pentest are therefore comparable to the costs for a "normal" penetration test.

Detailed Cost Information
Reference Prices
Simple Application
from €5,000
Multiple Systems
€10,000 - €30,000
Complex Infrastructure
€30,000+
Individual quotes available upon request
NIS2 Pentest
Trust through experience

Some companies we have been able to help

We've had the privilege of working with some of the world's leading companies and strengthening their IT security.

Frequently Asked Questions

When does the NIS2 directive come into force?

At EU level, the NIS2 directive has been in force since January 16, 2023. However, EU member states have until October 18, 2024 to transpose the directive into national law. This is the date from which companies in Germany must comply with the NIS2 directive.

Which sectors must now act according to the new NIS2 regulation?

The regulation lists various critical sectors as relevant. These include utilities, waste management, food producers, banks, the digital economy, healthcare, energy companies and transport companies. In addition, there are companies that are considered "essential" for maintaining public safety, regardless of their size or sector.

Is the managing director liable for non-compliance with the NIS2 directive?

Yes, the amendment from NIS to NIS2 explicitly regulates the liability of the managing director for non-compliance with the directive. They are even personally liable.

What penalties are imposed for non-compliance with the NIS2 directive?

The penalties depend on the size of the company. In general, the penalty can amount to up to 2% of global annual revenue or up to 10 million euros.

Does NIS2 also apply to small companies?

No. It is primarily aimed at companies with more than 50 employees. Small companies in very critical sectors may be an exception. However, this should be examined on a case-by-case basis.

What is the best way to prepare for NIS2?

Check whether you are affected. Have a risk analysis carried out and develop a security concept. This should include vulnerability management - regular security tests in the form of scans and penetration tests. Your employees should be trained and you should have an emergency plan ready. As the person responsible, it is generally worth reviewing Article 21 of the directive and checking where improvements are still needed.

What services does DSecured offer in the context of NIS2?

Vulnerability scans, penetration tests and red teaming - to identify problem areas. Phishing to raise employee awareness. General risk analyses and advice on the minimum standards from Article 21 NIS2.

We're here for you

Request a quote

Have questions about our services? We'd be happy to advise you and create a customized offer.

Quick Response

We'll get back to you within 24 hours

Privacy

Your data will be treated confidentially

Personal Consultation

Direct contact with our experts

Contact DSecured