NIS2 significantly broadens the population of EU organisations in scope compared with the original 2016 NIS Directive — energy, transport, health, digital infrastructure, public administration, postal services, managed service providers and more, alongside the finance-sector overlap with DORA. Member states have been transposing NIS2 into national law, and national cybersecurity authorities are moving from identifying essential and important entities into active supervision, audits and inspections.
We turn Article 21's risk-management measures into evidence: a scope determination, a gap analysis, and the manual penetration test that proves your controls actually hold.
We start by confirming exactly where you sit — essential entity, important entity, or a supplier to one — against the Annex I and Annex II sector lists, since misjudging this either wastes effort or leaves you exposed. Then we gap-analyse your risk-management measures against Article 21's ten minimum requirements, covering everything from incident handling and business continuity to supply-chain security and access control. The technical penetration test that follows is scoped to your actual in-scope systems, not a generic checklist.
Why it matters
NIS2 introduced something the original directive did not: personal accountability for management, and a 24-hour early-warning reporting deadline that is impossible to meet if you do not already know your own attack surface. A gap analysis on paper does not survive first contact with either a regulator or an attacker — only tested controls do, and national authorities across the EU are moving into active enforcement.
What we test
- Entity classification & Annex I/II scope determination
- Article 21 risk-management measures gap analysis
- External & internal network penetration testing
- Supply-chain & third-party vendor risk review
- Incident-detection & 24-hour early-warning readiness check
- Vulnerability handling & disclosure process review
Common vulnerabilities we uncover
- Unclear or undetermined essential / important entity status
- Missing or incomplete Article 21 risk-management measures
- Unassessed third-party and supply-chain dependencies
- No tested incident-reporting process against the 24-hour deadline
- Flat networks with no meaningful segmentation
- Management with no real visibility into cyber risk exposure
Our methodology
- Scoping & rules of engagement. We agree objectives, targets and boundaries for your nis2 compliance penetration testing, so testing is safe, authorized and focused on what matters to your business.
- Reconnaissance & mapping. We enumerate the full attack surface in scope, building a complete picture before any exploitation begins.
- Manual exploitation. Our senior testers chain vulnerabilities by hand — going far beyond automated scanners — to prove real, demonstrable impact.
- Analysis & reporting. Every finding is triaged, risk-rated with CVSS and written up with a copy-paste reproduction and clear remediation.
- Remediation support & free retest. We support your team through the fixes and retest the remediated issues to confirm they are genuinely closed.
Tools & techniques
We map your organisation against the Annex I/II sector lists and Article 21's risk-management measures — risk analysis, incident handling, business continuity, supply-chain security, vulnerability handling and disclosure, cryptography, access control and multi-factor authentication — then run a manual, exploit-led penetration test against the systems that carry real operational risk. Because NIS2 explicitly calls out supply-chain security, we also review your key third-party and vendor dependencies, not just your own perimeter.
Every finding is mapped back to the specific Article 21 measure it relates to, so your remediation plan reads as a compliance roadmap, not just a vulnerability list.
When you need this engagement
- You are a medium or large enterprise in an Annex I or Annex II sector
- You have received, or expect, an information request from a national cybersecurity authority
- You are unsure whether you are classified as essential or important
- Your Board or management needs to evidence personal accountability for cyber risk
- You are a supplier to an NIS2-regulated entity being asked for security assurance
What you receive
- NIS2 entity classification & scope memo
- Article 21 risk-management gap analysis
- Penetration test report with reproducible evidence
- Supply-chain risk review
- Incident-reporting readiness assessment
- Prioritised remediation roadmap
What’s included in your report
Every nis2 compliance penetration testing engagement concludes with a comprehensive, board-ready report and a working session to walk your team through it. Your report includes:
- An executive summary with overall risk posture for non-technical stakeholders
- Detailed technical findings, each with a step-by-step, copy-paste reproduction
- CVSS v3.1 severity ratings and business-impact context for every issue
- Prioritized, actionable remediation guidance your engineers can apply directly
- A complimentary retest to confirm fixes and update finding status
- A formal attestation letter for customers, auditors and compliance programs
Standards & frameworks
NIS2 Directive (EU 2022/2555)
National transposition law (member-state specific)
Outcomes you can expect
After your nis2 compliance penetration testing, you will have clear, evidence-based visibility into your real security risk — not a scanner’s guesswork. You will know exactly which weaknesses an attacker could exploit, what the business impact would be, and the precise steps to fix them in priority order. Teams use our findings to close critical gaps, satisfy customer and regulator security requirements, and demonstrate due diligence to their board. With a complimentary retest included, you also get documented proof that the issues are genuinely resolved.
Engagement details & logistics
Every nis2 compliance penetration testing starts with a short, no-obligation scoping call to understand your goals, environment and constraints, followed by a fixed-price proposal and a clear statement of work. Most engagements are delivered fully remotely, with on-site work arranged where it genuinely adds value. Throughout testing we maintain an agreed communication cadence and escalate any critical, high-impact finding to you immediately rather than waiting for the final report. All work is performed under a signed NDA with strict data-handling controls, using safe, non-disruptive techniques and carefully coordinated rules of engagement to protect your production systems. On completion you receive your report and a walkthrough session, followed by a complimentary retest once your fixes are in place. Typical engagements are booked one to three weeks in advance, and urgent or pre-deadline testing can often be accommodated — just ask at hi@agentoffense.com.
Why organizations choose AgentOffense
Our nis2 compliance penetration testing is delivered by senior offensive-security engineers who test the way real attackers do — manually, creatively and with a relentless focus on proving genuine, demonstrable impact. Here is what sets our engagements apart:
- Manual, exploit-driven testing that chains vulnerabilities the way a real attacker would, going far beyond what automated scanners can find.
- Reproducible proof for every finding, with copy-paste reproduction steps your engineers can follow and independently verify.
- Honest severity calibration so you invest in fixing what genuinely matters and avoid wasting effort on false positives and noise.
- Clear, business-focused reporting that speaks to engineers and executives alike, tying every issue to real-world impact.
- A complimentary retest included, so you get documented proof that your fixes actually close the attack path.
- Responsible, collaborative delivery with a named point of contact and secure handling of all data throughout the engagement.
Explore related services
NIS2 Compliance Penetration Testing is frequently scoped alongside our other offensive-security services for broader coverage. Explore related engagements that complement it:
How much does NIS2 Compliance Penetration Testing cost?
Every nis2 compliance penetration testing is scoped and priced individually, so you pay for exactly the coverage you need — with no hidden extras. After a short, no-obligation scoping call we send a fixed-price quote, usually within one business day, with clear deliverables, a firm timeline and a complimentary retest included. The price of your nis2 compliance penetration testing depends on the size and complexity of the target and the depth of testing required, so you always know the cost up front before any work begins.
Get a fixed-price quote
Frequently asked questions
Does NIS2 require penetration testing?
Article 21 requires "appropriate and proportionate" technical risk-management measures, including vulnerability handling. In practice, national cybersecurity authorities and any credible auditor expect that to be evidenced by regular penetration testing, not policy documents alone.
Is my company classified as essential or important under NIS2?
That depends on your sector, under Annex I or Annex II, and your size. Many medium-sized companies are now newly in scope. Our engagement starts by determining exactly where you land before recommending anything further.
What happens if we are a supplier to an NIS2-regulated company?
NIS2 explicitly requires regulated entities to assess supply-chain security, so you may be asked to provide security assurance or a penetration test report even if you are not directly in scope yourself.
How is NIS2 different from DORA?
NIS2 is the broader EU cybersecurity directive covering many sectors — energy, transport, health, digital infrastructure and more — while DORA applies specifically to financial entities with its own additional requirements. A financial entity can be in scope for both at once.