Article 21 of NIS2 requires essential and important entities to test and evaluate the effectiveness of their cybersecurity risk-management measures. We provide the independent, documented testing that produces.
Every engagement includes reporting written for direct submission, not internal notes you have to reformat before your auditor can use them.
We start by mapping your test scope to the network and information systems that actually support your essential or important function, not a generic web-app checklist.
Manual testing of application security, access control, and vulnerability-handling processes — the technical measures Article 21(2) lists explicitly.
A documented, independent test that demonstrates you're evaluating the effectiveness of your measures, not just asserting they exist.
Findings, methodology, and remediation evidence structured for your board, and for your national competent authority if requested.
Tell us which sector you fall under and whether you've been classified essential or important, and you'll get a proposal back mapped to Article 21.