Looking for a penetration test? Fixed-scope engagements for GDPR, NIS2 & DORA.Get a quote today →
Request a Quote
Compliance

NIS2 Compliance Testing & Article 21 Evidence

Article 21 of NIS2 requires essential and important entities to test and evaluate the effectiveness of their cybersecurity risk-management measures. We provide the independent, documented testing that produces.

At a Glance
Included WithAny Testing Engagement
Delivery FormatAudit-Ready Report
Best ForEssential & Important Entities
FrameworksNIS2 Art. 21

Built for the auditor, not just your team

Every engagement includes reporting written for direct submission, not internal notes you have to reformat before your auditor can use them.

01

Scope Mapped to Essential Systems

Core Coverage

We start by mapping your test scope to the network and information systems that actually support your essential or important function, not a generic web-app checklist.

  • Relevant if you're in energy, health, digital infrastructure, banking, transport, water, or another NIS2-named sector.
02

Article 21 Technical Measures Testing

Core Coverage

Manual testing of application security, access control, and vulnerability-handling processes — the technical measures Article 21(2) lists explicitly.

  • Covers supply-chain-facing APIs and integrations, since Article 21 names supply chain security directly.
03

Effectiveness Evidence, Not Just a Scan

Core Coverage

A documented, independent test that demonstrates you're evaluating the effectiveness of your measures, not just asserting they exist.

  • Most national implementing guidance points to at least an annual testing cycle.
04

Board & Authority-Ready Reporting

Core Coverage

Findings, methodology, and remediation evidence structured for your board, and for your national competent authority if requested.

  • Retest evidence carried forward into next year's cycle.

What to expect

What's Included

  • Scope built around your essential or important function, not a generic checklist
  • Manual testing of application security and access-control measures under Article 21(2)
  • Supply-chain and third-party integration testing
  • Annual-cycle structure so retests build on prior findings

Deliverables

  • Audit-ready report mapped to Article 21 technical measures
  • Evidence suitable for board-level risk reporting
  • Retest evidence once findings are remediated
  • Documentation your compliance lead can present to a competent authority on request

Ready to scope a NIS2-focused engagement?

Tell us which sector you fall under and whether you've been classified essential or important, and you'll get a proposal back mapped to Article 21.