Penetration Testing Hub › Penetration Testing Explained

Penetration Testing for NIS2 Compliance

Before you do anything

This page covers compliance rather than technique, but the site's rule holds throughout: only ever test systems you own or are explicitly authorised to test, under the Criminal Justice (Offences Relating to Information Systems) Act 2017.

NIS2 is the EU directive that widens and sharpens cybersecurity obligations for a large set of organisations — and it has brought a lot of Irish companies into scope for the first time. This page explains where penetration testing fits: what NIS2 actually expects, whether a test is strictly required, and how to make sure a test produces the evidence a regulator will accept.

Check the current status

Ireland's transposition of NIS2 was still being finalised as this was written. Confirm the current position and the exact obligations for your sector before acting — this page explains the shape of the requirement, not a fixed legal deadline.

What NIS2 expects

NIS2 requires in-scope 'essential' and 'important' entities to put in place appropriate, risk-based cybersecurity measures — and, crucially, to be able to demonstrate that those measures actually work. It doesn't hand you a checklist of tools. It expects risk management, incident handling, business continuity, supply-chain security, and evidence that you test and assess the effectiveness of your controls.

That word — effectiveness — is where testing comes in. You can claim your controls work; a penetration test is a direct, independent way to show they do.

Is penetration testing strictly required?

NIS2 doesn't name 'penetration testing' as a mandatory line item the way PCI DSS does. What it requires is that you assess the effectiveness of your security measures. In practice, penetration testing (alongside vulnerability scanning and other assessment) is the most recognised, defensible way to meet that expectation. A regulator asking 'how do you know your measures work?' is far better answered with a test report than with a policy document.

How testing supports each obligation

Turning a test into NIS2 evidence

A test only helps your compliance if it's documented the way an assessor expects. Make sure:

Where to start

If NIS2 has just brought you into scope, don't start with a big red-team exercise. Start by doing the basics (the groundwork in our 'do you need one yet' guide), then scope a penetration test against the systems that carry the most risk, and build a repeatable rhythm from there. For financial entities, DORA sets a stricter, threat-led testing regime on top — see our DORA hub.

Common questions

Does NIS2 require penetration testing?

NIS2 doesn't name penetration testing as a mandatory item, but it requires in-scope entities to assess the effectiveness of their security measures — and testing is the most recognised way to do that. A regulator asking how you know your controls work is far better answered with a test report and remediation trail than with policy documents alone.

Who is in scope for NIS2 in Ireland?

NIS2 covers a broad range of 'essential' and 'important' entities across sectors like energy, transport, health, digital infrastructure, and more, generally above certain size thresholds. Ireland's transposition sets the precise scope, and it was still being finalised as this was written — confirm your sector's current obligations before acting.

How often should we test for NIS2?

There's no fixed number, but the expectation is that testing is periodic and triggered by significant change, not a one-off. A defensible rhythm is at least annually plus after major changes, with findings tracked to remediation and a re-test to close the loop — that trail is what demonstrates ongoing effectiveness.

If you'd rather we did this

If NIS2 has brought you into scope and you want testing that produces evidence a regulator will accept, here's how a CyberLabs engagement works — scoped to your important systems, documented for compliance.

No prices on this page and no hard sell.

See how working with us works →

This page is educational and not legal advice. Only test systems you own or are explicitly authorised to test.  ·  ↑ Back to top