Is your work compliant with NIS2, DORA, DigiD or MIAUW?

We can align the pentest and reporting with the technical parts of your audit or compliance requirements. We agree the requirements to assess and the evidence needed during scoping. A pentest or pentest report does not, on its own, establish that your organization fully complies with a law or standard.

NIS2 and DORA

A pentest can provide insight into technical risks and the effectiveness of security controls. For NIS2, this supports a risk-based security approach. Under DORA, penetration testing is one of the possible assessment methods within a broader testing program. A regular pentest is not equivalent to formal TLPT, which has additional requirements for scope, execution and the parties involved.

DigiD

A DigiD pentest provides technical findings for the annual ICT security assessment. We align the scope with the applicable Logius DigiD framework and arrangements with your auditor. The auditor also assesses the other required components and prepares the assessment report. Our pentest does not replace that assessment.

Standards and assessment methods

For ISO 27001, NEN 7510 or PCI DSS engagements, we agree which technical requirements and systems are in scope. For an engagement with MIAUW requirements, we agree the methodology, documentation and reproducibility upfront. An assessment methodology is not the same as a legal obligation or certification.

Which reporting do you need?

Discuss the coverage, evidence and reporting format with your auditor in advance. We align the plan and any additional work with those needs. This helps avoid receiving a technical report that does not adequately address your audit requirements.

View our pentest plans or discuss your compliance requirements with us.