Yes, DongIT pentests meet the requirements of the main Dutch and European cybersecurity regulations. Our reports are designed to be directly usable by your auditor, supervisory authority or certifying body.
NIS2 (Dutch Cybersecurity Act)
Since 15 August 2026, the Dutch Cybersecurity Act has been in effect as the implementation of the EU NIS2 Directive. Our pentests cover the risk assessment and periodic testing that essential and important entities must perform. Reports include management summaries and risk classifications aligned with ENISA guidelines, so you can meet your notification and accountability obligations. Fines under NIS2 can reach up to €10 million.
DORA (Digital Operational Resilience Act)
Financial entities have been required under DORA to conduct annual ICT testing since 17 January 2025. For major financial institutions this also includes Threat-Led Penetration Testing (TLPT), for which the Netherlands uses the TIBER-NL framework. Our pentests support DORA Articles 24 and 25 requirements and deliver reports aligned with reporting obligations to the Dutch Central Bank (DNB) and Authority for the Financial Markets (AFM).
DigiD assessments
For DigiD integrations, we conduct pentests according to the Logius framework v4.0. This is mandatory annually for all organizations that allow citizens to log in via DigiD. Reports are aligned with Logius audit requirements and directly usable by your external auditor.
MIAUW (Dutch government-wide pentest methodology)
The Dutch government-wide pentest framework agreement 2026 uses MIAUW (Methodology for Information Security Research with Audit Value) as the standard. This methodology, developed by Brenno de Winter and maintained by the LibreKAT Foundation, focuses on auditability and reproducibility. Our approach aligns with MIAUW requirements for documentation and verifiability.
ISO 27001, NEN 7510 and PCI DSS
In addition to the above regulations, we support pentests for:
- ISO 27001 Annex A.8.8. Technical vulnerability testing as part of your ISMS.
- NEN 7510. Information security for healthcare institutions.
- PCI DSS. For organizations handling card payments.
- ISO/IEC 27002. As a complement to ISO 27001.
Auditor-usable reports
All DongIT reports include management summaries, compliance mapping and risk classifications that your auditor can use directly. We know from experience what external auditors expect, since DongIT itself has been ISO 27001 certified since 2025 and holds the CCV Keurmerk Pentesten.
Have specific compliance requirements? Contact us for a complimentary scoping conversation, or view our pentest packages.
Nederlands