Which organizations are our pentest services for?

DongIT performs pentests for organizations that need demonstrable security. Both because legislation requires it (NIS2, DORA, DigiD, GDPR) and because customers, partners or supervisory authorities demand it. From SMB webshops to enterprise organizations, and from healthcare institutions to Dutch central government.

When a pentest is mandatory

For these organizations a pentest is not optional but legally or contractually required:

  • Essential and important entities under NIS2. The Dutch Cybersecurity Act has been in effect since 15 August 2026, with fines up to €10 million. This includes energy, water, telecom, transport, digital infrastructure, financial market infrastructure and public ICT service providers.
  • Financial entities under DORA. Banks, insurers, payment institutions and crypto-asset service providers have been required to conduct annual ICT testing since 17 January 2025.
  • DigiD-connected services. Government organizations and public service providers with a DigiD integration must undergo an annual pentest per Logius framework v4.0.
  • Healthcare institutions under NEN 7510. Hospitals, public health services, GP practices and health insurers must demonstrably comply with NEN 7510 for information security of personal health information.
  • Dutch central government under MIAUW. The Dutch government-wide pentest framework agreement 2026 uses the MIAUW methodology as its standard. Applicable to ministries, High Councils of State and independent administrative bodies.

When a pentest is strategically valuable

Even without a legal obligation, these organizations choose to conduct a pentest:

  • Software vendors and SaaS providers. Enterprise procurement teams and Third Party Risk Management processes increasingly require a recent pentest report before signing a contract.
  • SMB organizations with customer data. Webshops, portals and online service providers that process personal data fall under GDPR accountability and use the Web Security Scan Trustmark to strengthen customer trust.
  • Enterprise IT and municipalities. For ISO 27001 certification (Annex A.8.8), internal audits and third-party risk management accountability towards clients and supervisory authorities.
  • Organizations in supply chains of essential entities. If NIS2-covered clients purchase your services, your security becomes part of their compliance accountability.

Which types of systems

DongIT performs pentests on web applications, mobile applications, APIs, network infrastructure, cloud environments (Azure, AWS, GCP), OT systems and source code. For concrete scoping and advice on which type of pentest suits your situation, we schedule a complimentary scoping conversation.

Contact us for a complimentary scoping conversation, or view our pentest packages and pricing.