NIS2 pentest

Assessment per article 21 Dutch Cybersecurity Act, in effect 15 August 2026

Get a NIS2 and Dutch Cybersecurity Act pentest

Does your organization fall under the new Dutch Cybersecurity Act (Cbw), which takes effect on 15 August 2026? Preparing for oversight by the Dutch Authority for Digital Infrastructure (RDI)? Does an enterprise client require a NIS2 statement in your supply chain? For essential and important entities under NIS2, a pentest is one of the most concrete ways to demonstrate compliance. There is no transition period: all obligations apply from day one.

DongIT delivers NIS2 pentests specifically aligned with the ten security measures from article 21 of the Dutch Cybersecurity Act, the Dutch implementation of the NIS2 directive (EU) 2022/2555. Findings are explicitly mapped to the relevant article 21 categories, so your compliance officer, supervisory authority or auditor has standardized evidence directly available.

Our pentests are performed by OSCP-certified ethical hackers under our four-eyes principle: minimum of two testers per engagement with peer review on every finding. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe. DongIT is itself ISO 27001:2022-certified since 2015.

NIS2 directive and Dutch Cybersecurity Act

What we test in a NIS2 pentest

A NIS2 pentest assesses your applications, infrastructure and networks against the technical security measures from article 21 Dutch Cybersecurity Act. We explicitly map every finding to the relevant article 21 category, so your compliance officer and supervisory authority have standardized evidence.

  • Article 21(2)(a): risk analysis and information system policies. Concrete validation that your implemented measures align with defined risks.
  • Article 21(2)(d): supply chain security. Assessment of third-party access, supplier integrations and integration points.
  • Article 21(2)(f): policies and procedures for evaluation. The pentest itself is a demonstrable implementation of this obligation.
  • Article 21(2)(g): basic cyber hygiene. Testing of password policies, patch management, system hardening and access control.
  • Article 21(2)(h): cryptography. TLS configuration, key management, secure storage of sensitive data and encryption at rest.
  • Article 21(2)(i): personnel security and access control. Identity and access management, role separation, MFA and authorization flows.
  • Article 21(2)(j): multi-factor authentication and secure communication. Validation of MFA implementation and communication security between systems.

For organizations that need to cover both NIS2 and other frameworks (ISO 27001, DigiD, DORA, BIO2), we can double-map findings to multiple frameworks in one report. This saves time and cost compared to multiple separate engagements.

Why not to delay your NIS2 pentest

The Dutch Cybersecurity Act takes effect on 15 August 2026, without a transition period. This means that from day one, three obligations simultaneously apply to the more than 8,000 Dutch organizations that fall under the law:

Registration obligation

Registration in the NCSC entity register. Your organization must be formally known to the Dutch National Cyber Security Centre from day one.

Duty of care

Adequate security measures per article 21. Measures must be demonstrably implemented and evaluated.

Notification obligation

Report significant incidents within 24 hours to the NCSC, with detailed reporting within 72 hours. Including incidents in your supply chain.

What if you are not compliant? For essential entities, fines apply up to €10 million or 2% of global annual turnover. For important entities up to €7 million or 1.4% of global turnover. Directors can be held personally liable for shortcomings. The RDI and NCSC have announced active enforcement from the effective date.

Why choose DongIT for your NIS2 pentest

NIS2 compliance requires a pentest partner who understands how supervisory authorities and auditors work. We ourselves have been assessed under strict regimes: DongIT has been ISO 27001:2022-certified since 2015 and is CCV Keurmerk Pentesten-accredited. We know first-hand how an audit works from the inside.

  • CCV Keurmerk Pentesten. Independent accreditation that safeguards the quality and methodology of our pentests. For supervisory authorities and auditors an additional quality indicator that strengthens your compliance reporting.
  • ISO 27001:2022 certified. DongIT is ISO 27001 certified. We know exactly which evidence your auditor values and how to deliver it efficiently.
  • Four-eyes principle. Minimum of two OSCP-certified pentesters per engagement, with peer review on every finding. Additional quality assurance for your audit dossier.
  • 500+ organizations have relied on our pentests since 2012, in sectors that NIS2 affects: healthcare, financial, government and industry.
  • Security Reporter platform. Self-developed reporting environment. Data stays in Europe, no US-hosting. A concrete advantage under NIS2 and GDPR.
  • Direct communication lines. No call-center intermediary layer. You speak directly with the pentester delivering your engagement.

Our approach: from pentest to compliance evidence

We follow a structured approach aligned with how NIS2 supervision works. Every step delivers evidence you can use for internal reporting and external assessment.

  1. Scope alignment with your NIS2 position

    We jointly determine whether you fall under NIS2 as an essential or important entity, and which systems and applications are in scope. This aligns with the registration obligation in the NCSC entity register that applies from 15 August 2026.

  2. Technical pentest

    Manual testing by OSCP-certified ethical hackers under our four-eyes principle, supplemented with automated tooling. Testing per NCSC guidelines, OWASP and NIST frameworks.

  3. Reporting with article 21 mapping

    Delivery via Security Reporter. Every finding mapped to the relevant article 21 category from the Dutch Cybersecurity Act, with CVSS scoring and remediation guidance. Directly usable for your compliance reporting to the supervisory authority or enterprise client.

  4. Remediation support

    Our specialists support your team with interpreting findings and prioritizing remediation. When facing a compliance deadline, we work together on a risk-based approach so critical issues are resolved first.

  5. Retest and supervisory authority support

    Formal retest of resolved vulnerabilities. During RDI inspections or external assessments we can be present to answer technical questions directly.

Who is required to comply with NIS2 and the Dutch Cybersecurity Act?

The Dutch Cybersecurity Act applies to essential and important entities in 18 sectors with at least 50 employees or €10 million turnover. Not sure whether your organization falls within scope? Contact us for a preliminary conversation.

Essential entities

Large organizations (250+ employees or €50M+ turnover) in critical sectors.

  • Energy and drinking water
  • Transport and postal services
  • Financial sector and insurers
  • Healthcare and pharmaceuticals
  • Digital infrastructure and cloud
  • ICT service management services
  • Government and public administration

Penalty: fines up to €10 million or 2% of global turnover.

Important entities

Medium-sized organizations (50+ employees or €10M+ turnover) in additional sectors.

  • Postal and courier services
  • Waste management
  • Food production, processing and distribution
  • Chemical production and distribution
  • Digital providers (marketplaces, search engines)
  • Research institutions
  • Critical manufacturing sectors

Penalty: fines up to €7 million or 1.4% of global turnover.

Even without a legal obligation, your enterprise clients or supply chain partners may require NIS2 conformity as part of their own supply chain security. For these situations we deliver the same reporting structure you can share directly with your clients.

Combining with other compliance engagements

NIS2 overlaps substantially with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:

NIS2 and ISO 27001

ISO 27001 certification covers a substantial portion of article 21 requirements. Findings double-mapped to Dutch Cybersecurity Act and Annex A controls.

More about ISO 27001 pentest

NIS2 and DigiD

For executive agencies that are both essential entity and have a DigiD connection. One coordinated engagement.

More about DigiD pentest

NIS2 and DORA

For financial entities. Both frameworks overlap substantially; we structure reporting to meet both compliance requirements.

Request DORA pentest

NIS2 and BIO2

For Dutch government organizations. NIS2 obligation combined with Baseline Informatiebeveiliging Overheid 2, usable for ENSIA reporting.

Request BIO2 pentest

NIS2 and NEN 7510

For healthcare organizations and healthcare IT vendors. Healthcare qualifies as essential entity; we combine with NEN 7510-specific controls.

Request NEN 7510 pentest

NIS2 and cyber insurance

An increasing number of cyber insurers require demonstrable NIS2 conformity as a condition for coverage. Our reporting meets these requirements.

Request a quotation

What does a NIS2 pentest cost?

The price depends on the size of your NIS2 scope, the number of systems and applications and any combined scopes with other compliance frameworks. For clearly defined engagements we offer standard packages. For essential entities with complex infrastructure we work with a scoping conversation and a tailored quotation.

  • Quick Pentest, €2,960 excl. VAT
  • Expert Pentest, from €5,040 excl. VAT (most chosen)
  • Extensive Pentest, from €7,200 excl. VAT
  • Enterprise and multi-scope engagements, tailored quotation

NIS2 scope as starting point

For every NIS2 engagement we start with a complimentary scoping conversation covering your entity classification, article 21 implementation and compliance strategy. This ensures you know exactly what the investment will be.

Frequently asked questions about NIS2 pentesting

Below are the most frequently asked questions about NIS2 and Dutch Cybersecurity Act pentesting. For a complete overview please visit our FAQ page.

When does the Dutch Cybersecurity Act take effect?

The Dutch Cybersecurity Act (Cbw) takes effect on 15 August 2026 as the Dutch implementation of NIS2 directive (EU) 2022/2555. The Dutch Senate approved the bill on 7 July 2026, the House of Representatives on 15 April 2026. There is no transition period: all obligations apply from day one. The Act replaces the earlier Network and Information Systems Security Act (Wbni) from 2018.

Am I an essential or important entity?

That depends on your sector and organization size. Essential entities are large organizations (250+ employees or €50M+ turnover) in critical sectors such as energy, transport, financial and healthcare. Important entities are medium-sized organizations (50+ employees or €10M+ turnover) in additional sectors. In our scoping conversation we help determine which category you fall into and which obligations specifically apply.

Is a pentest legally required under NIS2?

Article 21(2)(f) requires policies and procedures to evaluate the effectiveness of security measures. A pentest is the most concrete implementation of this. Although the law does not prescribe a specific frequency, we recommend at least annual pentesting for essential entities and biennial pentesting for important entities.

Do I need to register somewhere under the Dutch Cybersecurity Act?

Yes. Organizations that fall under the Dutch Cybersecurity Act must register in the entity register via the NCSC from 15 August 2026. In addition to the registration obligation, a duty of care applies (adequate security measures per article 21) and a notification obligation (significant incidents within 24 hours to NCSC, detailed reporting within 72 hours). Directors are personally responsible for compliance.

What are the fines for non-compliance?

Essential entities face fines up to €10 million or 2% of global turnover (whichever is higher). For important entities, up to €7 million or 1.4% of global turnover. In addition, directors can be held personally liable under the new law. The RDI has announced active enforcement from the effective date.

What about supply chain requirements?

Article 21(2)(d) requires supply chain security. Your enterprise clients can ask you as a supplier to demonstrate NIS2 conformity, even if you do not directly fall within scope. We deliver reporting you can share with your supply chain partners.

Who is the supervisory authority under the Dutch Cybersecurity Act?

The Dutch Authority for Digital Infrastructure (RDI) is the primary supervisory authority. For incident notification, the Dutch National Cyber Security Centre (NCSC) is the reporting body. Sectoral supervision may additionally apply for specific sectors, for example DNB for the financial sector.

Does a NIS2 pentest combine well with an ISO 27001 audit?

Yes. NIS2 and ISO 27001 overlap substantially. For certified organizations we can double-map pentest findings to both article 21 Dutch Cybersecurity Act and Annex A controls from ISO 27001:2022. This saves time and cost compared to two separate engagements.

How long does a NIS2 pentest take?

Active testing time ranges from 32 hours for a compact NIS2 scope to 120 hours or more for extensive multi-scope engagements at essential entities. Total duration from scoping conversation to final report is typically 4 to 8 weeks.

Ready for 15 August 2026?

The Dutch Cybersecurity Act takes effect in a matter of weeks and there is no transition period. Working toward demonstrable NIS2 compliance? Preparing for RDI oversight? Or does an enterprise client require a NIS2 statement in your supply chain? We start with a complimentary scoping conversation covering your entity classification and compliance strategy. Response within one business day. Quotation within three business days.