NIS2 pentest

Assessment per article 21 Dutch Cybersecurity Act, in effect 15 August 2026

Get a NIS2 and Dutch Cybersecurity Act pentest

Do you need technical security evidence for NIS2 and the Dutch Cybersecurity Act? DongIT examines vulnerabilities and attack paths in your systems. We align the scope with your risk profile and the evidence you need.

Illustration of interconnected business and supplier systems with their security under examination.

DongIT delivers NIS2 pentests specifically aligned with the ten security measures from article 21 of the Dutch Cybersecurity Act, the Dutch implementation of the NIS2 directive (EU) 2022/2555. Findings are explicitly mapped to the relevant article 21 categories, so your compliance officer, supervisory authority or auditor has standardized evidence directly available.

Our pentests are performed by certified ethical hackers under our four-eyes principle: minimum of two testers per engagement with peer review on every finding. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited.

What we test in a NIS2 pentest

A NIS2 pentest assesses your applications, infrastructure and networks against the technical security measures from article 21 of the NIS2 directive. We explicitly map every finding to the relevant article 21 category, so your compliance officer and supervisory authority have standardized evidence.

  • Article 21(2)(a): risk analysis and information system policies. Concrete validation that your implemented measures align with defined risks.
  • Article 21(2)(d): supply chain security. Assessment of third-party access, supplier integrations and integration points.
  • Article 21(2)(f): policies and procedures for evaluation. The pentest itself is a demonstrable implementation of this obligation.
  • Article 21(2)(g): basic cyber hygiene. Testing of password policies, patch management, system hardening and access control.
  • Article 21(2)(h): cryptography. TLS configuration, key management, secure storage of sensitive data and encryption at rest.
  • Article 21(2)(i): personnel security and access control. Identity and access management, role separation, MFA and authorization flows.
  • Article 21(2)(j): multi-factor authentication and secure communication. Validation of MFA implementation and communication security between systems.

For organizations that need to cover both NIS2 and other frameworks (ISO 27001, DigiD, DORA, BIO2), we can double-map findings to multiple frameworks in one report. This saves time and cost compared to multiple separate engagements.

Article 21(2)(g) also explicitly covers cybersecurity awareness and training for staff. Our security workshops and master classes provide a practical, demonstrable way to fulfill that part of the duty of care.

Why not to delay your NIS2 pentest

The Dutch Cybersecurity Act has been in effect since 15 August 2026, without a transition period. This means that from day one, three obligations simultaneously apply to the more than 8,000 Dutch organizations that fall under the law:

Registration obligation

Registration in the NCSC entity register. Your organization must be formally known to the Dutch National Cyber Security Centre from day one.

Duty of care

Adequate security measures per article 21. Measures must be demonstrably implemented and evaluated.

Notification obligation

Notify significant incidents as soon as possible and no later than 24 hours, followed by further reporting within the applicable deadlines. Notifications through MijnNCSC are shared with the relevant sectoral CSIRT and supervisor. Not every supplier incident is automatically reportable by your organization.

What if you are not compliant? The sectoral supervisor may require corrective measures or impose sanctions. The consequences depend on your legal status, the infringement and the applicable rules. The NCSC provides incident support as a CSIRT, a distinct role from that of the supervisor.

Why choose DongIT for your NIS2 pentest

NIS2 compliance requires a pentest partner who understands how supervisory authorities and auditors work. We ourselves have been assessed under strict regimes: DongIT has been ISO 27001:2022-certified since 2025 and is CCV Keurmerk Pentesten-accredited. We know first-hand how an audit works from the inside.

  • CCV Keurmerk Pentesten. Independent accreditation that safeguards the quality and methodology of our pentests. For supervisory authorities and auditors an additional quality indicator that strengthens your compliance reporting.
  • ISO 27001:2022 certified. DongIT is ISO 27001 certified. We know exactly which evidence your auditor values and how to deliver it efficiently.
  • Four-eyes principle. Minimum of two OSCP-certified pentesters per engagement, with peer review on every finding. Additional quality assurance for your audit dossier.
  • 500+ organizations have relied on our pentests since 2012, in sectors that NIS2 affects: healthcare, financial, government and industry.
  • Security Reporter platform. Self-developed reporting environment. Data stays in Europe, no US-hosting. A concrete advantage under NIS2 and GDPR.
  • Direct communication lines. No call-center intermediary layer. You speak directly with the pentester delivering your engagement.

Our approach: from pentest to compliance evidence

We follow a structured approach aligned with how NIS2 supervision works. Every step delivers evidence you can use for internal reporting and external assessment.

  1. Scope alignment with your NIS2 position

    We jointly determine whether you fall under NIS2 as an essential or important entity, and which systems and applications are in scope. This aligns with the registration obligation in the NCSC entity register that applies from 15 August 2026.

  2. Technical pentest

    Manual testing by OSCP-certified ethical hackers under our four-eyes principle, supplemented with automated tooling. Testing per NCSC guidelines, OWASP and NIST frameworks.

  3. Reporting with article 21 mapping

    Delivery via Security Reporter. Every finding mapped to the relevant article 21 category from the NIS2 directive, with CVSS scoring and remediation guidance. Directly usable for your compliance reporting to the supervisory authority or enterprise client.

  4. Remediation support

    Our specialists support your team with interpreting findings and prioritizing remediation. When facing a compliance deadline, we work together on a risk-based approach so critical issues are resolved first.

  5. Retest and supervisory authority support

    Formal retest of resolved vulnerabilities. During RDI inspections or external assessments we can be present to answer technical questions directly.

Who is required to comply with NIS2 and the Dutch Cybersecurity Act?

The Dutch Cybersecurity Act applies to essential and important entities in 18 sectors with at least 50 employees or €10 million turnover. Not sure whether your organization falls within scope? Contact us for a preliminary conversation.

Essential entities

Large organizations (250+ employees or €50M+ turnover) in critical sectors.

  • Energy and drinking water
  • Transport and postal services
  • Financial sector and insurers
  • Healthcare and pharmaceuticals
  • Digital infrastructure and cloud
  • ICT service management services
  • Government and public administration

Penalty: fines up to €10 million or 2% of global turnover.

Important entities

Medium-sized organizations (50+ employees or €10M+ turnover) in additional sectors.

  • Postal and courier services
  • Waste management
  • Food production, processing and distribution
  • Chemical production and distribution
  • Digital providers (marketplaces, search engines)
  • Research institutions
  • Critical manufacturing sectors

Penalty: fines up to €7 million or 1.4% of global turnover.

Even without a legal obligation, your enterprise clients or supply chain partners may require NIS2 conformity as part of their own supply chain security. For these situations we deliver the same reporting structure you can share directly with your clients.

Combining with other compliance engagements

NIS2 overlaps substantially with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:

NIS2 and ISO 27001

ISO 27001 certification covers a substantial portion of article 21 requirements. Findings double-mapped to Dutch Cybersecurity Act and Annex A controls.

More about ISO 27001 pentest

NIS2 and DigiD

For executive agencies that are both essential entity and have a DigiD connection. One coordinated engagement.

More about DigiD pentest

NIS2 and DORA

For financial entities. Both frameworks overlap substantially; we structure reporting to meet both compliance requirements.

Request DORA pentest

NIS2 and BIO2

For Dutch government organizations. NIS2 obligation combined with Baseline Informatiebeveiliging Overheid 2, usable for ENSIA reporting.

Request BIO2 pentest

NIS2 and NEN 7510

For healthcare organizations and healthcare IT vendors. Healthcare qualifies as essential entity; we combine with NEN 7510-specific controls.

Request NEN 7510 pentest

NIS2 and cyber insurance

An increasing number of cyber insurers require demonstrable NIS2 conformity as a condition for coverage. Our reporting meets these requirements.

Request a quotation

What does a NIS2 pentest cost?

The price depends on the size of your NIS2 scope, the number of systems and applications and any combined scopes with other compliance frameworks. For clearly defined engagements we offer standard packages. For essential entities with complex infrastructure we work with a scoping conversation and a tailored quotation.

  • Quick Pentest, €2,960 excl. VAT
  • Expert Pentest, from €5,040 excl. VAT (most chosen)
  • Extensive Pentest, from €7,200 excl. VAT
  • Enterprise and multi-scope engagements, tailored quotation

NIS2 scope as starting point

For every NIS2 engagement we start with a complimentary scoping conversation covering your entity classification, article 21 implementation and compliance strategy. This ensures you know exactly what the investment will be. See our pentest cost and plans for the fixed and starting prices.

Frequently asked questions about NIS2 pentesting

Below are the most frequently asked questions about NIS2 and Dutch Cybersecurity Act pentesting. For a complete overview please visit our FAQ page.

When does the Dutch Cybersecurity Act take effect?

The Dutch Cybersecurity Act (Cbw) has been in effect from 15 August 2026 as the Dutch implementation of NIS2 directive (EU) 2022/2555. The Dutch Senate approved the bill on 7 July 2026, the House of Representatives on 15 April 2026. There is no transition period: all obligations apply from day one. The Act replaces the earlier Network and Information Systems Security Act (Wbni) from 2018.

Am I an essential or important entity?

This depends on your activities, sector, size and any specific designations or exceptions. Employee count or turnover alone is not sufficient to determine your status; group relationships may also matter. Consult the NCSC guidance and, if needed, your sectoral supervisor or legal advisor. We can then align the technical assessment with the established scope and risks.

Is a pentest legally required under NIS2?

NIS2 requires a risk-based approach and procedures to assess the effectiveness of security measures. Article 21(2)(f) of the EU directive does not prescribe the same pentest or frequency for every organization. A pentest can be an appropriate technical assessment depending on your risks and the applicable Dutch and sectoral requirements. We tailor the assessment accordingly; the report is not proof of complete NIS2 compliance.

Do I need to register somewhere under the Dutch Cybersecurity Act?

Organizations covered by the Dutch Cybersecurity Act must register in the entity register. Duties of care and incident notification also apply. An initial notification of a significant incident is required as soon as possible and no later than 24 hours, followed by further reporting. Notifications through MijnNCSC are shared with the relevant sectoral CSIRT and supervisor. Consult the current NCSC guidance for registration, reporting deadlines and applicable exceptions.

What are the fines for non-compliance?

Possible sanctions depend on your legal status, the infringement and the applicable rules. In addition to a fine, a supervisor may require measures to address shortcomings. A pentest helps identify technical risks but does not automatically prevent sanctions or establish complete compliance. Ask your legal advisor or sectoral supervisor to assess the implications for your organization where needed.

What about supply chain requirements?

Article 21(2)(d) of the NIS2 directive addresses supply chain security. Customers may therefore set security requirements for you as a supplier, even if you are not directly covered by the Dutch Cybersecurity Act. The requirements depend on the risks, services and contractual arrangements. An appropriately scoped pentest report can provide technical evidence but is not a general NIS2 compliance statement.

Who is the supervisory authority under the Dutch Cybersecurity Act?

This depends on your sector. The RDI supervises several sectors but is not the supervisor for every organization. A supervisor oversees compliance, while a CSIRT supports organizations with cyber incidents. These are distinct roles. Notifications through MijnNCSC reach the relevant sectoral CSIRT and supervisor. Consult the NCSC overview for your sector.

Does a NIS2 pentest combine well with an ISO 27001 audit?

Yes. Where the technical assessment requirements overlap, one pentest can provide useful findings for both processes. We agree the systems, risks and requirements to assess and how findings will be mapped to the relevant frameworks. This avoids unnecessary duplicate testing. Your auditor or supervisor assesses whether the evidence is sufficient for the respective process.

How long does a NIS2 pentest take?

Active testing time ranges from 32 hours for a compact NIS2 scope to 120 hours or more for extensive multi-scope engagements at essential entities. Total duration from scoping conversation to final report is typically 4 to 8 weeks.

Demonstrable NIS2 compliant?

The Dutch Cybersecurity Act has been in effect and there is no transition period. Working toward demonstrable NIS2 compliance? Preparing for RDI oversight? Or does an enterprise client require a NIS2 statement in your supply chain? We start with a complimentary scoping conversation covering your entity classification and compliance strategy. Response within one business day. Quotation within three business days.