Penetration Testing Hub › Penetration Testing Explained
Penetration Testing for NIS2 Compliance
This page covers compliance rather than technique, but the site's rule holds throughout: only ever test systems you own or are explicitly authorised to test, under the Criminal Justice (Offences Relating to Information Systems) Act 2017.
NIS2 is the EU directive that widens and sharpens cybersecurity obligations for a large set of organisations — and it has brought a lot of Irish companies into scope for the first time. This page explains where penetration testing fits: what NIS2 actually expects, whether a test is strictly required, and how to make sure a test produces the evidence a regulator will accept.
Check the current status
Ireland's transposition of NIS2 was still being finalised as this was written. Confirm the current position and the exact obligations for your sector before acting — this page explains the shape of the requirement, not a fixed legal deadline.
What NIS2 expects
NIS2 requires in-scope 'essential' and 'important' entities to put in place appropriate, risk-based cybersecurity measures — and, crucially, to be able to demonstrate that those measures actually work. It doesn't hand you a checklist of tools. It expects risk management, incident handling, business continuity, supply-chain security, and evidence that you test and assess the effectiveness of your controls.
That word — effectiveness — is where testing comes in. You can claim your controls work; a penetration test is a direct, independent way to show they do.
Is penetration testing strictly required?
NIS2 doesn't name 'penetration testing' as a mandatory line item the way PCI DSS does. What it requires is that you assess the effectiveness of your security measures. In practice, penetration testing (alongside vulnerability scanning and other assessment) is the most recognised, defensible way to meet that expectation. A regulator asking 'how do you know your measures work?' is far better answered with a test report than with a policy document.
How testing supports each obligation
- Risk management — a test gives you real, prioritised findings to feed your risk register, rather than theoretical risks.
- Effectiveness of measures — the core evidence: proof your controls hold, or a clear list of where they don't.
- Incident handling — testing (especially red-team-style work) shows whether you'd actually detect and respond to an attack.
- Supply chain — testing exposed systems and third-party integrations helps you see the risk partners introduce.
- Governance — a repeatable testing programme demonstrates the management accountability NIS2 emphasises.
Turning a test into NIS2 evidence
A test only helps your compliance if it's documented the way an assessor expects. Make sure:
- The scope maps to your important systems, not just the easy ones.
- Findings are risk-rated and tracked to remediation, with dates.
- A re-test confirms fixes — closing the loop is the evidence that matters.
- Testing is periodic and after significant change, not a one-off.
- The report and remediation trail are retained and presentable.
Where to start
If NIS2 has just brought you into scope, don't start with a big red-team exercise. Start by doing the basics (the groundwork in our 'do you need one yet' guide), then scope a penetration test against the systems that carry the most risk, and build a repeatable rhythm from there. For financial entities, DORA sets a stricter, threat-led testing regime on top — see our DORA hub.
Common questions
Does NIS2 require penetration testing?
NIS2 doesn't name penetration testing as a mandatory item, but it requires in-scope entities to assess the effectiveness of their security measures — and testing is the most recognised way to do that. A regulator asking how you know your controls work is far better answered with a test report and remediation trail than with policy documents alone.
Who is in scope for NIS2 in Ireland?
NIS2 covers a broad range of 'essential' and 'important' entities across sectors like energy, transport, health, digital infrastructure, and more, generally above certain size thresholds. Ireland's transposition sets the precise scope, and it was still being finalised as this was written — confirm your sector's current obligations before acting.
How often should we test for NIS2?
There's no fixed number, but the expectation is that testing is periodic and triggered by significant change, not a one-off. A defensible rhythm is at least annually plus after major changes, with findings tracked to remediation and a re-test to close the loop — that trail is what demonstrates ongoing effectiveness.
If NIS2 has brought you into scope and you want testing that produces evidence a regulator will accept, here's how a CyberLabs engagement works — scoped to your important systems, documented for compliance.
No prices on this page and no hard sell.
This page is educational and not legal advice. Only test systems you own or are explicitly authorised to test. · ↑ Back to top