NIS2 Penetration Testing Requirements: A 5-Step Plan for UK Suppliers

by Rebecca Sutton

An EU customer’s contract mentions NIS2. The real question is not “what is this directive.” It is “what do we now have to do about testing.” NIS2 penetration testing requirements come from Article 21. It demands that businesses prove their security controls actually work. UK suppliers get pulled into that demand through contracts, even though NIS2 itself is EU law. Here is a working plan for a UK firm trying to get ahead of it.

Step 1: work out whether NIS2 actually reaches you

NIS2 is the EU’s Network and Information Systems Directive. It covers eighteen sectors, from energy and healthcare to digital infrastructure, postal services and public administration. EU member states had until 17 October 2024 to write it into national law. Most missed that date. The European Commission chased 23 states over the delay. Most have since caught up and started active enforcement.

None of that binds a UK company directly. What matters is simpler: do you supply goods, software, hosting or services to an business regulated under NIS2? Those businesses must manage risk across their own supply chains. So the obligation flows downhill, through contracts, security questionnaires and audit clauses. It lands on suppliers who were never “in scope” in a legal sense.

Start with your contracts. Check existing and upcoming agreements with EU customers for any mention of NIS2, security audits, or a right to inspect your controls. That single check tells you how urgent the rest of this list is.

Business colleagues reviewing contract paperwork, the kind of EU customer agreement that can bring NIS2 penetration testing requirements to a UK supplier

Does it matter if your customer is “essential” or “important”?

NIS2 splits regulated businesses into two tiers. The tier your EU customer sits in shapes how strict their demands on you will be. Large entities count as essential: broadly, 250 or more staff, or turnover above €50 million, in higher-risk sectors such as energy, transport, banking and health. Medium-sized businesses count as important: roughly 50 to 249 staff, or €10 million to €50 million in turnover, across a wider range of sectors.

Either figure is enough to cross the threshold. An business does not need to hit both the headcount and the turnover mark. A small number of businesses are in scope regardless of size, including sole providers of a critical national service. Essential entities face closer supervision and earlier audits. A supplier to one of them should expect requirements to arrive sooner, and to be checked more closely, than a supplier to a smaller, important-tier customer.

Step 2: understand the NIS2 penetration testing requirements in Article 21

Article 21(2) lists the risk-management measures that essential and important entities must have. One item is a policy to assess whether cybersecurity measures actually work. NIS2 never uses the phrase “penetration testing.” Two of its recitals point straight at it anyway. Recital 49 names penetration testing as a way to catch missing patches and weak passwords. Recital 58 ties fast detection of exploitable flaws to sound risk management.

Regulators and auditors have settled on one reading of this. A vulnerability scan alone will not satisfy Article 21 for anything that matters. Real, human-led penetration testing is what “assessing effectiveness” means in practice.

Step 3: set a defensible testing cadence

NIS2 sets no exact schedule. Businesses default to established practice instead. Annual testing is treated as a minimum, not a strategy. A fresh test should follow any major infrastructure change, a new application going live, or a security incident. If your EU customer’s contract sets its own frequency, that figure overrides the general default.

Do not stop at the calendar date, though. Systems that change constantly between annual tests carry risk the test never catches. Many businesses pair one thorough scoped engagement a year with lighter, more frequent testing of whatever has changed since.

Step 4: scope the test and choose who runs it

Match the test to what your EU customer actually cares about. That usually means the systems, applications or connections that touch their data or their supply chain. A test that ignores that boundary wastes budget on the wrong assets. Never bought a test before? It is worth learning the warning signs that separate a genuine provider from a scan with a report template before quotes start arriving.

Pick a tester who can produce a report an auditor will actually accept. That means a clear, documented testing methodology, evidence behind each finding, and a retest once issues are fixed. A pile of raw scanner output will not satisfy a customer’s compliance team, whatever the testing underneath was worth. Independent accreditation, such as CREST membership in the UK, gives that compliance team an external reason to trust the result, rather than having to judge your tester’s competence themselves.

Ask any provider how they handle retesting before you sign anything. A report that lists findings but never confirms they were fixed leaves the evidence trail half finished, and that is exactly the gap an auditor tends to notice first. Would rather not work out the scope alone? Aardwolf Security can help build a test around what your EU customer’s contract actually asks for, instead of a generic package that may miss the point.

Step 5: keep the evidence an audit will ask for

Save the scope document, the report, remediation records and any retest confirmation together. Keep them ready to produce quickly. It helps to know what a thorough penetration test report actually looks like, so you can judge whether the one you have filed away will hold up. NIS2-driven customer contracts increasingly carry audit rights. A business that can hand over clean, dated evidence answers the question in minutes rather than weeks.

What happens if you ignore the NIS2 penetration testing requirements

An EU entity regulated under NIS2 faces real fines directly. Essential entities risk up to €10 million or 2% of global turnover. Important entities risk up to €7 million or 1.4%. Germany has gone further still, allowing fines up to €20 million under its own implementing law.

A UK supplier will not receive those fines from an EU regulator. But the practical cost is still real: a failed security questionnaire, a lost contract renewal, or removal from an approved supplier list, all because the required evidence never arrived.

How this sits alongside the UK’s own rules

The UK is not standing still on this either. Its own equivalent, the Cyber Security and Resilience Bill, was introduced to Parliament in November 2025. It covers similar ground, expanding regulation to managed service providers, data centres and designated critical suppliers, with a tighter incident reporting window than most UK businesses currently follow. It runs on a separate track from NIS2, with its own scope and enforcement. A UK business with EU customers can end up needing to satisfy both regimes at once.

Has a contract, a security questionnaire or an internal audit raised NIS2 for your business? Get in touch with Aardwolf Security for a straightforward conversation about scope, before deadline pressure forces the decision.

FAQ

Do UK companies need to register or report to an NIS2 regulator?

No. NIS2 registration and direct enforcement apply to entities regulated by EU member states. A UK company only feels its effects through the contracts it signs with those entities.

Will a basic vulnerability scan satisfy an EU customer’s NIS2 requirement?

Usually not on its own. Article 21 and its recitals point towards genuine, human-led penetration testing as the accepted way to prove security controls work. An automated scan report rarely does that on its own.

How quickly should a UK supplier act once NIS2 comes up in a contract?

Treat it as a near-term priority. Scoping and running a proper penetration test, then fixing what it finds, takes weeks rather than days. Customers usually attach a deadline to the requirement, too.

Does passing one penetration test settle the matter for good?

No. NIS2-style obligations expect ongoing assessment. Plan for annual testing at minimum, plus extra tests after any significant change to your systems.

What are the core NIS2 penetration testing requirements in one sentence?

Prove, with a properly scoped and documented penetration test, that your security controls work, repeat that proof at least once a year, and keep the evidence ready for audit.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like