COMPLIANCE

NIS2 Compliance

NIS2 (Directive (EU) 2022/2555) expands cybersecurity obligations across critical and important entities in the EU. Technical security testing is one of the risk-based measures Article 21 requires. This page explains what NIS2 expects, how testing supports those measures, and what evidence regulators look for.

NIS2 IN FINLAND

Which Finnish companies does NIS2 apply to?

In Finland, NIS2 is transposed into national law through the Finnish Cybersecurity Act (kyberturvallisuuslaki), with the Finnish Transport and Communications Agency (Traficom) acting as the national competent authority. It applies to essential and important entities operating in Finland across critical sectors: energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, public administration, space, postal and courier, waste management, and the manufacture of critical equipment. Size thresholds and sector sub-categories determine whether an organisation is an essential or important entity; some entities — such as DNS service providers, public administration bodies, and certain market infrastructure operators — are in scope regardless of size.

Key obligations

Article 21 requires entities to implement risk-based technical, operational, and organisational measures: vulnerability handling and disclosure, network security, access control and authentication, encryption, incident handling and response, business continuity, supply chain security, secure development, and the regular testing and verification of the effectiveness of security measures. Senior management bears accountability for cybersecurity governance and must approve and oversee the risk management measures, with personal liability for governance failures.

Deadlines

The directive entered into force on 18 January 2023 and applied from 18 October 2024, with member states required to transpose it into national law by 17 October 2024. For significant incidents, an early warning must be filed within 24 hours, a full incident notification within 72 hours, and a final report within one month. Finnish national timelines align with these EU-level requirements.

Penalties for non-compliance

Essential entities face administrative fines of up to €10 million or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. Important entities face up to €7 million or 1.4%. Member states must also provide for personal liability for management bodies in the event of governance failures. Traficom is responsible for enforcement and supervision in Finland.

How a readiness assessment works

A readiness assessment begins with an applicability assessment to confirm whether your organisation is in scope and classified as essential or important. A gap analysis against the Article 21 measures follows, covering governance, incident reporting, supply chain risk, and technical controls. The output is a prioritised remediation roadmap aligned to your risk assessment and regulatory deadlines, with evidence structured so that Traficom or an auditor can trace each measure to operating controls. Where testing is included, findings are mapped to the relevant Article 21 measures.

WHAT NIS2 REQUIRES

What does NIS2 require of our organisation?

NIS2 (Directive (EU) 2022/2555) requires essential and important entities across critical and important sectors to implement risk-based technical, operational, and organisational measures to manage cybersecurity risks. Article 21 sets out the minimum measures, including vulnerability handling and disclosure, network security, access control, incident handling, and the regular testing and verification of the effectiveness of security measures. Member states may add specifics through national implementation, but the Article 21 baseline applies across the EU.

Senior management bears accountability for cybersecurity governance and must approve and oversee the risk management measures. Non-compliance can carry significant penalties, and entities must demonstrate that measures are operating, not merely documented in policy.

Are we an essential or important entity?

Classification depends on sector, size, and role. Essential and important entities are defined in the directive across critical and important sectors. The NIS2 Compliance Advisory service assesses applicability and classification based on your operations. Final determination is made by your competent national authority under national law; this page does not constitute legal classification advice.

Which Article 21 measures involve testing?

The measures most directly involving testing are vulnerability handling and disclosure, network security, and the ongoing verification of effectiveness. Documented penetration testing provides evidence that these measures are operating. The scope of testing should align with the entity's risk assessment and the systems in scope.

HOW TESTING MAPS TO NIS2

How does penetration testing map to NIS2 Article 21?

Penetration testing does not by itself achieve NIS2 compliance. It provides evidence for specific Article 21 measures, particularly vulnerability handling, network security, and the requirement to verify the effectiveness of security measures. Testing is one input into the broader risk management programme the directive requires, alongside governance, incident reporting, and supply chain risk management.

Does a penetration test make us NIS2 compliant?

No. NIS2 compliance requires the full set of technical, operational, and organisational measures, governance, incident reporting, and supply chain risk management. A penetration test supports specific measures but does not replace the management system or the other obligations the directive imposes on essential and important entities.

How often should we test under NIS2?

NIS2 does not prescribe a fixed testing frequency. It requires risk-based measures and ongoing effectiveness review. Testing frequency should reflect your risk profile, the rate of change to your systems, and your entity classification. We help determine an appropriate cadence during scoping rather than applying a generic interval.

Which VariHunt services support which Article 21 measures?

  • Web Application Penetration Testing supports vulnerability handling and secure development for web-facing systems.
  • API Security Testing covers the API surfaces that Article 21 network security measures address.
  • IT Security & Audit Services delivers the gap analysis against Article 21 and the remediation roadmap.
  • NIS2 Compliance Advisory provides applicability classification, governance, and incident reporting procedures including the 72-hour notification obligation.
  • Tabletop & Desktop Exercises test incident response readiness, a core NIS2 obligation.

EVIDENCE

What evidence do regulators and auditors expect?

Regulators and auditors expect documented evidence that Article 21 measures are operating. This typically includes current penetration test reports, a vulnerability management process with remediation tracking, incident response procedures with tested escalation, and management oversight records showing governance and accountability.

What should the test report include for NIS2?

The report should define scope, rate findings by severity, map each finding to the relevant Article 21 measure, and include remediation status. A retest confirming remediated findings strengthens the evidence. Reports should be current relative to the audit or regulatory review window, and scoped to the systems covered by your risk assessment.

Is a retest included?

Where the engagement includes penetration testing, a retest of remediated findings is included in the engagement price. Verified fixes are documented and an attestation letter is issued. The engagement is not considered closed until the retest is complete.

ENGAGEMENT STRUCTURE

How does VariHunt structure a NIS2 engagement?

A NIS2 engagement typically begins with an applicability assessment to confirm whether your organisation is in scope and whether it is an essential or important entity. A gap analysis against Article 21 measures follows, covering governance, incident reporting, supply chain risk, and the technical measures. The output is a prioritised remediation roadmap aligned to your risk assessment.

What does the advisory deliverable contain?

The deliverable includes the applicability assessment, the gap analysis mapped to Article 21 measures, a prioritised remediation roadmap, and incident reporting procedures designed to meet the 72-hour notification obligation. Where testing is included, findings are mapped to the relevant measures with remediation status.

Do you work with our existing risk assessment?

Yes. Where a risk assessment exists, we align the engagement to it so testing and gaps map to the risks you have already identified. Where one does not exist, the advisory can include developing a risk assessment as part of the programme.

GETTING STARTED

What do we need to provide before a NIS2-aligned engagement?

Before starting, we need your sector, approximate size, and current security documentation. Any existing risk assessment, prior test reports, and regulatory deadlines help us scope accurately. Rules of engagement, points of contact, and the systems or programmes in scope are agreed during the scoping call before any work begins.

Can VariHunt certify our NIS2 compliance?

No. VariHunt is not a certification body or a competent authority. We provide testing and advisory that support your compliance programme. Formal compliance determination is made by your competent national authority under national implementation of the directive.

FAQ

Frequently asked questions

How long does a NIS2 engagement take?

Duration depends on entity classification, the number of in-scope systems, and current control maturity. An applicability and gap assessment and a full remediation programme differ in length. A precise timeline is agreed during scoping rather than stated in advance, and aligned to any regulatory deadline you must meet.

What methodology do you follow?

NIS2 advisory uses the Article 21 minimum security measures as the assessment baseline, mapped to national implementation where relevant. Technical testing within the engagement follows OWASP WSTG for web and OWASP MASVS for mobile, with CVSS v3.1 for severity rating. Every finding is manually validated.

Is a retest included?

Where the engagement includes penetration testing, a retest of remediated findings is included in the price. Verified fixes are documented and an attestation letter is issued. The engagement is not considered closed until the retest is complete and the evidence is finalised.

What does the report contain?

The deliverable includes an applicability assessment, a gap analysis against Article 21 measures, severity-rated findings where testing was performed, and a prioritised remediation roadmap. Each finding is mapped to the relevant Article 21 measure and includes remediation status and retest evidence.

How does this map to NIS2?

Findings and gaps are mapped directly to NIS2 Article 21 security measures, including vulnerability handling, network security, and effectiveness verification. This lets auditors and risk functions trace each item to the directive's requirements and to your risk management programme and control evidence.

What do you need from us before starting?

We need your sector, approximate size, current security documentation, and the systems or programmes in scope. Any existing risk assessment, prior test reports, and regulatory deadlines help. Rules of engagement and points of contact are agreed during scoping before work begins.

Discuss your compliance timeline

Book a scoping call to align testing with your audit or regulatory deadlines.