COMPLIANCE
NIS2 (Directive (EU) 2022/2555) expands cybersecurity obligations across critical and important entities in the EU. Technical security testing is one of the risk-based measures Article 21 requires. This page explains what NIS2 expects, how testing supports those measures, and what evidence regulators look for.
NIS2 IN FINLAND
In Finland, NIS2 is transposed into national law through the Finnish Cybersecurity Act (kyberturvallisuuslaki), with the Finnish Transport and Communications Agency (Traficom) acting as the national competent authority. It applies to essential and important entities operating in Finland across critical sectors: energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, public administration, space, postal and courier, waste management, and the manufacture of critical equipment. Size thresholds and sector sub-categories determine whether an organisation is an essential or important entity; some entities — such as DNS service providers, public administration bodies, and certain market infrastructure operators — are in scope regardless of size.
Article 21 requires entities to implement risk-based technical, operational, and organisational measures: vulnerability handling and disclosure, network security, access control and authentication, encryption, incident handling and response, business continuity, supply chain security, secure development, and the regular testing and verification of the effectiveness of security measures. Senior management bears accountability for cybersecurity governance and must approve and oversee the risk management measures, with personal liability for governance failures.
The directive entered into force on 18 January 2023 and applied from 18 October 2024, with member states required to transpose it into national law by 17 October 2024. For significant incidents, an early warning must be filed within 24 hours, a full incident notification within 72 hours, and a final report within one month. Finnish national timelines align with these EU-level requirements.
Essential entities face administrative fines of up to €10 million or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. Important entities face up to €7 million or 1.4%. Member states must also provide for personal liability for management bodies in the event of governance failures. Traficom is responsible for enforcement and supervision in Finland.
A readiness assessment begins with an applicability assessment to confirm whether your organisation is in scope and classified as essential or important. A gap analysis against the Article 21 measures follows, covering governance, incident reporting, supply chain risk, and technical controls. The output is a prioritised remediation roadmap aligned to your risk assessment and regulatory deadlines, with evidence structured so that Traficom or an auditor can trace each measure to operating controls. Where testing is included, findings are mapped to the relevant Article 21 measures.
WHAT NIS2 REQUIRES
NIS2 (Directive (EU) 2022/2555) requires essential and important entities across critical and important sectors to implement risk-based technical, operational, and organisational measures to manage cybersecurity risks. Article 21 sets out the minimum measures, including vulnerability handling and disclosure, network security, access control, incident handling, and the regular testing and verification of the effectiveness of security measures. Member states may add specifics through national implementation, but the Article 21 baseline applies across the EU.
Senior management bears accountability for cybersecurity governance and must approve and oversee the risk management measures. Non-compliance can carry significant penalties, and entities must demonstrate that measures are operating, not merely documented in policy.
Classification depends on sector, size, and role. Essential and important entities are defined in the directive across critical and important sectors. The NIS2 Compliance Advisory service assesses applicability and classification based on your operations. Final determination is made by your competent national authority under national law; this page does not constitute legal classification advice.
The measures most directly involving testing are vulnerability handling and disclosure, network security, and the ongoing verification of effectiveness. Documented penetration testing provides evidence that these measures are operating. The scope of testing should align with the entity's risk assessment and the systems in scope.
HOW TESTING MAPS TO NIS2
Penetration testing does not by itself achieve NIS2 compliance. It provides evidence for specific Article 21 measures, particularly vulnerability handling, network security, and the requirement to verify the effectiveness of security measures. Testing is one input into the broader risk management programme the directive requires, alongside governance, incident reporting, and supply chain risk management.
No. NIS2 compliance requires the full set of technical, operational, and organisational measures, governance, incident reporting, and supply chain risk management. A penetration test supports specific measures but does not replace the management system or the other obligations the directive imposes on essential and important entities.
NIS2 does not prescribe a fixed testing frequency. It requires risk-based measures and ongoing effectiveness review. Testing frequency should reflect your risk profile, the rate of change to your systems, and your entity classification. We help determine an appropriate cadence during scoping rather than applying a generic interval.
EVIDENCE
Regulators and auditors expect documented evidence that Article 21 measures are operating. This typically includes current penetration test reports, a vulnerability management process with remediation tracking, incident response procedures with tested escalation, and management oversight records showing governance and accountability.
The report should define scope, rate findings by severity, map each finding to the relevant Article 21 measure, and include remediation status. A retest confirming remediated findings strengthens the evidence. Reports should be current relative to the audit or regulatory review window, and scoped to the systems covered by your risk assessment.
Where the engagement includes penetration testing, a retest of remediated findings is included in the engagement price. Verified fixes are documented and an attestation letter is issued. The engagement is not considered closed until the retest is complete.
ENGAGEMENT STRUCTURE
A NIS2 engagement typically begins with an applicability assessment to confirm whether your organisation is in scope and whether it is an essential or important entity. A gap analysis against Article 21 measures follows, covering governance, incident reporting, supply chain risk, and the technical measures. The output is a prioritised remediation roadmap aligned to your risk assessment.
The deliverable includes the applicability assessment, the gap analysis mapped to Article 21 measures, a prioritised remediation roadmap, and incident reporting procedures designed to meet the 72-hour notification obligation. Where testing is included, findings are mapped to the relevant measures with remediation status.
Yes. Where a risk assessment exists, we align the engagement to it so testing and gaps map to the risks you have already identified. Where one does not exist, the advisory can include developing a risk assessment as part of the programme.
GETTING STARTED
Before starting, we need your sector, approximate size, and current security documentation. Any existing risk assessment, prior test reports, and regulatory deadlines help us scope accurately. Rules of engagement, points of contact, and the systems or programmes in scope are agreed during the scoping call before any work begins.
No. VariHunt is not a certification body or a competent authority. We provide testing and advisory that support your compliance programme. Formal compliance determination is made by your competent national authority under national implementation of the directive.
FAQ
Duration depends on entity classification, the number of in-scope systems, and current control maturity. An applicability and gap assessment and a full remediation programme differ in length. A precise timeline is agreed during scoping rather than stated in advance, and aligned to any regulatory deadline you must meet.
NIS2 advisory uses the Article 21 minimum security measures as the assessment baseline, mapped to national implementation where relevant. Technical testing within the engagement follows OWASP WSTG for web and OWASP MASVS for mobile, with CVSS v3.1 for severity rating. Every finding is manually validated.
Where the engagement includes penetration testing, a retest of remediated findings is included in the price. Verified fixes are documented and an attestation letter is issued. The engagement is not considered closed until the retest is complete and the evidence is finalised.
The deliverable includes an applicability assessment, a gap analysis against Article 21 measures, severity-rated findings where testing was performed, and a prioritised remediation roadmap. Each finding is mapped to the relevant Article 21 measure and includes remediation status and retest evidence.
Findings and gaps are mapped directly to NIS2 Article 21 security measures, including vulnerability handling, network security, and effectiveness verification. This lets auditors and risk functions trace each item to the directive's requirements and to your risk management programme and control evidence.
We need your sector, approximate size, current security documentation, and the systems or programmes in scope. Any existing risk assessment, prior test reports, and regulatory deadlines help. Rules of engagement and points of contact are agreed during scoping before work begins.
Book a scoping call to align testing with your audit or regulatory deadlines.