EresusSecurity
Back to Research
Guide

NIS2 Compliance and Penetration Testing: Article 21, the 24-Hour Clock, and €10M Fine Risk

Yiğit İbrahim SağlamOffensive Security Specialist
August 24, 2026
6 min read
GuideCompliance

NIS2 Compliance and Penetration Testing: Article 21, the 24-Hour Clock, and €10M Fine Risk

The EU's NIS2 Directive has been in force across member states since 17 October 2024. The difference from the first NIS Directive in one sentence: NIS1 was advisory; NIS2 has teeth. For essential entities, it prescribes administrative fines of at least €10 million or 2% of global annual turnover — whichever is higher. And management bodies face personal accountability for non-compliance.

This guide covers who NIS2 captures, where penetration testing sits in Article 21's security measures, what Implementing Regulation 2024/2690 expects from security testing, and how non-EU suppliers to the EU should prepare.

Who NIS2 Captures: Essential and Important Entities

NIS2 establishes two categories across 18 sectors:

Highly critical sectors (essential entities): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, space.

Other critical sectors (important entities): postal and courier, waste management, chemicals, food, manufacturing (electronics, machinery, vehicles, medical devices), digital providers (marketplaces, search engines, social networks), research.

Size threshold: medium-sized and larger entities (50+ employees or €10M+ turnover) fall in scope. Some provider types (DNS, cloud, data centres, managed security services, trust services) are captured regardless of size.

The Turkey connection: companies based outside the EU but providing these services to EU customers — especially MSPs, MSSPs, cloud and software development — feel NIS2 through its supply chain provisions: your EU customer is obliged to assess the cybersecurity practices of their suppliers under Article 21(2)(d). That's where the questionnaires, contract clauses, and audit requests come from.

Article 21: The Security Measures List

Article 21(2) enumerates the measures essential and important entities must take — all on an "all-hazards" basis:

  1. Risk analysis and information system security policies
  2. Incident handling
  3. Business continuity (backup, disaster recovery, crisis management)
  4. Supply chain security — including vulnerabilities of direct suppliers
  5. Security in network acquisition, development and maintenance (including vulnerability handling and disclosure)
  6. Procedures to assess effectiveness of cybersecurity measures
  7. Basic cyber hygiene and training
  8. Cryptography and encryption policies
  9. HR security, access control, asset management
  10. Multi-factor authentication and secured communication channels

The list doesn't spell out "penetration testing" — because Article 21(5) delegates the technical and methodological requirements to the Commission. Those requirements landed in Implementing Regulation 2024/2690.

2024/2690: Regular Security Testing, Now Explicit

The Implementing Regulation, published November 2024, details Article 21(2) for digital infrastructure and ICT service management providers. Recital 15 is direct:

"The relevant entities should regularly carry out security tests based on a dedicated policy and procedures to verify whether the cybersecurity risk-management measures are implemented and function properly. Security tests... may include automated or manual tests, penetration tests, vulnerability scanning, static and dynamic application security tests, configuration tests or security audits."

The Regulation further expects security testing at system set-up, after significant infrastructure or application upgrades, and after maintenance — with test findings feeding back into policies and independent reviews.

Reading: under NIS2, testing is not an annual checkbox — it's a policy-linked, change-triggered cycle whose findings feed governance.

Article 23: The 24/72/720-Hour Reporting Chain

NIS2's incident reporting regime is stricter than a single 72-hour window:

  • 24 hours: early warning from awareness (is this suspicious, potentially significant?)
  • 72 hours: incident notification (initial assessment, severity and impact indicators)
  • On request: interim report
  • 1 month: final report (root cause, detailed description)

The "significant incident" threshold is also concrete: for example, direct financial loss exceeding €500,000 or 5% of annual turnover, exfiltration of trade secrets, death or serious health damage, or unauthorized access capable of causing severe operational disruption.

Pentest connection: issuing an "early warning" within 24 hours depends on detection capacity actually working. The rehearsal for detection rules, log infrastructure, and incident response procedures is regular penetration testing and red teaming.

Management Bodies' Personal Accountability

One of NIS2's most overlooked provisions is Article 20: management bodies must approve and oversee the implementation of security measures and can be held liable for infringements. Member states may also require management cybersecurity training.

Practical consequence: pentest findings, remediation timelines, and risk acceptance decisions documented in board reporting are no longer IT's internal matter — they are the governing body's legal responsibility.

The Non-EU Supplier's Preparation Path

If your EU customer is an NIS2 entity, expect these demands:

  1. Supplier security assessment (Article 21(2)(d)): your security policies, testing cadence, incident response capability
  2. Contract clauses: incident notification timelines, audit rights, security commitments
  3. In some sectors: your customer's auditors testing your environment

Priority order for preparation:

Step What to do Why
1 Security policy set aligned with Article 21(2)(a) First question in every questionnaire
2 Annual pentest + vulnerability scan cadence with report archive Proof of "regular testing"
3 Incident response runbook + 24/72-hour rehearsal Contractual notification deadlines
4 MFA and access control inventory Article 21(2)(i) and explicit Regulation expectation
5 Your own supply chain assessment The chain question moves one level down

Frequently Asked Questions

What are the NIS2 fines for non-compliance?

Essential entities: at least €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities: at least €7 million or 1.4%. Additional measures include binding instructions, orders to implement security audit recommendations, and periodic penalty payments.

Does NIS2 Article 21 mandate penetration testing?

Article 21(2) lists measures and delegates frequency/methodology to the Commission. Implementing Regulation 2024/2690 (for digital infrastructure and ICT service management providers) explicitly names regular security tests and cites penetration tests among them. In practice: entities in scope are expected to run a policy-linked, regular testing cycle whose findings feed governance.

Does my Turkish company fall under NIS2?

If you provide services in the EU or have an entity established in a member state, you may be directly in scope. Even if not, your EU customers must assess supply chain security under Article 21(2)(d) — so NIS2 expectations reach you through contracts and questionnaires.

What are NIS2 incident reporting deadlines?

Early warning within 24 hours of awareness, incident notification within 72 hours, interim report on request, final report within one month. Significant incident thresholds include financial loss over €500,000 or 5% of turnover, and unauthorized access capable of causing severe operational disruption.

Should NIS2 and KVKK/GDPR be considered together?

Yes — an NIS2 entity processing personal data sits at the intersection of two regimes: KVKK/GDPR breach notification and NIS2 incident reporting have different thresholds and deadlines. A single incident response plan designed for both reduces double-penalty risk.

Closing

NIS2 turned cybersecurity in the EU from "IT's job" into a governing body's legal responsibility. Penetration testing is the evidentiary link in that structure: it proves your policies work, your detection meets the 24-hour threshold, and your supply chain commitments are not empty words.

Eresus Security provides testing and readiness assessments for NIS2 entities and companies in EU supply chains. To evaluate your compliance posture, request a scoping call.

Security Validation

Have you tested this risk in your own system?

Eresus Security delivers real exploit evidence through penetration testing, AI agent security, and red team operations.

Request a pilot test

Related Services