NIS2: testing that proves your measures work
NIS2 asks essential and important entities across the EU to manage cyber risk, report incidents quickly and show their security measures work. Here is what it requires, how it reaches UK organisations, and where testing fits.
What NIS2 is
NIS2, Directive (EU) 2022/2555, is the EU’s main cybersecurity law for organisations that keep society and the economy running. It replaced the original NIS Directive, and EU member states had until 17 October 2024 to write it into national law.
It covers medium and large organisations in 18 sectors. Eleven are classed as highly critical, including energy, transport, banking, health, drinking water, digital infrastructure, managed ICT services and public administration. Seven more are classed as other critical sectors, including postal services, waste management, chemicals, food, manufacturing, digital providers and research. Some organisations, such as DNS providers and trust service providers, are covered whatever their size.
In-scope organisations are either essential or important entities. Both must meet the same security measures; essential entities face proactive supervision, important entities supervision after the event.
The ten security measures
Article 21 requires appropriate and proportionate technical, operational and organisational measures, and lists ten minimum areas. Testing can provide evidence for most of them.
| Article 21(2) | Measure | Where testing helps |
|---|---|---|
| (a) | Risk analysis and information system security policies | Threat modelling |
| (b) | Incident handling | Tabletop exercises |
| (c) | Business continuity, backups and crisis management | Tabletop exercises |
| (d) | Supply chain security | Attack surface management, supplier testing |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling | Vulnerability management, application testing |
| (f) | Policies to assess whether your security measures work | Penetration testing, red teaming |
| (g) | Basic cyber hygiene and training | Phishing simulation |
| (h) | Cryptography and encryption | Covered in application, cloud and infrastructure testing |
| (i) | Human resources security, access control and asset management | Asset discovery, identity review |
| (j) | Multi-factor authentication and secured communications | Tested in cloud and phishing engagements |
Point (f) matters most here: you need policies and procedures to assess whether your measures actually work. Regular penetration testing and red teaming are the most direct way to show they do.
Incident reporting and accountability
Article 23 sets tight deadlines for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month. Rehearsing those deadlines in a tabletop exercise is far better than meeting them for the first time in a real incident.
Article 20 makes management bodies responsible for approving the measures and overseeing them, and requires them to take training. Member states can hold them liable for failures.
Fines can reach €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher.
What it means for UK organisations
NIS2 does not apply in the UK. UK operators of essential services and relevant digital service providers are covered by the NIS Regulations 2018, which the Cyber Security and Resilience Bill, introduced to Parliament in November 2025, sets out to update and extend, including to managed service providers and data centres.
NIS2 still matters to UK organisations if you provide services in the EU, where you must comply in the member states you operate in, or if you supply EU organisations that are in scope. Supply chain security is one of the ten measures, so your EU customers will pass requirements down to you through contracts and questionnaires.
How APOLLOSEC helps
- Evidence that your measures work, through penetration testing and red teaming under Article 21(2)(f).
- Vulnerability handling with an audit trail: findings, deadlines and retests recorded on the platform.
- Supply chain visibility through attack surface management, including assets run by suppliers under your name.
- Incident rehearsal against the 24-hour, 72-hour and one-month reporting deadlines.
- Awareness you can measure through phishing simulation.