APOLLOSEC

NIS2: testing that proves your measures work

NIS2 asks essential and important entities across the EU to manage cyber risk, report incidents quickly and show their security measures work. Here is what it requires, how it reaches UK organisations, and where testing fits.

Last reviewed 9 October 2026. This page explains the law in plain English; it is not legal advice.

What NIS2 is

NIS2, Directive (EU) 2022/2555, is the EU’s main cybersecurity law for organisations that keep society and the economy running. It replaced the original NIS Directive, and EU member states had until 17 October 2024 to write it into national law.

It covers medium and large organisations in 18 sectors. Eleven are classed as highly critical, including energy, transport, banking, health, drinking water, digital infrastructure, managed ICT services and public administration. Seven more are classed as other critical sectors, including postal services, waste management, chemicals, food, manufacturing, digital providers and research. Some organisations, such as DNS providers and trust service providers, are covered whatever their size.

In-scope organisations are either essential or important entities. Both must meet the same security measures; essential entities face proactive supervision, important entities supervision after the event.

The ten security measures

Article 21 requires appropriate and proportionate technical, operational and organisational measures, and lists ten minimum areas. Testing can provide evidence for most of them.

Article 21(2)MeasureWhere testing helps
(a)Risk analysis and information system security policiesThreat modelling
(b)Incident handlingTabletop exercises
(c)Business continuity, backups and crisis managementTabletop exercises
(d)Supply chain securityAttack surface management, supplier testing
(e)Security in acquisition, development and maintenance, including vulnerability handlingVulnerability management, application testing
(f)Policies to assess whether your security measures workPenetration testing, red teaming
(g)Basic cyber hygiene and trainingPhishing simulation
(h)Cryptography and encryptionCovered in application, cloud and infrastructure testing
(i)Human resources security, access control and asset managementAsset discovery, identity review
(j)Multi-factor authentication and secured communicationsTested in cloud and phishing engagements

Point (f) matters most here: you need policies and procedures to assess whether your measures actually work. Regular penetration testing and red teaming are the most direct way to show they do.

Incident reporting and accountability

Article 23 sets tight deadlines for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month. Rehearsing those deadlines in a tabletop exercise is far better than meeting them for the first time in a real incident.

Article 20 makes management bodies responsible for approving the measures and overseeing them, and requires them to take training. Member states can hold them liable for failures.

Fines can reach €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher.

What it means for UK organisations

NIS2 does not apply in the UK. UK operators of essential services and relevant digital service providers are covered by the NIS Regulations 2018, which the Cyber Security and Resilience Bill, introduced to Parliament in November 2025, sets out to update and extend, including to managed service providers and data centres.

NIS2 still matters to UK organisations if you provide services in the EU, where you must comply in the member states you operate in, or if you supply EU organisations that are in scope. Supply chain security is one of the ten measures, so your EU customers will pass requirements down to you through contracts and questionnaires.

How APOLLOSEC helps

  • Evidence that your measures work, through penetration testing and red teaming under Article 21(2)(f).
  • Vulnerability handling with an audit trail: findings, deadlines and retests recorded on the platform.
  • Supply chain visibility through attack surface management, including assets run by suppliers under your name.
  • Incident rehearsal against the 24-hour, 72-hour and one-month reporting deadlines.
  • Awareness you can measure through phishing simulation.

Questions we get asked

Does NIS2 apply to UK companies?

Not in the UK itself, where the NIS Regulations 2018 apply. UK companies that provide in-scope services in the EU must comply in the member states where they operate, and UK suppliers to in-scope EU organisations will usually see NIS2 requirements in their contracts.

Does NIS2 require penetration testing?

The directive does not name penetration testing, but Article 21 requires policies and procedures to assess whether your security measures are effective. Penetration testing is the most common way to provide that evidence, and some national laws and the implementing rules for digital infrastructure providers spell out security testing in more detail.

What is the difference between essential and important entities?

Mostly size and sector. Large organisations in the highly critical sectors are usually essential entities; most others in scope are important entities. The security measures are the same; the supervision regime and maximum fines differ.

How quickly must incidents be reported under NIS2?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.

Need evidence for NIS2, or for an EU customer?

Talk to us