Compliance guide

NIS2 & GDPR: how you prove
compliance through penetration testing

A practical guide for companies working with the European market: who the requirements apply to, what evidence each framework expects, and exactly what a penetration test contributes to your compliance file.

Cybersecurity compliance pressure no longer comes only from inside the company. Organisations that work with European partners, process personal data or operate in regulated sectors increasingly face one question: "can you prove your systems have been tested?" This guide explains how NIS2 and GDPR frame that question — and how a penetration test produces exactly the evidence being asked for.

Does NIS2 apply to companies outside the EU?

NIS2 is a European Union directive, so it does not apply directly as law outside the EU. Its effect still reaches non-EU companies through three concrete routes:

  • Operations or subsidiaries in the EU — if you provide services on the European market, you may fall directly within the scope of "essential" or "important" entities.
  • The supply chain — if you supply a regulated EU entity, it will ask you for security evidence as part of its own NIS2 compliance. The requirement travels upstream, to you.
  • Legislative alignment — countries neighbouring the EU, Moldova included, are progressively aligning their cybersecurity frameworks with European standards. Companies that adopt the requirements early win a real advantage in tenders and partnerships.
In short: do not wait for NIS2 to become local law. If you sell into the EU, or supply someone who does, the requirement already reaches you — through contracts, not legislation.

What NIS2 requires when it comes to testing

Article 21 of NIS2 requires "appropriate and proportionate technical, operational and organisational measures" for managing cyber risk. Among them are policies for assessing the effectiveness of security measures — in other words, having defences is not enough; you have to prove they work.

A penetration test produces exactly that proof: a practical check of your defences against real attack scenarios, documented in a report that auditors and partners accept as evidence.

How GDPR connects to penetration testing

Article 32 of the GDPR requires appropriate technical measures to ensure the confidentiality, integrity and availability of personal data — plus "a process for regularly testing, assessing and evaluating" how effective those measures are.

A penetration test finds where personal data can be exposed — a vulnerable web application, an unauthenticated API, a misconfigured cloud bucket — and gives the Data Protection Officer direct audit evidence that the measures were tested, not merely declared.

What each framework asks for — and what the pentest delivers

FrameworkRelevant requirementWhat the penetration test delivers
NIS2 — Art. 21Assessing the effectiveness of risk-management measuresA practical check of the defences plus a findings report, as documented evidence
GDPR — Art. 32Confidentiality, integrity, availability plus regular testingIdentification of personal-data exposure paths plus audit evidence for the DPO
OWASP Top 10Reference methodology for web applicationsStructured testing across the most common vulnerability classes
Sector requirements (finance and payments)Testing aligned to the regulator (e.g. the National Bank of Moldova)Reporting validated requirement by requirement, audit-ready

Deliverables that go straight into the compliance file

  • A technical report with the vulnerabilities found, the risk rating and the remediation steps.
  • An executive summary for management and the board.
  • A mapping of the findings onto NIS2 and GDPR requirements, on request.
  • A retest after remediation, as proof the issues were actually closed.
These same deliverables have already supported financial institutions and payment processors through audits and registration with the National Bank of Moldova. See the case studies.

Frequently asked questions

Does NIS2 apply to companies outside the EU?

NIS2 is an EU directive, so it does not apply directly as law outside the Union. It still affects non-EU companies that have operations in the EU, that supply a regulated EU entity (which will ask them for security evidence), or whose national legislation is progressively aligning with European standards. Many companies adopt the requirements early, as a competitive advantage.

What does NIS2 require in terms of security testing?

Article 21 mandates risk-management measures, including assessing how effective those measures are and testing security. Penetration tests produce the documented proof that defences were checked in practice against real attack scenarios — the evidence auditors and authorities ask for.

How does a penetration test relate to the GDPR?

Article 32 requires technical measures for the confidentiality, integrity and availability of personal data, plus regular testing of those measures. A pentest identifies where personal data can be exposed and gives the DPO direct audit evidence.

How often should a penetration test be run?

At least once a year, and after any significant change to the systems — a major release, new infrastructure, a migration. Regulated environments often test more frequently, or move to continuous testing.

What deliverables do I get for the compliance file?

A technical report with vulnerabilities, risks and remediation, an executive summary, a mapping onto NIS2/GDPR requirements where needed, and a retest after remediation. Together they form audit evidence that is ready to present.

This material is informational and does not constitute legal advice. Whether NIS2 and GDPR apply depends on each organisation’s specific situation; consult a specialist for legal interpretation.

Ready for NIS2 and GDPR?

Book a free consultation and get a testing plan matched to your perimeter and your compliance requirements.