NIS2 Audit, technical side
Evidence that your NIS2 measures hold. Not another binder, a real test and the deliverables that go with it.
Article 21(2) of the NIS2 directive does not just ask you to deploy measures, it asks you to assess how effective they are. That is exactly what this engagement covers: an OSWE-certified pentester attacks your exposed systems, documents what gives way, and produces the technical evidence your audit file needs. You walk away with an actionable report, a matrix mapping every finding to the article 21(2) measures, a prioritized remediation plan, and a retest that confirms the fixes. This is the technical side of your compliance, not the governance side: we do not write your security policy or your business continuity plan, and we tell you so before we start.
- measures covered by technical evidence
- Art. 21(2)
- certified pentester
- OSWE
- to validate your fixes
- retest included
The deliverable
What the evidence file looks like.
A summary, every gap with its hand-replayed proof, and the matrix that maps findings back to the article 21.2 measures. What your auditor will ask you to produce.
NIS2 audit, technical side
ANONYMISED COMPANY
No critical flaw, but a chain rated high leads from a free trial account to administrator control of the instance. Fix expected before the next release.
Privilege escalation through mass assignment on the profile API
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PATCH /api/v1/users/me HTTP/1.1
Host: api.client-anonymise.example
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.[...]
Content-Type: application/json
Content-Length: 37
{"displayName":"test","role":"admin"}HTTP/1.1 200 OK
Content-Type: application/json
Content-Length: 51
{"id":"u_2841","displayName":"test","role":"admin"}Request replayed by hand, token truncated, identifiers replaced.
Coverage matrix, excerpt
Directive (EU) 2022/2555, article 21.2
| Measure | What the audit provides | Status |
|---|---|---|
| (a)Risk analysis and information system security policies | Governance side. Not covered by this audit, which produces technical evidence. | Out of scope |
| (d)Supply chain security | Inventory of third-party components exposed on the tested scope: 3 past end of support. | Partial evidence |
| (e)Development, maintenance and vulnerability handling | 13 vulnerabilities identified, scored with CVSS v3.1 and tied to a named fix. | Evidence produced |
| (f)Assessing the effectiveness of the measures | Penetration test then retest: 12 of 13 fixes replayed and verified, 1 risk accepted in writing. | Evidence produced |
| (i)Access control policies and asset management | Privilege escalation reproduced from a standard account (F-01). 42 exposed hosts found, 6 missing from the declared inventory. | Partial evidence |
| (j)Multi-factor authentication | MFA missing on the administration console reachable from the internet. | Partial evidence |
This excerpt documents the technical evidence expected by article 21.2 (f). It is neither a NIS2 attestation nor a certification: neither exists. The governance side (risk analysis, security policy, continuity, awareness training) stays out of scope.
Anonymised mock-up: an example of the deliverable format, with fictional data. No engagement report is ever published, and the name of a client is never disclosed.
NIS2 audit pricing, technical side.
5-day engagement
€2,250
- Day rate €450 net, VAT not applicable (art. 293 B CGI)
- Focused scope: one exposed web application and its APIs
- Coverage matrix for the article 21(2) measures
- Executive and technical report (evidence, CVSS, prioritized remediation)
- 1 retest included to validate the fixes
- Live readout with your teams
10-day engagement
€4,500
- Day rate €450 net, VAT not applicable (art. 293 B CGI)
- Extended scope: several applications or environments
- In-depth mapping of the external surface and assets
- Coverage matrix and detailed remediation plan
- 2 retests included to validate the fixes
- Live readout, summary for the management body
Custom
On request
- Day rate €450 net, VAT not applicable (art. 293 B CGI)
- Several legal entities or a group-wide scope
- Sector-specific constraints or bespoke environments
- Recurring campaign to track progress over time
- Number of retests defined in the quote
- Scope defined before pricing
Features
What the technical side covers.
The effectiveness evidence article 21(2)(f) calls for
Measure (f) requires policies and procedures to assess the effectiveness of cybersecurity risk management measures. A penetration test is the most direct way to produce it: it does not state that a control exists, it shows whether it holds.
Coverage matrix, measure by measure
Every finding is mapped to measures (a) through (j) of article 21(2), with three honest states: proven by testing, partially covered, or out of reach for a technical control. Out of ten measures, a test establishes four outright and sheds light on four more.
A technical scope that is actually tested
Exposed web applications, REST, GraphQL and SOAP APIs, access controls between roles, TLS configuration and secrets handling. We test what an attacker can reach, not what a document describes.
Inventory of exposed assets
Mapping your external surface (forgotten subdomains, reachable admin services, expired certificates) feeds both the test and your asset inventory, which NIS2 expects and few organisations keep current.
Deliverables built to go into the file
Two-tier report (executive summary for the management body, technical detail with proof of exploitation and CVSS scores), coverage matrix, prioritized remediation plan with estimated effort. Timestamped, dated, usable by an auditor.
A traceable, standard methodology
OWASP Testing Guide, OSSTMM and PTES, a signed audit agreement, tracked phases. An auditor can follow what was tested, how, and on which scope. No opaque in-house recipe.
How it works
From scoping to the re-test.
- 01
Scoping and qualification
We first check that you are in scope (annexes I or II, size thresholds), then define what will be tested, on which environments and in which windows. Audit agreement and written authorization signed before any action.
- 02
Mapping the exposed surface
An inventory of what is genuinely reachable from the internet: subdomains, entry points, APIs, admin services, certificates. This mapping serves both the test and your asset inventory.
- 03
Penetration testing and evidence collection
Manual exploitation of vulnerabilities, capturing evidence as we go. Every finding is confirmed, CVSS-scored, and mapped to the article 21(2) measures it informs.
- 04
Readout and retest
Two-tier report, coverage matrix and prioritized remediation plan, presented in a working session. Once your fixes are deployed, the included retest verifies that they close the findings and updates the matrix.
Benefits
What evidence changes in your audit file.
You answer the one question that stalls an audit
"How do you know all of this works?" A binder of policies does not answer that. A test report showing what gave way, what held, and what you fixed afterwards does.
You know what the technical side does not cover
Governance, risk analysis, business continuity, crisis management: those measures belong to an organisational audit, not a test. The matrix we deliver says so explicitly, so you know what is left to handle and with whom.
The price is published before any sales call
€450 net per day, €2,250 for a 5-day engagement, €4,500 for 10 days, retest included. VAT not applicable, article 293 B of the French tax code. On a market where nobody publishes a figure, you can budget before talking to us.
FAQ
Your questions about the NIS2 audit.
Does this NIS2 audit cover my whole compliance?
How much does the technical side of a NIS2 audit cost?
Is a penetration test mandatory for NIS2 compliance?
Which article 21(2) measures can a test actually prove?
Am I in scope for NIS2?
Can the deliverables be shown to an auditor or a regulator?
Should we test in production or in staging?
A NIS2 audit to scope?
Tell us your sector, your size and your exposed scope: we come back within one business day with a scoping note and a quote.