NIS2 Audit, technical side
Evidence that your NIS2 measures hold. Not another binder, a real test and the deliverables that go with it.
Article 21(2) of the NIS2 directive does not just ask you to deploy measures, it asks you to assess how effective they are. That is exactly what this engagement covers: an OSWE-certified pentester attacks your exposed systems, documents what gives way, and produces the technical evidence your audit file needs. You walk away with an actionable report, a matrix mapping every finding to the article 21(2) measures, a prioritized remediation plan, and a retest that confirms the fixes. This is the technical side of your compliance, not the governance side: we do not write your security policy or your business continuity plan, and we tell you so before we start.
- Art. 21(2)
- measures covered by technical evidence
- OSWE
- certified pentester
- retest included
- to validate your fixes
NIS2 audit pricing, technical side.
- 450 € net per day, VAT not applicable (art. 293 B CGI)
- Focused scope: one exposed web application and its APIs
- Coverage matrix for the article 21(2) measures
- Executive and technical report (evidence, CVSS, prioritized remediation)
- 1 retest included to validate the fixes
- Live readout with your teams
- 450 € net per day, VAT not applicable (art. 293 B CGI)
- Extended scope: several applications or environments
- In-depth mapping of the external surface and assets
- Coverage matrix and detailed remediation plan
- 2 retests included to validate the fixes
- Live readout, summary for the management body
- 450 € net per day, VAT not applicable (art. 293 B CGI)
- Several legal entities or a group-wide scope
- Sector-specific constraints or bespoke environments
- Recurring campaign to track progress over time
- Number of retests defined in the quote
- Scope defined before pricing
Fonctionnalités
What the technical side covers.
The effectiveness evidence article 21(2)(f) calls for
Measure (f) requires policies and procedures to assess the effectiveness of cybersecurity risk management measures. A penetration test is the most direct way to produce it: it does not state that a control exists, it shows whether it holds.
Coverage matrix, measure by measure
Every finding is mapped to measures (a) through (j) of article 21(2), with three honest states: proven by testing, partially covered, or out of reach for a technical control. Out of ten measures, a test establishes four outright and sheds light on four more.
A technical scope that is actually tested
Exposed web applications, REST, GraphQL and SOAP APIs, access controls between roles, TLS configuration and secrets handling. We test what an attacker can reach, not what a document describes.
Inventory of exposed assets
Mapping your external surface (forgotten subdomains, reachable admin services, expired certificates) feeds both the test and your asset inventory, which NIS2 expects and few organisations keep current.
Deliverables built to go into the file
Two-tier report (executive summary for the management body, technical detail with proof of exploitation and CVSS scores), coverage matrix, prioritized remediation plan with estimated effort. Timestamped, dated, usable by an auditor.
A traceable, standard methodology
OWASP Testing Guide, OSSTMM and PTES, a signed audit agreement, tracked phases. An auditor can follow what was tested, how, and on which scope. No opaque in-house recipe.
Comment ça marche
From scoping to the re-test.
- 01
Scoping and qualification
We first check that you are in scope (annexes I or II, size thresholds), then define what will be tested, on which environments and in which windows. Audit agreement and written authorization signed before any action.
- 02
Mapping the exposed surface
An inventory of what is genuinely reachable from the internet: subdomains, entry points, APIs, admin services, certificates. This mapping serves both the test and your asset inventory.
- 03
Penetration testing and evidence collection
Manual exploitation of vulnerabilities, capturing evidence as we go. Every finding is confirmed, CVSS-scored, and mapped to the article 21(2) measures it informs.
- 04
Readout and retest
Two-tier report, coverage matrix and prioritized remediation plan, presented in a working session. Once your fixes are deployed, the included retest verifies that they close the findings and updates the matrix.
Bénéfices
What evidence changes in your audit file.
You answer the one question that stalls an audit
"How do you know all of this works?" A binder of policies does not answer that. A test report showing what gave way, what held, and what you fixed afterwards does.
You know what the technical side does not cover
Governance, risk analysis, business continuity, crisis management: those measures belong to an organisational audit, not a test. The matrix we deliver says so explicitly, so you know what is left to handle and with whom.
The price is published before any sales call
450 € net per day, 2 250 € for a 5-day engagement, 4 500 € for 10 days, retest included. VAT not applicable, article 293 B of the French tax code. On a market where nobody publishes a figure, you can budget before talking to us.
FAQ
Your questions about the NIS2 audit.
Does this NIS2 audit cover my whole compliance?
How much does the technical side of a NIS2 audit cost?
Is a penetration test mandatory for NIS2 compliance?
Which article 21(2) measures can a test actually prove?
Am I in scope for NIS2?
Can the deliverables be shown to an auditor or a regulator?
Should we test in production or in staging?
A NIS2 audit to scope?
Tell us your sector, your size and your exposed scope: we come back within one business day with a scoping note and a quote.