Skip to main content
own2pwn

NIS2 Audit, technical side

Evidence that your NIS2 measures hold. Not another binder, a real test and the deliverables that go with it.

Article 21(2) of the NIS2 directive does not just ask you to deploy measures, it asks you to assess how effective they are. That is exactly what this engagement covers: an OSWE-certified pentester attacks your exposed systems, documents what gives way, and produces the technical evidence your audit file needs. You walk away with an actionable report, a matrix mapping every finding to the article 21(2) measures, a prioritized remediation plan, and a retest that confirms the fixes. This is the technical side of your compliance, not the governance side: we do not write your security policy or your business continuity plan, and we tell you so before we start.

Art. 21(2)
measures covered by technical evidence
OSWE
certified pentester
retest included
to validate your fixes

NIS2 audit pricing, technical side.

Recommandé
5-day engagement
2 250 €
  • 450 € net per day, VAT not applicable (art. 293 B CGI)
  • Focused scope: one exposed web application and its APIs
  • Coverage matrix for the article 21(2) measures
  • Executive and technical report (evidence, CVSS, prioritized remediation)
  • 1 retest included to validate the fixes
  • Live readout with your teams
Scope my NIS2 audit
10-day engagement
4 500 €
  • 450 € net per day, VAT not applicable (art. 293 B CGI)
  • Extended scope: several applications or environments
  • In-depth mapping of the external surface and assets
  • Coverage matrix and detailed remediation plan
  • 2 retests included to validate the fixes
  • Live readout, summary for the management body
Scope my NIS2 audit
Custom
On quote
  • 450 € net per day, VAT not applicable (art. 293 B CGI)
  • Several legal entities or a group-wide scope
  • Sector-specific constraints or bespoke environments
  • Recurring campaign to track progress over time
  • Number of retests defined in the quote
  • Scope defined before pricing
Get in touch

Fonctionnalités

What the technical side covers.

The effectiveness evidence article 21(2)(f) calls for

Measure (f) requires policies and procedures to assess the effectiveness of cybersecurity risk management measures. A penetration test is the most direct way to produce it: it does not state that a control exists, it shows whether it holds.

Coverage matrix, measure by measure

Every finding is mapped to measures (a) through (j) of article 21(2), with three honest states: proven by testing, partially covered, or out of reach for a technical control. Out of ten measures, a test establishes four outright and sheds light on four more.

A technical scope that is actually tested

Exposed web applications, REST, GraphQL and SOAP APIs, access controls between roles, TLS configuration and secrets handling. We test what an attacker can reach, not what a document describes.

Inventory of exposed assets

Mapping your external surface (forgotten subdomains, reachable admin services, expired certificates) feeds both the test and your asset inventory, which NIS2 expects and few organisations keep current.

Deliverables built to go into the file

Two-tier report (executive summary for the management body, technical detail with proof of exploitation and CVSS scores), coverage matrix, prioritized remediation plan with estimated effort. Timestamped, dated, usable by an auditor.

A traceable, standard methodology

OWASP Testing Guide, OSSTMM and PTES, a signed audit agreement, tracked phases. An auditor can follow what was tested, how, and on which scope. No opaque in-house recipe.

Comment ça marche

From scoping to the re-test.

  1. 01

    Scoping and qualification

    We first check that you are in scope (annexes I or II, size thresholds), then define what will be tested, on which environments and in which windows. Audit agreement and written authorization signed before any action.

  2. 02

    Mapping the exposed surface

    An inventory of what is genuinely reachable from the internet: subdomains, entry points, APIs, admin services, certificates. This mapping serves both the test and your asset inventory.

  3. 03

    Penetration testing and evidence collection

    Manual exploitation of vulnerabilities, capturing evidence as we go. Every finding is confirmed, CVSS-scored, and mapped to the article 21(2) measures it informs.

  4. 04

    Readout and retest

    Two-tier report, coverage matrix and prioritized remediation plan, presented in a working session. Once your fixes are deployed, the included retest verifies that they close the findings and updates the matrix.

Bénéfices

What evidence changes in your audit file.

01

You answer the one question that stalls an audit

"How do you know all of this works?" A binder of policies does not answer that. A test report showing what gave way, what held, and what you fixed afterwards does.

02

You know what the technical side does not cover

Governance, risk analysis, business continuity, crisis management: those measures belong to an organisational audit, not a test. The matrix we deliver says so explicitly, so you know what is left to handle and with whom.

03

The price is published before any sales call

450 € net per day, 2 250 € for a 5-day engagement, 4 500 € for 10 days, retest included. VAT not applicable, article 293 B of the French tax code. On a market where nobody publishes a figure, you can budget before talking to us.

FAQ

Your questions about the NIS2 audit.

Does this NIS2 audit cover my whole compliance?

No, and nobody should sell you that. This engagement covers the technical side: evidence that your security measures are effective, and an inventory of your exposed assets. The governance side (risk analysis, security policy, business continuity, crisis management, awareness) belongs to an organisational audit, which we do not perform. The matrix we deliver states explicitly which article 21(2) measures remain to be handled elsewhere, and that is precisely what makes it usable by your auditor.

How much does the technical side of a NIS2 audit cost?

Our day rate is 450 € net, VAT not applicable under article 293 B of the French tax code. A 5-day engagement comes to 2 250 €, a 10-day engagement to 4 500 €, retest included in both cases. Group or multi-entity scopes are quoted after scoping. We publish these figures because nobody on this market does, and because a flat price announced before the scope is defined is a number, not an engagement.

Is a penetration test mandatory for NIS2 compliance?

The directive does not name penetration testing as such. Measure (f) of article 21(2) requires policies and procedures to assess the effectiveness of risk management measures. Testing is the most direct and most documentable way to satisfy that requirement, but it is not the only possible route. That said, a purely declarative compliance posture leaves that measure without evidence.

Which article 21(2) measures can a test actually prove?

Four outright: security in development and vulnerability handling (e), effectiveness assessment (f), application-side access control (i), and multi-factor authentication and secure communications (j). Four partially: risk analysis (a), which it feeds with proven scenarios, supply chain (d) through the exposed surface, cyber hygiene (g) through forgotten accounts and services, and cryptography (h) through configurations. Two not at all: incident handling (b) and business continuity (c).

Am I in scope for NIS2?

Two conditions apply together: operating in a sector listed in annexes I or II of the directive, and meeting the size of a medium enterprise, meaning at least 50 employees or more than 10 million euros in turnover. The sector comes first, not the headcount. Some critical entities are in scope regardless of size. If you are unsure, tell us your sector and size during scoping and we will tell you before invoicing anything.

Can the deliverables be shown to an auditor or a regulator?

They are built for it: a timestamped two-tier report, proof of exploitation, CVSS scores, a matrix mapping findings to the article 21(2) measures, a prioritized remediation plan, and a retest report attesting to the fixes. We help you demonstrate the effectiveness of your measures. We do not issue a certification or a NIS2 compliance attestation, which does not exist and which nobody can issue.

Should we test in production or in staging?

Staging by default, provided it mirrors production. A staging environment that has drifted produces a report that does not describe your real exposure, so weak evidence. If only production is representative, we test there, with non-destructive tests, an agreed window and a stop procedure. This is settled during scoping.

A NIS2 audit to scope?

Tell us your sector, your size and your exposed scope: we come back within one business day with a scoping note and a quote.