NIS2 demands evidence, not a plan.

    Your auditor will not accept a policy document as proof of penetration testing. Sectricity delivers the pentest evidence your regulator expects for NIS2 Article 21, with full remediation tracking and a retest before your audit date. A pentest is the technical evidence within your NIS2 file, not a legal compliance certificate and not a full NIS2 programme. It works the same whether you fall under the Belgian NIS2 law or the Dutch Cybersecurity Act.

    Key NIS2 facts

    June 2026
    NIS2 self-assessment deadline for entities in the Netherlands
    18 sectors
    Sectors covered by NIS2 in Belgium and the Netherlands
    72 hours
    Maximum time to report a significant security incident under NIS2

    Not every pentest report convinces your auditor

    The difference between what gets rejected and what actually works

    What your auditor won't accept

    An automated vulnerability scan with no human validation of findings

    What actually works for NIS2

    External pentest by certified ethical hackers using OWASP/PTES methodology

    What your auditor won't accept

    A policy document or compliance checklist presented as evidence of security testing

    What actually works for NIS2

    Internal test of network, Active Directory, cloud environments, and applications

    What your auditor won't accept

    A report with no remediation trail or tracked follow-up

    What actually works for NIS2

    Remediation tracking via the RedSOC dashboard, demonstrable evidence for your auditor

    What your auditor won't accept

    No proof that vulnerabilities were fixed before your audit date

    What actually works for NIS2

    Retest per vulnerability after remediation, included as standard, no separate invoice

    What your auditor won't accept

    An outdated report or one scoped for the wrong systems

    What actually works for NIS2

    A current, correctly scoped report in the format Belgian and Dutch regulators expect

    Built for your NIS2 audit

    Every deliverable is built to stand up as evidence in front of your regulator, not just your IT team.

    NIS2 Article 21 mapped

    Every finding is explicitly linked to the NIS2 Article 21 measure it evidences. Your auditor gets usable evidence, not a generic report.

    Human-validated results

    Every finding is manually confirmed by a certified ethical hacker before it enters your report. No scanner noise that wastes your time.

    Remediation tracker included

    We deliver a structured remediation tracker alongside the report. Show progress to your auditor at any stage of the process.

    Two to four week turnaround

    Most scopes are completed and reported within two to four weeks. We understand audit deadlines and structure our work around yours.

    Retest at no extra cost

    Once you have remediated findings, we retest to confirm fixes before your audit. Included as standard, not as a separate invoice.

    Broad technical scope

    Web applications, networks, APIs, cloud environments and social engineering vectors. All in one coordinated scope, one report.

    Who benefits most from this?

    Compliance officers

    You need documented penetration testing evidence for your NIS2 file. We deliver exactly that, in the format regulators expect, and leave the policy work to you.

    IT managers

    You know you need a pentest but are unsure what to include in scope. We define it with you and deliver clear, actionable technical findings.

    CISOs

    You need a credible, human-led test your board and auditor will accept. Not a scanner report repackaged as a penetration test.

    CEOs and board members

    NIS2 makes management personally liable for non-compliance. A documented pentest protects both your organisation and you personally.

    Frequently asked questions

    NIS2 Article 21 requires organisations to implement risk management measures and assess the effectiveness of their cybersecurity controls. National regulators in Belgium and the Netherlands increasingly expect documented, human-led security testing as evidence of Article 21 compliance. A penetration test with tracked remediation is the most widely accepted form of that evidence.

    Most engagements are completed and reported within two to four weeks of scoping confirmation, depending on the agreed scope. We provide a fixed delivery date before work begins so you can plan your audit schedule around it, and we can accelerate when your audit deadline requires it.

    Yes. Both essential and important entities are required to implement Article 21 security measures, including evidence of security testing. The depth and frequency of testing may vary based on your entity classification, but the requirement to document your security posture applies to both categories.

    A vulnerability scan identifies known weaknesses using automated tools. A penetration test actively attempts to exploit those weaknesses using human intelligence and real attack techniques. NIS2 auditors expect evidence of active testing, not just a list of CVEs. A scan alone will not satisfy an Article 21 compliance requirement in most cases.

    Each finding in our report is tagged to the specific NIS2 Article 21 security measure it relates to, such as access control, incident handling or cryptography. This lets your auditor see which measures are technically evidenced and which still need remediation. The compliance judgement itself stays with your auditor.

    No. We are not a compliance consultancy and we do not run full NIS2 programmes. We deliver the technical half: penetration testing, red teaming, social engineering and security awareness, plus the reporting you use as evidence. The policy and governance track stays with your own compliance lead or advisory partner. That keeps our scope sharp and our evidence usable.

    Book your NIS2 pentest with audit-ready report and free retest

    External pentest, internal network test, remediation tracking and retest. Your pentest evidence for the NIS2 file, ready in 2 to 4 weeks.