NIS2
Article 21 requires risk controls to be tested for effectiveness, although it does not prescribe a pentest.





and moreEU rules for cyber risk, operational resilience, personal data, and digital products.
Article 21 requires risk controls to be tested for effectiveness, although it does not prescribe a pentest.
Articles 24–25 require a testing programme; the separate TLPT duty applies only to selected financial entities.
Article 32 requires regular evaluation of security measures, but it leaves the testing method risk-based.
Manufacturers must test products with digital elements and manage vulnerabilities throughout the support period.
Assurance, payment, healthcare, government, application, and cloud security standards.
The criteria do not name pentesting, but auditors and customers commonly expect current independent evidence.
Auditors use testing evidence to assess technical vulnerability management and security testing controls.
Requirement 11.4 explicitly requires internal and external penetration testing at least every 12 months.
The Security Rule requires risk analysis and periodic technical evaluation, not a named pentest.
CA-8 explicitly covers penetration testing when that control is selected for the system.
A verification standard whose higher assurance levels depend on hands-on security testing.
Cloud and PII guidance extends ISO 27001 controls; testing evidence follows the shared-responsibility boundary.
Run a security assessment of your system, or contact us if your compliance programme requires additional support.