Pentesting for NIS2
NIS2 is the EU directive on cybersecurity risk management. It applies to essential and important entities across critical and digital sectors, from energy and health to cloud and managed services. It requires technical and organizational measures plus evidence that risk controls work. National authorities can fine up to 2% of worldwide annual turnover or €10 million.
The controls we cover
Requirement summaryEntities must ensure security across the lifecycle of their network and information systems, from acquisition through development to maintenance, including how vulnerabilities are handled and disclosed.
AISafe tests web, API, and source-code surfaces, then records validated findings, remediation, and retests to document that acquisition, development, and maintenance controls work in practice.
Requirement summaryEntities must put in place policies and procedures for evaluating how effective their cybersecurity risk-management measures actually are.
AISafe produces repeatable test cycles and retest records that give the assessment process technical evidence on whether risk-management controls are working.
Quick facts
| Applicability | Essential and important entities in critical and digital sectors: energy, transport, health, digital infrastructure, cloud, and managed services. |
| Requirement | Yes for in-scope entities, with national transposition setting the exact duties. |
| Cost | Proportional to the entity’s size, exposure, and sector; smaller entities carry lighter duties, and automated AISafe testing keeps the evidence affordable. |
| Cadence | Risk-based; NIS2 sets no fixed frequency. Testing yearly and after significant changes is common practice. |
AISafe Labs delivers on-demand, audit-ready evidence for Article 21: scoped reports, reproducible findings, and remediation validation , in hours, where other vendors take weeks. AISafe Labs complements, never replaces, a statutory audit, and does not determine your NIS2 classification.
