Penetration Testing Under NIS2 and DORA: What to Test, How Often, and What Evidence to Keep
Key takeaways NIS2 never uses the phrase “penetration test.” Yet supervisory authorities across the EU already treat penetration testing as the default way to prove compliance with Article 21(2)(f), and inspectors expect test evidence on request even when no law sets a fixed testing calendar. For CTOs, Heads of Compliance, and CISOs at essential and […]