Security Testing Requirements of NIS2 Implementing Regulation

CIR Requirements and ENISA guidance on security testing

SHARE

Loading the Elevenlabs Text to Speech AudioNative Player...

Requirements in CIR 2024/2690 and ENISA Guidance Explained

The Network and Information Systems Directive (NIS2), in force since January 2023, aims to improve cybersecurity across the EU’s 18 critical sectors. It establishes the obligation for essential and important entities to implement cybersecurity risk management measures, but leaves the detailed rules to EU Member States and national laws. However, in the case of organizations providing cross-border services critical for the EU’s digital infrastructure, the European Commission regulates them directly at the Union level.

With these entities in mind, the Commission Implementing Regulation (EU) 2024/2690 (CIR) was adopted in October 2024. The NIS2 Implementing Regulation translates the broad obligations of NIS2 Article 21, on general cybersecurity risk-management measures that essential and important entities must adopt, into concrete, binding requirements.

Alongside the CIR, the European Union Agency for Cybersecurity (ENISA) published its Technical Implementation Guidance in June 2025. This non-binding document mirrors the structure of the CIR Annex and provides practical guidance on how requirements can be implemented, examples of evidence that can be shown to auditors, and mappings to good practices, European and international standards and national frameworks.

In this article, we give an overview of CIR and ENISA’s guidance and explain exactly where cybersecurity assessments fit into CIR requirements and ENISA recommendations — and how to turn each into traceable compliance evidence.

Understanding the CIR and Annex I

The Commission Implementing Regulation (CIR) applies to specific subgroup of entities in the scope of NIS2, which are: domain name system (DNS) service providers, top-level domain name registries, cloud computing service providers, data centre service providers, content delivery network (CDN) providers, managed service providers and managed security service providers, providers of online marketplaces, online search engines, and social networking platforms, trust service providers.

These organizations must comply with CIR’s Annex I, which sets out binding technical and methodological requirements regarding cybersecurity risk management. These requirements are grouped into thirteen thematic areas, together covering the governance, operational, and technical aspects of cybersecurity risk management:

  1. Policy on the security of network and information systems
  2. Risk management policy
  3. Incident handling
  4. Business continuity and crisis management
  5. Supply chain security
  6. Security in acquisition, development and maintenance of network and information systems
  7. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
  8. Basic cyber hygiene practices and security training
  9. Cryptography
  10. Human resources security
  11. Access control
  12. Asset management
  13. Environmental and physical security

Each area includes specific, verifiable requirements, some of which are policy-driven (such as incident management or supply chain security), while others are technical (such as vulnerability management, secure development, or logging and monitoring).

A recurring feature across all areas is the obligation to document, test, and review measures periodically. Annex I prescribes what entities must do and requires them to demonstrate that their controls are effective in practice. For example, organizations must establish a security testing policy (Annex, point 6.5.1), conduct regular vulnerability scans (Annex, point 6.10), and put in place procedures to assess the effectiveness of all measures (Annex, point 7.1).

In this way, the CIR turns NIS2 from a principle-based directive into a structured and enforceable compliance framework.

Understanding ENISA’s Technical Implementation Guidance

To complement the binding requirements of the Commission Implementing Regulation, ENISA published its Technical Implementation Guidance, developed in cooperation with the European Commission and the NIS Cooperation Group.

The non-binding guidance is intended primarily for the relevant entities covered by the CIR, but ENISA notes that it can also support national authorities in designing supervisory approaches, and it may serve as a reference for other organisations seeking to strengthen their cybersecurity practices.

For each of the thirteen thematic areas of the CIR Annex, ENISA provides three layers of support:

  1. Guidance – indicative and actionable advice on how a requirement may be implemented in practice.
  2. Examples of evidence – suggestions for the kind of records or artefacts that can demonstrate a measure is in place (e.g., test reports, audit logs).
  3. Mappings – cross-references to industry standards and good practices such as ISO/IEC 27001 and 27002, NIST Cybersecurity Framework 2.0, ETSI EN standards, and national frameworks.

For every obligation in the CIR Annex — whether establishing cybersecurity policies, securing development processes, conducting vulnerability management, or testing business continuity — ENISA provides both implementation ideas and examples of compliance evidence.

The guidance also stresses flexibility and proportionality: organisations are expected to meet the intent of the requirement, but the specific methods can vary depending on size, risk exposure, and operational complexity. For instance, vulnerability management (Annex, point 6.10) might be satisfied through automated scanning in a lower-risk environment, or through penetration testing and third-party reviews in a higher-risk one.

In short, while the CIR sets the minimum binding standard, ENISA’s guidance offers the practical blueprint for achieving it — and for documenting the process in a way that will withstand regulatory scrutiny.

Do you have questions?
Let's talk.

Get in touch with our cybersecurity experts

Security Testing Requirements in CIR and ENISA Guidance

The Commission Implementing Regulation (EU) 2024/2690 and the ENISA Technical Implementation Guidance set out a comprehensive framework for cybersecurity risk management practices across thirteen thematic areas, ranging from governance and policies to supply chain security, incident handling, and physical protection of systems. Among these, security testing is a recurring theme, appearing in multiple Annex points as both a requirement and a means of verifying that measures are effective.

Below is a closer look at the cybersecurity testing requirements of CIR.

Security testing in SDLC

The CIR requires that security testing be integrated into the secure development life cycle (Annex, point 6.2), including the safe handling of test data. ENISA advises taking this further by using a mix of techniques — penetration testing, static and dynamic application security testing, and manual code reviews — applied at different stages of development. This ensures that vulnerabilities are identified before systems move into production, and that test results and data handling are properly documented.

Change management

In change management (Annex, point 6.4), the CIR obliges entities to test and assess significant changes before deployment. ENISA’s guidance highlights practical ways of achieving this, such as embedding vulnerability scanning or targeted penetration tests into pre-release processes, with approval records and remediation evidence maintained as proof of compliance.

Security testing policy

A central obligation is the security testing policy (Annex, point 6.5.1). The CIR makes this a mandatory, documented policy defining scope, frequency, methodologies, and the recording of results. ENISA expands this into a full testing programme, recommending the inclusion of vulnerability assessments, penetration tests, red or purple team exercises, code reviews, and attack simulations. A structured approach, with test reports and remediation records retained, turns testing from an ad hoc task into a repeatable compliance process.

Network segmentation

Testing is also integral to network segmentation (Annex, point 6.8), where entities must periodically review effectiveness. ENISA advises validating segmentation through penetration tests and vulnerability scans, demonstrating that lateral movement is not possible in practice.

Vulnerability handling and disclosure

Similarly, vulnerability handling and disclosure (Annex, point 6.10) requires regular vulnerability scanning and remediation of critical issues. ENISA recommends broadening this to penetration testing and third-party assessments, with retesting to confirm that fixes have been applied.

Policies and procedures

Beyond individual measures, Annex I also requires entities to establish policies and procedures for assessing the effectiveness of their security measures (Annex, point 7.1). Here, ENISA suggests that vulnerability assessments, penetration testing, and team-based exercises such as red, blue, or purple teaming should form part of effectiveness evaluations. Linking reports and remediation timelines to key performance indicators provides auditable proof that measures are not only in place but performing as intended.

The table below clarifies the cybersecurity testing requirements of CIR and the non-binding recommendations of ENISA regarding the CIR requirements.

NIS2 implementing regulation infographic | CIR requirements and Enisa guidance
NIS2 Security Testing – CIR Requirements and ENISA’s Recommendations

Beyond CIR: ENISA’s Good Practice Recommendations

While the CIR defines the binding baseline, ENISA goes further by identifying other areas where additional security testing can significantly enhance cyber resilience. These recommendations are not mandatory, but they represent recognised good practice and may well inform future supervisory expectations. They also address aspects of cybersecurity that, if left untested, can become single points of failure in an organisation’s defences.

Business continuity and disaster recovery

One area ENISA highlights is business continuity and disaster recovery (BC/DR). The CIR already requires entities to have BC/DR plans in place and to test them periodically (Annex, point 4.1.4).

ENISA advises taking this further by subjecting those plans to cyber-attack simulations or red team exercises. These exercises put theoretical recovery strategies under realistic attack conditions, validating whether critical services can be restored within acceptable timeframes. The resulting reports, lessons learned, and updates to continuity documentation create not just compliance evidence but a tangible improvement cycle for resilience.

Supply chain security

Supply chain security is another domain where ENISA recommends deeper testing. While the CIR obliges relevant entities to establish supply chain security policies (Annex, point 5.1), ENISA notes that these policies should be backed by practical verification. This can include penetration testing or targeted security assessments of critical suppliers. Such measures reduce the risk of systemic disruption introduced through third-party services, and supplier assessment reports or remediation actions serve as concrete proof that risks are being managed proactively.

Network and infrastructure hardening

When it comes to network and infrastructure hardening, ENISA recommends moving beyond periodic configuration checks to active vulnerability scanning and penetration testing of both perimeter and internal systems. This approach ensures that misconfigurations, legacy exposures, or overlooked services are discovered before attackers can exploit them. Scan logs, remediation tickets, and pentest reports form the evidentiary trail that demonstrates this ongoing diligence.

Human resources security

ENISA also turns attention to the human factor, particularly in the area of human resources security. While the CIR requires measures such as background checks and disciplinary processes (Annex, point 10), ENISA suggests complementing these with insider threat simulations as part of red team campaigns. These exercises test an organisation’s resilience to social engineering and insider risks — scenarios that cannot be fully mitigated by policy alone. Documented results of such simulations and adjustments to awareness programmes provide evidence that insider threats are taken seriously and countered with practical measures.

Logging and monitoring

The CIR requires comprehensive logging and incident handling (Annex, points 3.2–3.5), but ENISA advises validating these capabilities through red or purple team exercises. By simulating realistic attack behaviour, organisations can measure whether their security operations centre (SOC) detects, triages, and responds to cyber threats within acceptable timelines. Detection metrics, SOC reports, and exercise logs then form the evidence base for both compliance and operational assurance.

Taken together, these recommendations illustrate ENISA’s broader philosophy: testing should extend beyond the strict legal minimum to cover the systems, processes, and people that underpin an organisation’s resilience. By adopting these practices, entities not only strengthen their posture against attackers but also demonstrate maturity that will resonate with regulators, customers, and partners alike.

The Importance of NIS2 Directive Security Testing

The NIS2 implementing regulation and ENISA guidance provide a clear regulatory framework, but the importance of cybersecurity measures goes beyond compliance. Europe’s critical infrastructure is increasingly at the frontline of nation-state activity: cyber operations, hybrid threats, and information warfare often target civilian networks, not just military ones. The boundaries between civil and military domains are blurring, and private organisations now share responsibility for defending the resilience of Europe’s digital society.

For relevant public and private entities within the scope of cybersecurity regulations like CIR and NIS2, security testing helps to ensure that the essential services people depend on — communications, data, commerce — cannot be easily disrupted by adversaries who operate with persistence and intent.

Each penetration test, vulnerability scan, and attack simulation minimizes cyber risk and contributes to the collective defence of Europe’s digital infrastructure.

Private organisations cannot control the geopolitical environment, but they can control their cybersecurity posture. By embracing security testing and other appropriate security measures, they strengthen their resilience and play a vital role in ensuring that the bad actors — whether criminals or state-sponsored — do not succeed in undermining the systems we all rely on.

About the author

Picture of Ewelina Baran

Ewelina Baran

Ewelina is a SEO copywriter specialized in technology, more specifically in cybersecurity. She holds a masters degree in English Philology from Jagiellonian University, Krakow.

RELATED POSTS

Ready to take your security
to the next level?

We are! Let’s discuss how we can work together to create strong defenses against real-life cyber threats.

Stay informed, stay secure

Subscribe to our monthly newsletter

Get notified about new articles, industry insights and cybersecurity news