Penetration testing for NIS 2 & DORA
NIS 2 Article 21(2) requires you to handle vulnerabilities and to assess the effectiveness of your cybersecurity measures — penetration testing is the standard, defensible way to evidence both. We map findings to the relevant NIS 2 measures and, for financial entities under DORA, align with Threat-Led Penetration Testing (TLPT), giving you audit-ready proof for boards and competent authorities.
Penetration testing in Romania
Based in Bucharest, we deliver penetration testing across Romania — on-site or remote — for banks, fintechs, energy, healthcare, public sector and technology companies. We report in English and Romanian and have worked with a large share of the Romanian banking sector, so we understand local regulatory expectations (BNR, DNSC / NIS 2) alongside EU frameworks like DORA.
Our methodology
A structured, repeatable process based on PTES, OSSTMM and NIST SP 800-115: scoping, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation and reporting.
What we test
Web and API applications, mobile apps, internal and external infrastructure, cloud and crypto systems, wireless networks, and AI/LLM systems — individually or as a combined engagement.
Scoping & rules of engagement
We agree a precise scope, safe testing windows and clear rules of engagement up front, avoid destructive tests and coordinate any sensitive actions with your team.
Reporting & retest
You receive a prioritized technical report and an executive summary, plus a free remediation retest once findings are fixed.
Frameworks & standards
What you get
- Technical report with reproducible, CVSS-rated findings
- Executive summary for management and auditors
- Prioritized remediation roadmap
- Free remediation retest
FAQ
Does NIS 2 require penetration testing?
Not by name, but Article 21(2) requires vulnerability handling and assessing the effectiveness of your security measures — penetration testing is the accepted way to evidence this for essential and important entities, and to prepare for Article 23 incident reporting.
How long does a pentest take?
Typically 1–3 weeks depending on scope and complexity; we confirm a timeline after scoping.
How often should we test?
At least annually, and after any major change — DORA and NIS 2 expect regular testing of critical systems.
Which standard do you follow?
We blend PTES, OSSTMM and NIST SP 800-115, and map findings to MITRE ATT&CK and OWASP where relevant.
