Checking for vulnerabilities is required.
Companies certified to ISO 27001 or covered by NIS2 must systematically find, assess and fix technical vulnerabilities and review the effectiveness of their measures. Regular vulnerability scans and penetration tests are the usual way to demonstrate this.
What ISO 27001 requires
The standard does not prescribe a specific tool. It does require technical vulnerabilities to be identified, assessed and addressed in a timely manner. That is why certification and surveillance audits regularly ask for vulnerability scans and penetration tests: they are the obvious evidence.
- Annex A 8.8, management of technical vulnerabilities: obtain information about vulnerabilities, evaluate your exposure, take appropriate measures
- Annex A 8.29, security testing in development and acceptance: test applications for security before they go live
- Annex A 5.35, independent review of information security at planned intervals
- Clause 9.1, monitoring, measurement, analysis and evaluation: demonstrate the effectiveness of the management system
What NIS2 requires
The NIS2 Directive (EU) 2022/2555 has been transposed into national law across the EU, in Germany through the BSI Act. Entities in scope must implement risk management measures. Management must approve these measures, oversee their implementation and can be held liable for violations.
- Art. 21(2)(e): security in the acquisition, development and maintenance of systems, including vulnerability handling
- Art. 21(2)(f): policies and procedures to assess the effectiveness of the measures
- For providers of digital infrastructure and IT services such as cloud, data centres and managed services, Implementing Regulation (EU) 2024/2690 makes this concrete: regular vulnerability scans (Annex 6.10) and security testing that explicitly includes penetration tests (Annex 6.7)
Vulnerability scan or penetration test?
Auditors and authorities usually expect both: continuous automated checks and a manual test at intervals. veyrisk covers the continuous checks. You can request a penetration test by the experts of neonotu GmbH directly from us.
Vulnerability scan
Automated, broad and regular. It finds known vulnerabilities and misconfigurations on all reachable systems and shows whether fixes work. This is the ongoing basis of vulnerability management.
Penetration test
Manual, targeted and at a point in time. Experts try to combine weaknesses and actually get in. Usual before new systems go live, after major changes and at fixed intervals, often yearly.
What veyrisk provides for your evidence
| Requirement | Standard | veyrisk contribution |
|---|---|---|
| Identify vulnerabilities | ISO A 8.8, NIS2 Art. 21(2)(e) | Continuous scans of domains, servers, web apps, cloud and Microsoft 365 |
| Assess risk | ISO A 8.8 | Priority per finding based on severity, exploitation and importance of the system |
| Document treatment | ISO A 8.8, NIS2 Art. 21(2)(e) | History per finding: new, fixed, reopened, accepted with justification |
| Assess effectiveness | ISO 9.1, NIS2 Art. 21(2)(f) | Remediation times against targets, follow-up scans confirm the fix |
| Report to management | ISO 9.3, NIS2 approval by management | Management report and NIS2 evidence report as PDF |
| Access and accounts | NIS2 Art. 21(2)(i), (j) | Check of multi-factor sign-in and admin rights in Microsoft 365 and cloud |
What veyrisk does not cover
ISO 27001 and NIS2 require much more than vulnerability management, such as policies, training, backups, contingency plans and incident reporting. veyrisk provides the technical part and the evidence for it.
This page is not legal advice. Whether NIS2 applies to your company can be clarified with the scope check of your national authority, in Germany the BSI, or with your legal advisor.
Frequently asked questions
Does ISO 27001 require a penetration test?
Not literally. The standard requires technical vulnerabilities to be identified and addressed and security to be reviewed. In audits, however, regular vulnerability scans and penetration tests are considered the usual evidence.
How often do we need to scan?
Neither ISO 27001 nor NIS2 specifies a fixed frequency. What is required is a regular approach appropriate to the risk. Continuous automated scans and a manual test at intervals are common practice.
Does veyrisk help as a supplier to a customer covered by NIS2?
Yes. Many companies in scope ask their suppliers for evidence of security. The veyrisk NIS2 evidence report documents findings, remediation times and accepted risks.
What does your attack surface look like?
We scan your external attack surface for free and walk you through the results in 30 minutes.