Services
Understand veyrisk
PricingDemo consoleContact
EN
Sign inBuy now
■ ISO 27001 and NIS2

Checking for vulnerabilities is required.

Companies certified to ISO 27001 or covered by NIS2 must systematically find, assess and fix technical vulnerabilities and review the effectiveness of their measures. Regular vulnerability scans and penetration tests are the usual way to demonstrate this.

■ ISO/IEC 27001:2022

What ISO 27001 requires

The standard does not prescribe a specific tool. It does require technical vulnerabilities to be identified, assessed and addressed in a timely manner. That is why certification and surveillance audits regularly ask for vulnerability scans and penetration tests: they are the obvious evidence.

  • Annex A 8.8, management of technical vulnerabilities: obtain information about vulnerabilities, evaluate your exposure, take appropriate measures
  • Annex A 8.29, security testing in development and acceptance: test applications for security before they go live
  • Annex A 5.35, independent review of information security at planned intervals
  • Clause 9.1, monitoring, measurement, analysis and evaluation: demonstrate the effectiveness of the management system
■ NIS2

What NIS2 requires

The NIS2 Directive (EU) 2022/2555 has been transposed into national law across the EU, in Germany through the BSI Act. Entities in scope must implement risk management measures. Management must approve these measures, oversee their implementation and can be held liable for violations.

  • Art. 21(2)(e): security in the acquisition, development and maintenance of systems, including vulnerability handling
  • Art. 21(2)(f): policies and procedures to assess the effectiveness of the measures
  • For providers of digital infrastructure and IT services such as cloud, data centres and managed services, Implementing Regulation (EU) 2024/2690 makes this concrete: regular vulnerability scans (Annex 6.10) and security testing that explicitly includes penetration tests (Annex 6.7)
■ Scan and pentest

Vulnerability scan or penetration test?

Auditors and authorities usually expect both: continuous automated checks and a manual test at intervals. veyrisk covers the continuous checks. You can request a penetration test by the experts of neonotu GmbH directly from us.

01

Vulnerability scan

Automated, broad and regular. It finds known vulnerabilities and misconfigurations on all reachable systems and shows whether fixes work. This is the ongoing basis of vulnerability management.

02

Penetration test

Manual, targeted and at a point in time. Experts try to combine weaknesses and actually get in. Usual before new systems go live, after major changes and at fixed intervals, often yearly.

■ Evidence

What veyrisk provides for your evidence

RequirementStandardveyrisk contribution
Identify vulnerabilitiesISO A 8.8, NIS2 Art. 21(2)(e)Continuous scans of domains, servers, web apps, cloud and Microsoft 365
Assess riskISO A 8.8Priority per finding based on severity, exploitation and importance of the system
Document treatmentISO A 8.8, NIS2 Art. 21(2)(e)History per finding: new, fixed, reopened, accepted with justification
Assess effectivenessISO 9.1, NIS2 Art. 21(2)(f)Remediation times against targets, follow-up scans confirm the fix
Report to managementISO 9.3, NIS2 approval by managementManagement report and NIS2 evidence report as PDF
Access and accountsNIS2 Art. 21(2)(i), (j)Check of multi-factor sign-in and admin rights in Microsoft 365 and cloud
■ Limits

What veyrisk does not cover

ISO 27001 and NIS2 require much more than vulnerability management, such as policies, training, backups, contingency plans and incident reporting. veyrisk provides the technical part and the evidence for it.

This page is not legal advice. Whether NIS2 applies to your company can be clarified with the scope check of your national authority, in Germany the BSI, or with your legal advisor.

■ FAQ

Frequently asked questions

Does ISO 27001 require a penetration test?

Not literally. The standard requires technical vulnerabilities to be identified and addressed and security to be reviewed. In audits, however, regular vulnerability scans and penetration tests are considered the usual evidence.

How often do we need to scan?

Neither ISO 27001 nor NIS2 specifies a fixed frequency. What is required is a regular approach appropriate to the risk. Continuous automated scans and a manual test at intervals are common practice.

Does veyrisk help as a supplier to a customer covered by NIS2?

Yes. Many companies in scope ask their suppliers for evidence of security. The veyrisk NIS2 evidence report documents findings, remediation times and accepted risks.

■ Free first scan

What does your attack surface look like?

We scan your external attack surface for free and walk you through the results in 30 minutes.