NODUM

Pentesting and ISO 27001, ENS and NIS2: what they ask for and what they do not

None of these three is met with a pentest, and not all of them ask for one by that name. But all three ask for things a pentest helps to demonstrate. This is what each one says.

ISO/IEC 27001

The 2022 version includes in its Annex A the management of technical vulnerabilities (control 8.8) and security testing in development and acceptance (control 8.29). It does not mention pentesting by name: it asks you to know your vulnerabilities and deal with them.

A pentest report is one of the pieces of evidence that can be provided for those controls. Whether it is enough is decided by whoever audits your management system.

Spanish National Security Framework (ENS)

The ENS (Royal Decree 311/2022) applies to the Spanish public sector and to the companies that provide it with services or solutions. It names penetration testing explicitly in the monitoring measure (op.mon.3): it is one of the periodic inspections required of HIGH category systems.

In every category it requires checking the security of an application before it goes into production (mp.sw.2), and in the MEDIUM and HIGH categories, doing those tests in an isolated environment.

MEDIUM and HIGH category systems also need an audit to certify their conformity with the ENS, and that certification is issued by a certification body.

NIS2

Directive (EU) 2022/2555 asks the companies it covers, among other measures, for security in the development and maintenance of their systems, "including vulnerability handling and disclosure", and for procedures to assess whether their security measures work (Article 21). It applies through each country's national law.

It also asks them to look after the security of their supply chain. So even if your company is not covered by NIS2, it may reach you through a customer that is, as a questionnaire or a request for evidence.

What a pentest provides and what it does not

It provides dated technical evidence: what was tested, which vulnerabilities were verified and how they were fixed. That is the kind of information the sections above ask for.

It does not provide a certification or a statement of compliance. We are not a certification body or an accredited organisation, and our report does not prove compliance with any standard: whether you comply is decided by whoever audits that standard.