Test the NIS2 measures on your external attack surface
Hadrian discovers your internet-facing assets, validates which vulnerabilities attackers can exploit and runs pentests on demand. You get current evidence for the Article 21 measures that face the internet.
Worldstream, a Dutch cloud infrastructure provider preparing for NIS2, gets each finding checked for real-world exploitability before it reaches the team.
NIS2 requirements Hadrian supports
NIS2 (Directive (EU) 2022/2555) applies to medium-sized and large entities in the sectors listed in its Annexes I and II, such as energy, transport, banking, health, digital infrastructure, food and manufacturing, plus some entities regardless of size. Member States had to apply their national rules from 18 October 2024.
Asset management
Your measures must cover human resources security, access control policies and asset management. In practice, that starts with knowing which systems you have and who owns them.
Atlas keeps a continuously updated inventory of your internet-facing assets, technologies and services, including assets missing from your official records. Role-based access lets you give each team its own assets.
An exported inventory of internet-facing assets and the technologies on each, which you can reconcile with your asset register.
Vulnerability handling
Build security into how you acquire, develop and maintain network and information systems, including how you handle and disclose vulnerabilities.
Hadrian validates vulnerabilities on internet-facing systems, ranks them by business context and gives step-by-step remediation guidance. Retesting after a fix confirms the vulnerability is closed.
Records for each vulnerability showing when it was found, who owned it and when the retest confirmed it was closed.
Assess whether your measures work
Have policies and procedures to assess how effective your cybersecurity risk-management measures are.
Atlas tests your external attack surface continuously, and Nova runs pentests on demand. Together they show whether the controls on your internet-facing systems hold up against real attack techniques.
Nova pentest reports, plus trends in validated exposures and remediation times over time.
Supply chain security
Cover security in your relationships with direct suppliers and service providers, and take into account the vulnerabilities specific to each one.
Atlas identifies third-party technologies and services on your external attack surface and validates the exposures they introduce. Secure Share sends a single risk to a supplier without giving them platform access.
A list of third-party technologies in your perimeter, and the supplier-related risks you shared and closed.
Management body oversight
Management bodies must approve the Article 21 measures and oversee how they are implemented. They can be held liable when the entity infringes Article 21.
Atlas executive summary exports and Nova report executive summaries give leadership a plain view of validated external risk and remediation progress.
Executive summary reports shared with the management body over time.
Hadrian supports these NIS2 measures for your external attack surface. It does not certify NIS2 compliance.
Know every internet-facing asset you own
Article 21 includes asset management and risk analysis. Atlas starts from a single domain or brand name and finds the assets tied to your organization, including shadow IT, forgotten subdomains and cloud instances. Passive scans run every hour, so the inventory keeps up as your environment changes.
Vulnerability handling your team can act on
Hadrian tests each exposure and only raises the ones it can exploit, with reproduction steps and remediation guidance. Findings can go to Jira, ServiceNow or Microsoft Teams. Once a risk is marked resolved, Hadrian retests it to confirm the fix.
Check that your security measures hold up
Article 21(2)(f) asks for policies and procedures to assess whether your measures work. Atlas tests continuously as your environment changes. Nova runs scoped pentests of web apps and APIs on demand, and Hadrian maps the report to NIS2 Article 21.
More from customers
Budenheim
Budenheim added continuous external visibility to a security program built on audits and scheduled penetration tests.
SHV Energy
SHV Energy's security staff save 40 hours per week on average, and Hadrian retests risks automatically once they are marked resolved.
Article 21 does not name penetration testing. It asks for measures that include vulnerability handling and procedures to assess whether your security measures are effective, taking into account the state of the art and relevant standards. Many teams use pentests and continuous testing to cover those points. Check your national transposition law and any implementing acts for your sector, as they can add detail.
Usually, if you are a medium-sized or large entity in a sector listed in Annex I or II and provide services in the EU. Some entities are in scope regardless of size, such as providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers. Your national law sets the details and whether you are an essential or important entity.
For infringements of Article 21 or 23, Member States must allow maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher (Article 34). Management bodies can also be held liable under Article 20.
For financial entities, NIS2 treats DORA as a sector-specific act. Recital 28 of NIS2 says DORA's provisions on ICT risk management, incident reporting, resilience testing, information sharing and ICT third-party risk apply instead of the equivalent NIS2 provisions. See our DORA page for how Hadrian supports those requirements.
Atlas covers the continuous side: asset discovery, validated exposures and retesting across your external attack surface. Nova adds depth with scoped, on-demand pentests of web apps and APIs, with reports mapped to NIS2 Article 21. Atlas shares its asset data with Nova, so pentests start from your real attack surface.
Find the gaps in your NIS2 measures before attackers do
Book a demo to see your internet-facing assets, the exposures Hadrian validates on them, and the reports your team can share with management and auditors.