Have a NIS2 pentest conducted
We test like an attacker attacks and report like a regulator reads. This turns every vulnerability into proof that you take your NIS2 duty of care seriously and are taking proactive measures to prevent incidents.
We test like an attacker attacks and report like a regulator reads. This turns every vulnerability into proof that you take your NIS2 duty of care seriously and are taking proactive measures to prevent incidents.
NIS2 pentest
The Cybersecurity Act requires appropriate measures and the periodic review of their effectiveness. Our ethical hackers test your network and information systems and deliver the report with which you can demonstrate this to your management and regulator.
Schedule a no-obligation consultationDownload Buyer’s Guide
Retest standard included·Reporting within 5 working days·According to the CCV certification mark
SOME OF OUR CLIENTS
| Characteristic | Warpnet | Other parties |
|---|---|---|
| Approach | ||
| Retest | ||
| Methodology | ||
| Reporting | ||
| Presentation of Evidence | ||
| Support |
Certifications & methodologies
CCVOSCPOSSTMMPTESOWASPMeow







Developers of cable and asset management solutions

Right in the middle of the process toward ISO 27001 certification, Patchmanager wanted to structurally strengthen the digital resilience of both the organization's internal network and the product — with regular, in-depth pentests as the foundation.

The collaboration began with three black-box penetration tests and, as trust grew, expanded to include gray-box and white-box testing. During the white-box test, Warpnet was granted full access to the architecture, source code, and accounts to identify risks.

Each test delivered a clear, risk-based report that allowed Patchmanager to get to work immediately. The collaboration evolved into 24/7 SOC services featuring continuous monitoring, response, and the complete remediation of risks and incidents.
“We are very happy with the collaboration with Warpnet. The team has in-depth expertise and truly looks at how they can help us. They communicate well, are flexible, and always do more than they are supposed to do.”
Certifications & Accreditations
Frequently Asked Questions
Yes. Once your team has implemented the recommendations, we can perform a retest upon request to confirm that the vulnerabilities have indeed been resolved. This demonstrates to your management board and regulator that a finding has not only been identified, but also resolved.
The Cybersecurity Act does not mention the word pentest. The law prescribes ten duty of care measures, including policies and procedures to assess the effectiveness of your measures (Article 21, paragraph 2, sub f) and securing systems against vulnerabilities (Article 21, paragraph 2, sub e). A pentest is the most concrete way to demonstrate that effectiveness. You decide for yourself, based on your risk analysis, which measures are appropriate and proportionate.
After a no-obligation intake, you will receive a quotation, and that is the price you will pay. The price depends on the size of the systems with which you deliver your service. Reporting, explanation, and re-testing are included as standard. Below you will find general price indications for a one-time pentest and Pentesting as a Service (continuous pentesting).
One-time pentest: v.a. €3,200
Pentesting as a Service: approx. €1,250 per month
The Cybersecurity Act, the Dutch implementation of NIS2, entered into force on August 15, 2026. There is no transition or grace period: the registration obligation, the duty of care, and the notification obligation apply from that date. Over 8,000 Dutch organizations fall under the law. You must report significant incidents within 24 hours, followed by a notification within 72 hours and a final report within a month.
Not automatically. ISO 27001 is a strong basis for the duty of care, but the law contains no provision that equates certification with compliance. Obligations such as registration with the NCSC, reporting deadlines, supply chain security, and the knowledge and approval of the management board fall outside your certificate. A pentest provides evidence for the technical part of the duty of care and is useful for both.
Then you will encounter it through the supply chain. Organizations subject to the law must include supply chain risks in their risk management and are assessed on this by their regulator. In practice, this means stricter requirements in contracts and increasingly frequent requests for a recent penetration test report. With a penetration test from Warpnet, you can answer that request with evidence, without having to go through a certification process yourself.