Is a Penetration Test Mandatory? What the Law Actually Requires
No German law mandates a pentest by name. The duty comes from PCI DSS, NIS2 Article 21, the CRA, KRITIS, TISAX, ISO 27001 and contracts. Which rule reaches you.
Zyberum Security Team · Published · 7 min read
No law in Germany says “you must have a penetration test”, with one exception for the financial sector. What the laws and standards say instead is that you must apply the state of the art, assess whether your measures work, and prove it. A penetration test is how almost everyone proves it, because nothing else answers “would an attacker get in?” in a form an auditor can read.
So the honest answer to “is a pentest mandatory for us?” is: which of the following applies to you?
The rules that lead to a pentest
| Rule | Who it covers | What it says about testing | How often in practice |
|---|---|---|---|
| PCI DSS v4.0.1, Requirement 11.4 | Anyone storing, processing or transmitting card data | Explicit: external and internal penetration tests, plus segmentation tests | At least every 12 months and after significant changes; segmentation every 6 months for service providers |
| NIS2, Article 21(2)(f); German NIS2 Implementation Act | Important and especially important entities in 18 sectors | Policies and procedures to assess the effectiveness of risk-management measures | Yearly test of exposed systems is the accepted evidence |
| Cyber Resilience Act, Annex I Part II and Article 32 | Manufacturers of products with digital elements sold in the EU | “Effective and regular tests and reviews” of the product’s security; conformity assessment needs evidence | Before placing on the market, then regularly over the support period |
| KRITIS, § 8a BSIG (continued by the NIS2 Implementation Act) | Operators of critical infrastructures | State-of-the-art precautions, proven to the BSI | Proof every two years; pentests are standard evidence |
| TISAX (VDA ISA catalogue) | Automotive suppliers handling OEM data | Technical checks of the information security measures; OEM contracts add explicit pentest clauses | Yearly for exposed systems, per assessment cycle |
| ISO/IEC 27001:2022, Annex A 8.8 and 8.29 | Certified organisations | Management of technical vulnerabilities; security testing in development and acceptance | Regularly; most certified companies test yearly |
| DORA, Articles 24 to 27 | Banks, insurers, payment institutions, their critical ICT providers | Explicit: a testing programme including penetration tests, and threat-led penetration testing for significant entities | TLPT at least every three years; other tests yearly |
| UN R155 and ISO/SAE 21434 | Vehicle manufacturers and, via contracts, their suppliers | The manufacturer must demonstrate appropriate and sufficient testing of the measures in the vehicle type | Per vehicle type approval and significant change |
| Customer contracts and questionnaires | Everyone selling to larger companies | “Annual penetration test by an independent party” is a standard clause | Yearly, report or attestation on request |
What “state of the art” means for you
Several of these rules, KRITIS and NIS2 in Germany, the CRA and the Machinery Regulation in the EU, do not list technical measures but demand the state of the art. The term is deliberately open: it points to what competent practitioners currently consider effective. For the question “do my controls work?”, that is a penetration test; the BSI’s own practical guide for penetration tests has described it as the method for years. If you choose not to test, you need a written reason why your situation does not require it, and that reason has to hold up in front of an auditor or, after an incident, a court.
When a pentest is not required
- You are a small company outside every sector above, with no card data, no OEM customers and no product with digital elements. Then nobody requires it. The question is whether you can afford to find out the hard way; an external infrastructure test costs 3,000 to 7,500 euros.
- Your product is purely internal and never leaves your network. The CRA does not apply; NIS2 may, depending on your sector and size.
- A customer accepts a vulnerability scan or your ISO 27001 certificate instead. Ask them, and get it in writing.
When it is effectively required, even without a clause
- You ship a connected product. From 11 December 2027 the CRA’s full requirements apply, including the conformity assessment under Article 32. Testing evidence is part of the technical documentation. For important products in class II, a notified body looks at it.
- You are in NIS2 scope. The effectiveness check in Article 21(2)(f) has to be done somehow, and the management is personally responsible for the measures. A pentest report dated this year is the quickest answer.
- You supply the automotive industry. TISAX assessments and OEM supplier contracts rarely leave testing optional; see TISAX and penetration testing.
- You handle card payments yourself rather than through a fully outsourced provider. PCI DSS 11.4 is unambiguous.
- You operate critical infrastructure. The BSI’s proof cycle expects to see testing.
What to do with this
- Find your rule. Go through the table and mark what applies. Most companies find two or three.
- Take the strictest cadence. If PCI DSS says yearly and your OEM customer says yearly, you test yearly; see how often to pentest.
- Scope to the rule. For PCI DSS, the cardholder data environment and its segmentation. For the CRA, the product and its update path. For NIS2, the internet-facing systems and the paths into the OT. Scoping to the rule also keeps the cost predictable.
- Keep the evidence. The report, the retest and the fix tickets are what the auditor wants. Store them for the proof cycle.
Zyberum tests against all of the rules above and writes reports that map findings to the relevant clause. We are not a certification body and do not issue certificates; we deliver the evidence you take into your audit or conformity assessment. If you are unsure which rule reaches you, a free consultation sorts it out in an hour.
FAQ
Frequently asked questions
Is a penetration test required by law in Germany?
Not by name, with one exception: financial entities under DORA must run threat-led penetration tests at least every three years. Everyone else has duties to assess the effectiveness of security measures, to apply the state of the art or to meet a standard, and a penetration test is the accepted way to prove it. Auditors and customers ask for one because nothing else gives the evidence as cleanly.
Does NIS2 require a pentest?
NIS2 Article 21(2)(f) requires policies and procedures to assess the effectiveness of your risk-management measures. The directive does not say "penetration test". In practice a pentest of the exposed systems is the simplest effectiveness check an auditor accepts, and the BSI names penetration tests among the tools for it.
Is a vulnerability scan enough to meet these requirements?
For PCI DSS no, it requires both quarterly scans and yearly penetration tests. For NIS2, ISO 27001 and the CRA a scan covers known weaknesses but not whether your controls hold against a real attacker, which is the question these rules ask. Most auditors want to see both.