Is a vulnerability scan mandatory under NIS2?
Published on August 16, 2026
This article is general information about laws and regulations, not legal advice.
In short: a vulnerability scan is not legally required under NIS2. No tool is. The law requires appropriate measures for risk management and the ability to demonstrate those measures. For many organisations, a continuous scan becomes the practical way to meet that bar, even though the law never uses the word "scan".
Anyone receiving their first NIS2 questionnaire from a large customer soon searches for whether a vulnerability scan is mandatory. The answer is short. The explanation behind it determines what you do need to arrange, and that is what this article is about.
What the law does require
Article 21 of the NIS2 directive requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to their network and information systems. Paragraph 2 explicitly lists topics such as risk analysis, incident handling, business continuity and supply chain security. In the Netherlands these requirements have been in force since 15 August 2026 through the Cyberbeveiligingswet (the Dutch NIS2 implementation), without a general transition period.
One element comes closer to scanning than the rest. Article 21(2) explicitly names vulnerability handling and disclosure under (e), as part of security in the acquisition, development and maintenance of systems, and policies and procedures to assess the effectiveness of the measures under (f). The directive leaves open how you find vulnerabilities, but without a way to find them, there is nothing to handle, disclose or assess.
Beyond that, the list names no product, scanner or frequency. The core of the duty of care: measures must fit your risks, and you must be able to show they work. Having measures in place is not enough; the bar is demonstrating them.
Why "mandatory" is the wrong question
Asking "which tool must I buy to be compliant" skips exactly the step the law puts first: the risk analysis. A vendor claiming its product is required by NIS2 is selling urgency. That applies to Exposentry too: scanning is not NIS2 compliance.
The question a regulator or auditor does ask: do you know your vulnerabilities, do you manage them, and can you show it? That is where the scan comes in.
Paper or measurement: what the other side wants to see
A policy document and a completed questionnaire describe the intention. An external measurement shows the reality: which systems are exposed to the internet today, which known vulnerabilities are visible on them, and whether the basics are configured correctly. For the supply-chain duty of care that difference is essential: your customer has to explain to their regulator why they trust you, and a dated, independent report is stronger evidence than a promise.
What demonstrable evidence looks like in practice
Four properties make a measurement usable as substantiation. It is dated: the report shows when the measurement took place, so it is clear how current the picture is. It is repeated: a single scan from last year says little about today; a series of reports shows that vulnerabilities are followed up. It is independent: an outside measurement by a party with no stake in the outcome carries more weight than a self-declaration. And it is verifiable: whoever receives the report must be able to check it has not been altered since, for instance through a digital seal with a timestamp.
A questionnaire can sit alongside such a measurement. The combination is strong: the paper describes the policy, the measurement substantiates that the policy works in practice.
Where the scan fits in vulnerability management
Vulnerability management follows the same steps everywhere: discover what you have, detect what is vulnerable on it, prioritise, remediate and demonstrate. The scan is the detection step in that process. The steps around it turn the resulting list into management you can account for. Organisations that set this up continuously are doing vulnerability monitoring: the same detection, but ongoing.
Deciding for yourself what is appropriate
"Appropriate and proportionate" means a one-person business with a single website needs something different from a software supplier to hospitals. For most SMEs in a supply chain the combination is the logical route: a continuous, broad vulnerability scan as the foundation, and targeted in-depth testing where the risks are greatest. How the two relate is covered in the difference between a penetration test and a vulnerability scan.
Conclusion
Is a vulnerability scan mandatory under NIS2? No. Is it, for most organisations, the practical way to fulfil and demonstrate the duty of care around vulnerabilities? In many cases, yes. The law does not prescribe a tool. In practice the bar is what you can demonstrate; that reading comes from audits and customer questionnaires, while the legal text itself stays technology-neutral. What you measure, you can substantiate and improve.
Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.