Three engagement models cover different points on that curve. For a one-off event — a release, an audit, a major change — a focused penetration test covers an agreed scope, validated findings, a technical report and a final validation statement, and can typically start within two weeks of scoping. For organizations that need visibility between regulatory cycles, recurring PTaaS adds planned testing cycles, a shared evidence workspace, structured retest capacity and regular checkpoints. And for regulated, multi-asset or business-critical environments — the profile of most NIS 2 essential entities and DORA-supervised financial institutions — a managed penetration testing programme adds multiple technical scopes, named service governance and custom retest commitments. All three are delivered by an EU-based team (with an EU hosting option) holding credentials such as OSCP, OSEP, OSED and CRTO, using a methodology built on PTES, NIST SP 800-115 and OWASP standards. Humans make every testing decision and validate every finding; AI supports preparation, triage and report quality, but runs no autonomous tests against client systems.
Why Is This the Resilient, Cost-Effective Way to Manage the Risk?
A fragmented approach — separate one-off tests for different audits, reports scattered across systems, and no shared remediation history — creates duplicated effort and makes it harder to demonstrate that vulnerabilities have actually been resolved.
Cost-effectiveness comes from reuse, not a lower day rate. A shared testing and evidence process allows organizations to reuse relevant findings, remediation history, retest results, and supporting evidence across multiple compliance and assurance activities, where applicable, instead of starting from zero with every engagement. IBM found a USD 1.3 million cost difference between breaches with lifecycles below and above 200 days, reinforcing the business value of identifying and addressing security weaknesses earlier.
Resilience comes from the Verify step, not the Find step. Finding vulnerabilities is only the beginning. Retesting confirms whether remediation actually closed the attack path, while a retained testing history and defined retest process provide evidence that risks are being addressed over time.
This turns penetration testing from a series of isolated assessments into a continuous Find → Fix → Verify → Prove process that supports both risk management and compliance evidence.
NIS2 Penetration Testing Checklist
Conclusion
The requirements for NIS2 penetration testing and DORA penetration testing are not identical — but both frameworks expect a risk-based, documented, verifiable process, not a one-off report. For Bulgarian organizations under the amended Cybersecurity Act, or under BNB/FSC supervision for DORA, the difference between “we have last year’s report” and “we have a defensible, current cycle from finding to verified closure” can decide the outcome of an audit, an insurance assessment, or a regulatory review. If you’re preparing your scope for NIS 2, DORA, or a combination of frameworks, IBA Group can review your environment and propose a risk-based testing plan tied to the requirements that actually apply to you.
Book a workspace demo or Discuss your assurance needs.
Penetration testing and the related evidence support compliance and assurance activities, but do not by themselves constitute certification or guarantee regulatory compliance.
FAQ
When did Bulgaria's Cybersecurity Act, transposing NIS 2, enter into force?
Bulgaria’s amended Cybersecurity Act, which transposes NIS 2, has been in force since 17.02.2026. Part of the Act’s secondary legislation, including an implementing ordinance and a national register of covered entities, is still being finalized.
Does NIS 2 set a specific penetration testing cadence?
No. Neither the NIS 2 Directive nor Bulgaria’s Cybersecurity Act sets a universal penetration testing frequency or scope. NIS 2 requires a risk-based approach, supported with evidence on request.
Who is the competent authority for DORA in Bulgaria?
DORA supervision in Bulgaria is split between the Bulgarian National Bank (BNB) and the Financial Supervision Commission (FSC/KFN). The BNB oversees credit and payment institutions, while the FSC/KFN covers investment firms, insurers, pension providers and crypto-asset service providers. The FSC can initiate penetration testing of investment firms, regulated markets and crowdfunding providers.
What is TLPT, and does it apply to every financial institution?
TLPT (Threat-Led Penetration Testing) is DORA’s most rigorous testing level, combining real threat intelligence, red and blue team components, and live production systems. TLPT applies only to identified significant entities, not every financial institution subject to DORA, and must be repeated at least every three years.
Does a single penetration test automatically make an organization compliant?
No. A single penetration test produces evidence that supports compliance and assurance activities, but compliance also depends on the applicable framework, scope, governance, controls, remediation and documentation.
Can one test cover requirements across several frameworks at once?
A single penetration test can cover some requirements across several frameworks when its scope and documentation are carefully designed. However, each framework has its own requirements. For example, TLPT requires live production systems and external threat intelligence, so one test rarely provides complete coverage across every framework.
How should we choose a penetration testing provider for a compliance engagement?
A penetration testing provider for a compliance engagement should have relevant technical expertise, appropriate tester credentials, the required level of independence, and a clear process for evidence, remediation and retesting. The provider should also distinguish clearly between legal requirements and recommended practice.










