6 industries required to run regular penetration tests

Youri van der Zwart ·

Penetration testing is no longer just a best practice reserved for tech-forward enterprises. Across a growing number of industries, it has become a regulatory requirement, and for good reason. Cyberattacks are growing more sophisticated, and regulators worldwide are responding by mandating that organizations actively test their own defenses. If your organization operates in one of the sectors below, understanding your penetration testing obligations is not optional. Here is a breakdown of the six industries where regular pen testing is either required by law or enforced through binding compliance frameworks.

Which sectors face mandatory pen testing rules

Mandatory pen testing requirements typically emerge where the consequences of a breach extend beyond the organization itself. When sensitive data, critical services, or public safety are at stake, regulators step in. The six industries below represent sectors where compliance frameworks explicitly require or strongly mandate regular penetration testing as part of a broader security posture.

1. Financial services and banking

Financial institutions sit at the top of every attacker’s target list, which is exactly why they face some of the strictest penetration testing mandates in any industry. Frameworks such as DORA (the EU’s Digital Operational Resilience Act), PCI DSS, and TIBER-EU all include explicit requirements for regular security testing, including penetration tests conducted by qualified professionals.

Under PCI DSS, organizations that handle cardholder data must conduct penetration tests at least once a year and after any significant infrastructure changes. DORA, which came into full effect in January 2025, goes further by requiring threat-led penetration testing (TLPT) for critical financial entities operating within the EU. These tests simulate real-world attack scenarios using threat intelligence, making them significantly more rigorous than standard assessments.

Banks, payment processors, insurance companies, and investment firms all fall within scope. The financial consequences of non-compliance, combined with the reputational damage of a breach, make proactive pen testing a business-critical activity in this sector.

2. Healthcare and medical institutions

Healthcare organizations store some of the most sensitive personal data in existence, and attackers know it. Patient records, medical histories, and billing information are high-value targets, and a successful breach can have life-threatening consequences if clinical systems are disrupted.

In the EU, the NIS2 Directive places many healthcare providers in the category of essential entities, requiring them to implement robust security measures, including regular testing of their systems. In the United States, HIPAA does not prescribe pen testing by name, but its Security Rule requires covered entities to conduct technical evaluations of their security controls, which regulators and auditors widely interpret as including penetration testing.

Hospitals, clinics, medical device manufacturers, and health data processors all need to take this seriously. Given the sensitivity of the data and the operational risks involved, pen testing in healthcare is as much about patient safety as it is about compliance.

3. Government and public sector organizations

Government bodies and public sector organizations are high-profile targets for both financially motivated attackers and state-sponsored threat actors. The consequences of a breach extend to national security, public trust, and the continuity of essential services.

The NIS2 Directive, which EU member states are implementing into national law, places government entities in the essential sector category, requiring them to adopt advanced cybersecurity measures, including regular security assessments. Many national governments also have their own frameworks. In the Netherlands, for example, the Baseline Informatiebeveiliging Overheid (BIO) sets security standards for public sector organizations, with penetration testing forming part of the expected security controls.

Local municipalities, national agencies, and public utilities all fall within scope. Given that public sector organizations often operate legacy infrastructure and face resource constraints, external pen testing provides an efficient way to identify exploitable weaknesses before attackers do.

4. Energy and critical infrastructure

The energy sector, along with other critical infrastructure providers such as water treatment, transportation, and telecommunications, faces some of the most severe consequences from a successful cyberattack. Disruption to these services affects entire populations, which is why regulators treat security testing in this sector with particular urgency.

NIS2 explicitly covers operators of essential services in the energy sector, requiring them to implement technical measures to manage cybersecurity risks, including the regular testing of security systems. The EU’s Network Code on Cybersecurity for the electricity sector adds further obligations for grid operators and energy companies operating across borders.

Operational technology (OT) environments present unique challenges for pen testing, as testing must be conducted carefully to avoid disrupting live systems. Specialized OT penetration testing methodologies exist precisely for this reason, and organizations in this sector should work with testers who understand both IT and OT security.

5. Retail and e-commerce

Any organization that accepts credit or debit card payments is subject to PCI DSS, which makes penetration testing a compliance requirement for a large portion of the retail and e-commerce sector. This includes online retailers, brick-and-mortar stores with card terminals, and any third-party service providers that process, store, or transmit cardholder data.

PCI DSS version 4.0, which became the only active standard in 2024, strengthened requirements around penetration testing by demanding that tests cover both network and application layers and that they follow a recognized methodology such as OWASP or NIST. Organizations must also test from both inside and outside their network perimeter.

Beyond PCI DSS, retailers that handle significant volumes of personal data fall under GDPR obligations to implement appropriate technical security measures. While GDPR does not mandate pen testing by name, it is widely recognized as a proportionate measure for demonstrating compliance with the regulation’s security requirements.

6. Legal and professional services firms

Law firms, accounting practices, consultancies, and other professional services organizations hold highly sensitive client data, including privileged communications, financial records, and intellectual property. This makes them attractive targets for corporate espionage and ransomware attacks alike.

While the legal sector has historically been slower to adopt formal cybersecurity frameworks, regulatory pressure is increasing. In the UK, the Solicitors Regulation Authority (SRA) has issued guidance requiring law firms to assess their cybersecurity risks systematically. In the EU, larger professional services firms increasingly fall within the scope of NIS2, particularly those providing services to essential or important entities.

Beyond direct regulation, client contracts and due diligence requirements are driving pen testing adoption in this sector. Many enterprise clients now require their legal and professional services providers to demonstrate a baseline level of cybersecurity maturity, including evidence of regular security testing, as a condition of engagement.

What happens when pen testing requirements are ignored

Ignoring mandatory penetration testing requirements carries consequences that go well beyond a failed audit. Regulatory bodies across the EU and beyond have demonstrated a clear willingness to impose significant fines on organizations that fail to meet their cybersecurity obligations. Under GDPR, fines can reach up to 20 million euros or 4% of global annual turnover. NIS2 introduces additional penalty structures for essential and important entities that fail to implement required security measures.

Beyond financial penalties, non-compliance exposes organizations to reputational damage, loss of client trust, and increased liability in the event of a breach. Regulators are increasingly treating a lack of proactive security testing as evidence of negligence, which can significantly affect the outcome of any post-breach investigation.

The good news is that getting compliant does not have to be complicated. We work with organizations across all of these sectors to deliver penetration testing that meets regulatory requirements without disrupting day-to-day operations. Whether you need to meet PCI DSS, NIS2, or sector-specific obligations, we can help you build a testing program that keeps you both secure and compliant. Reach out to us to discuss your specific requirements and find out how we can support your organization.

Frequently Asked Questions

How often should our organization conduct a penetration test to stay compliant?

V: Hoe vaak moet onze organisatie een penetratietest uitvoeren om compliant te blijven?nA: De vereiste frequentie hangt af van het toepasselijke framework: PCI DSS vereist minimaal één test per jaar en na grote infrastructuurwijzigingen, terwijl NIS2 en DORA risicogebaseerde testing voorschrijven. Het is verstandig om samen met een gespecialiseerde aanbieder een testschema op te stellen dat aansluit op uw specifieke regelgeving.

What is the difference between a standard penetration test and the threat-led penetration testing required under DORA?

V: Wat is het verschil tussen een standaard penetratietest en de threat-led penetratietest die DORA vereist?nA: Een standaard penetratietest volgt een vaste methodologie om bekende kwetsbaarheden te identificeren, terwijl threat-led penetration testing (TLPT) onder DORA gebruikmaakt van actuele dreigingsinformatie om realistische aanvalsscenario's te simuleren die specifiek gericht zijn op uw organisatie. Dit maakt TLPT aanzienlijk grondiger en gerichter dan een reguliere test.

Why does my organization need an external pen tester if we already have an internal IT security team?

V: Waarom heeft onze organisatie een externe pentester nodig als we al een intern IT-beveiligingsteam hebben?nA: Een extern team brengt een onafhankelijk perspectief en gespecialiseerde aanvalskennis die interne teams vaak niet hebben, en veel regelgevers — waaronder PCI DSS en DORA — eisen expliciet dat tests worden uitgevoerd door gekwalificeerde, onafhankelijke professionals. Bovendien voorkomt externe testing blinde vlekken die ontstaan wanneer interne teams hun eigen systemen beoordelen.

When should our organization schedule a penetration test outside of the regular annual cycle?

V: Wanneer moet onze organisatie buiten de reguliere jaarlijkse cyclus een penetratietest inplannen?nA: Een extra penetratietest is aan te raden na grote infrastructuurwijzigingen, de lancering van nieuwe applicaties, een fusie of overname, of na een beveiligingsincident. PCI DSS verplicht dit al expliciet na significante wijzigingen, maar ook andere frameworks verwachten dat organisaties proactief testen wanneer hun aanvalsoppervlak verandert.