← All articles

ARTICLE · DATA LEAK ACTIVE TESTING

NIS2 and data protection: proving your measures are effective

  • Compliance
  • 6 min read
  • Updated
Glowing cyan padlock on a circuit crossed by colourful data flows, an image of data protectionA measured result, not a configuration

The essentials in 30 seconds

  • Point (f) of Article 21 also requires you to assess the effectiveness of your risk management measures.
  • A console screenshot will not be enough: you will need test results, with their dates.
  • We build this evidence by replaying exfiltration scenarios with synthetic payloads and dating each result; you then track every fix.

Article 21 of NIS2 does not stop at security measures. Its point (f) also requires policies and procedures to assess their effectiveness. In plain terms, for data protection: you must be able to show, with dated results, how your controls behave when faced with an unauthorised exfiltration attempt. A configured DLP rule does not show that. A test that actually tried to get a synthetic file out does, for the scenario it tested.

What Article 21 really requires

Article 21 of Directive (EU) 2022/2555 requires essential and important entities to take “appropriate and proportionate” technical, operational and organisational measures. Its paragraph 2 lists at least ten areas, six of which directly concern your data:

  • (a) policies on risk analysis and information system security;
  • (b) incident handling;
  • (d) supply chain security;
  • (f) policies and procedures to assess the effectiveness of risk management measures;
  • (h) cryptography and, where appropriate, encryption;
  • (i) human resources security, access control and asset management.

Diagram · from the text to the evidence

NIS2, Article 21, point (f): from requirement to evidenceThree steps linked by arrows. What the text requires: assess the effectiveness of risk management measures. Expected evidence: a measured, dated result, not a documented configuration. What the test provides: a blocking and detection rate per channel, replayed over time.WHAT THE TEXT REQUIRESArticle 21, point (f)Assess the effectiveness of measuresEXPECTED EVIDENCEA measured, dated resultnot a documented configurationWHAT THE TEST PROVIDESA blocking and detection rateper channel, replayed over time

What point (f) expects, and what testing brings to it.

Where transposition stands, in the EU and the UK

The directive had to be transposed by 17 October 2024, with national measures applying from 18 October 2024 (Article 41 of Directive (EU) 2022/2555 on EUR-Lex). Transposition has been uneven across the EU: the European Commission sent reasoned opinions to 19 Member States on 7 May 2025, then on 8 July 2026 referred four of them to the Court of Justice of the EU for failing to notify full transposition (European Commission). NIS2 does not apply in the United Kingdom. There, the reference text remains the Network and Information Systems Regulations 2018, whose regulation 10 already requires operators of essential services to take appropriate and proportionate technical and organisational measures, with guidance such as the NCSC’s Cyber Assessment Framework (CAF). The Cyber Security and Resilience (Network and Information Systems) Bill, which reforms these Regulations and brings medium and large managed service providers and data centres into scope, is not yet law: as of 4 October 2026, it has completed its Commons stages and Lords committee stage, and Lords report stage is scheduled for 26 October 2026 (UK Parliament, bill progress).

NIS2 and data protection: configuration versus evidence

Open a typical compliance file: signed policies, screenshots of DLP rules, a control matrix. So much for the form. None of it demonstrates that a sensitive file cannot get out. A rule can be active and never trigger, because of a wrong pattern, an uncovered channel or an exception inherited from an old project. These DLP false negatives make no noise, and your dashboard will not flag them.

The stakes are far from theoretical. In its Annual Review 2025, the UK’s National Cyber Security Centre (NCSC) reports 204 nationally significant incidents between September 2024 and August 2025, against 89 the previous year. An experienced auditor will end up asking how you checked that your measure produces the expected effect, and a screenshot does not answer that.

What you show What it proves What is missing
Signed data protection policy An intention No measure of effect
Screenshot of DLP rules A configuration on a given date Behaviour when faced with a real attempt
Annual pentest A snapshot of a given scope Drift between two engagements
Repeated exfiltration test results A dated blocking and detection rate per channel Very little, provided findings lead to tracked fixes

Building evidence of effectiveness, step by step

  1. Link each measure to a leak risk. Start from your risk analysis (point (a)). For each category of critical data, list the plausible exfiltration channels: email, encrypted web traffic, personal Google Drive or Dropbox, Teams or Slack, USB drives, DNS. Attach each channel to at least one named measure.
  2. Define a measurable success criterion. “DLP is deployed” tells you nothing. “A file classified as confidential sent to an unapproved sharing service is blocked, or detected and reported to the SOC within 15 minutes” is a criterion, to be adapted to your context. Without a criterion, the point (f) assessment has nothing to assess.
  3. Replay attack scenarios with synthetic data. Active testing genuinely attempts the exfiltration, on your channels, with decoys that look like your data without being your data. No real business data is used. Our article on synthetic data in production details the method, and the page on data exfiltration testing sets out the overall framework.
  4. Repeat over time. A measure that is effective in January may no longer be in June: an agent update, a new SaaS application, a proxy change. The directive talks about procedures, which means an ongoing process. Each Enforcis campaign produces dated results; upcoming versions will let you schedule periodic replays, or replays triggered by a change, depending on how critical the scope is and how fresh the evidence needs to be.
  5. Track remediation. An auditor will hold a failure that was found and never fixed against you. Each failure therefore leads to a prioritised action, an owner, a deadline and then a new test. On the Enforcis side, upcoming versions will bring contextual, prioritised recommendations, validated by retest.

Scenario: the auditor’s question

An industrial equipment manufacturer, classified as an important entity, presents its file. The auditor picks a risk at random: technical drawings leaking to personal storage. First possible answer: “We have a DLP rule that covers this case”, with a screenshot as proof. Second answer: “This scenario is replayed every month. It failed in March on the Mac workstations, we fixed it in April, and the control has held ever since. Here is the history.” With the second answer, the auditor moves on to the next point.

Next step

What would you tell the auditor tomorrow?

A 30-minute demo: a full campaign across the 8 channels we test, on our demo environment. The POC shows, on site, how the solution behaves in your environment, on one simple scenario in a synthetic environment. What actually leaves through your channels is what the pilot shows you.

Checklist before an inspection

  • An up-to-date map of critical data and their exfiltration channels.
  • For each channel, a named measure and a written success criterion.
  • Dated test results, with the method described and the synthetic data used.
  • A history covering several months.
  • A gap register: action, owner, fix date, revalidation.
  • A summary presented to management, in line with Article 20 (see our DLP metrics for the board).
  • A link with the incident management process: a test that succeeds without an alert is also a detection finding.

FAQ

Does NIS2 explicitly require DLP?

No. The directive names no tool. It requires measures proportionate to the risk and an assessment of their effectiveness. If data leakage is among your major risks, you must show how you control it, with or without DLP.

What is a measurable success criterion for point (f)?

A sentence that says what must happen, on which channel and how quickly. For example: a file classified as confidential sent to an unapproved sharing service is blocked, or detected and reported to the SOC within 15 minutes. “DLP is deployed” is not one. We link each criterion to a risk from point (a) of Article 21, then replay it over time, as described in our comparison continuous validation, pentest or red team.

Should you wait for national law before acting?

No. The requirements of Article 21 have been set by the directive since 2022, and Member States had to apply them from 18 October 2024. National laws, some of them still pending, may change the deadlines and the inspection arrangements. In the UK, the Cyber Security and Resilience Bill will extend the NIS Regulations 2018, whose duty to take appropriate and proportionate measures already applies. The principle itself will not change.

Who should validate these results internally?

Article 20 makes management bodies responsible for approving the measures and overseeing their implementation. Present them with a summary of test results, with open gaps and their deadlines. That summary is what will show that oversight exists.

How your egress controls actually behave, observed scenario by scenario.

With synthetic payloads, we run controlled campaigns on the configured paths and observe how your controls actually behave, scenario by scenario: dated results to present to your management as well as to a NIS2 auditor or a UK NIS regulator.