← All articles

NIS2 penetration testing: how security firms win in AI assistants

7 September 2026 · by Wildbos

Security firms working in the NIS2 market have a new sales problem. Their prospects ask ChatGPT, Perplexity and Gemini about penetration testing obligations. And those assistants answer. The only question is: who do they name?

If your website is not among the sources, your company does not exist for that buyer. Not even if you are technically excellent. This article shows how GEO makes AI assistants name your security firm when NIS2 questions come up.

Why AI assistants now decide who wins NIS2 work

The first question a CISO or procurement manager asks is no longer "which security firm is already in my network?" It is: "what does the NIS2 penetration testing obligation involve, and who can do it for us?"

That question gets typed into ChatGPT or Perplexity. The answer arrives in seconds. And it contains a handful of sources.

Sound familiar? Do you look up technical specifications through an AI assistant yourself rather than through Google?

We see this pattern more and more among security decision makers. The orientation phase has moved. From search engines to conversation. Whoever is not named there does not even reach the shortlist.

This is not something that becomes relevant a year from now. It is happening at every orientation that no longer starts with Google.

NIS2 penetration testing: what security buyers actually ask

To know what you need to be found for, you need to know what is being asked. The questions security decision makers put to AI assistants are concrete.

  • "What are the NIS2 pentest requirements for essential entities?"
  • "How often does NIS2 require a penetration test?"
  • "Which security firms in the Netherlands carry out NIS2 pentests?"
  • "What is the difference between an audit and a pentest under NIS2?"

These are not questions a generic answer covers. The NIS2 directive requires 'important entities' and 'essential entities' to take appropriate and proportionate measures to manage their risks. The Netherlands transposed the directive into the Cyberbeveiligingswet, the Dutch Cybersecurity Act, which entered into force on 15 August 2026.

There is no transition or grace period. The registration duty, the duty of care and the reporting duty apply from day one. Organisations must be able to demonstrate that they have taken appropriate measures and that they test whether those measures work. How you test is not prescribed by law. In practice, a penetration test is one of the most widely used instruments for it.

The scope is broad. NIS2 covers energy, transport, banking, healthcare, digital infrastructure and ICT service providers. And it carries through into the requirements those organisations place on their own suppliers.

Do you see what this means for your security firm? Over eight thousand Dutch organisations fall under the act and have to reconsider how they test their measures. And most of them start their search with an AI assistant.

How AI assistants build answers, and why your website is not in them

AI assistants work differently from search engines. A search engine shows ten results. An assistant picks a handful of sources and summarises them.

There is no second page. There is no "see these five alternatives too". You are in, or you are not.

The blunt reality for many security firms: their website is technically fine, but it never gets cited. We run websites past four AI assistants using the questions that carry the revenue, and we see the same pattern every time.

The site is well built. The content is correct. But AI assistants do not find the pages relevant enough to cite.

Why not? Because most security sites are about their own services and certifications. They do not answer the questions customers actually ask an AI assistant.

A security firm writes at length about its own pentest methodology. But a CISO asks ChatGPT: "what does a NIS2 pentest cost and how long does it take?" That question is answered nowhere on the site.

AI crawlers often do not execute JavaScript. Content that only loads client-side is invisible to them. But the bigger problem is editorial: you are not writing what the customer is asking.

GEO for security firms: the three entry points that work

GEO, generative engine optimization, comes down to one thing: making sure AI assistants name your company as the answer to a question. For security firms, three entry points are effective.

1. Content that answers the customer's question

Write pages that directly answer the questions above. Not a 300-word page that points to your contact form. A 1,500-word page that answers the question in full.

Take "how often does NIS2 require a penetration test?" A good answer covers the directive, the national implementation, the risk-based approach and what that looks like in practice. And only then mentions your service.

This approach requires subject matter knowledge. Your security firm has it. The job is writing it down in a way an AI assistant can cite.

2. Mentions beyond your own domain

AI assistants do not rely only on what you say about yourself. They weigh external sources too: trade publications, news coverage and established technology sites.

A security firm named in an independent article about NIS2 pentests scores better than one that only fills its own website.

We send press releases to national media. Placement is the editor's call. But a well-written piece on NIS2 penetration testing with a genuine angle tends to land somewhere.

Those mentions build the authority AI assistants need in order to trust you.

3. Technical optimisation for AI crawlers

Make sure your site is readable for the crawlers behind ChatGPT, Perplexity, Gemini and Claude. Allow the relevant bots in your robots.txt. Serve your content server-side rendered.

The relevant AI crawlers are GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, PerplexityBot, Google-Extended and CCBot. Do not block them.

Structured data helps as well. With schema.org markup you tell AI assistants explicitly what you offer, where you operate and what your services involve.

This is not a one-off job. It is maintenance, particularly in a field moving as fast as this one.

A common mistake: companies make one technical change and expect to be named everywhere a month later. That is not how it works. GEO is a continuous process of content, mentions and technical work. Like SEO used to be, with different rules.

From found to chosen: turning GEO into won work

Being visible in AI answers is step one. The next step is the customer choosing you. The two are connected, but they are not the same thing.

An AI assistant names your company. The customer clicks through to your website. The story there has to hold up.

What we see work for security firms: pages that name the situation the buyer is in, show what the work actually involves, and are honest about what falls outside the scope. Buyers in this market recognise vagueness immediately.

Measurable results: which source URLs point to you

The only measurement that matters is whether your company is actually named in an answer, and which URL the assistant used to get there. Not impressions, not rankings. Mentions and sources.

Track it monthly across the assistants your buyers use, with a fixed set of questions. That way you see whether a competitor is gaining on you before it shows up in your pipeline.

Want to know whether your security firm is already being named in AI answers to NIS2 questions? Request a free AI visibility scan. We run your revenue questions past four assistants and you see immediately where you stand.

Frequently asked questions

What does the NIS2 penetration testing obligation actually involve?

NIS2 does not prescribe a penetration test in so many words. Article 21(2) lists ten categories of measures; point (f) requires policies and procedures to assess whether your measures are actually effective. A pentest is one of the common ways to demonstrate that, not a legally mandated product. In the Netherlands this runs through the Cyberbeveiligingswet, which entered into force on 15 August 2026.

How often does NIS2 require a penetration test?

The directive names no frequency. The requirement is risk-based: you must be able to justify that your testing matches your risks. In practice organisations often choose annually, supplemented by a test after a major infrastructure change. That is a practice-based choice, not a statutory norm.

How can my security firm get found in ChatGPT and Perplexity?

Through a combination of three things: content that directly answers your audience's NIS2 questions, mentions on external sites such as trade publications, and technical optimisation for AI crawlers. This takes ongoing attention, not a single action. We measure monthly whether your company is actually named in AI answers.

Further reading

The act has been in force since August and the first questions are being asked now. Whoever gets named at that moment is on the shortlist. The rest hear about it once the work has already been awarded.