For agencies and delivery firms · regulated accounts

Three EU laws make your client prove their software works.

Which ones apply depends on what your client does. More than one can apply at once. The duty is always theirs.

This is a summary of the law in August 2026. It is not legal advice. Your client's counsel owns that call.

§ 1 · Which rule applies

Your client's rules reach your code.

Three EU laws make your client prove their software works. Which ones apply depends on what they do. More than one can apply at once.

If your clientThe ruleThey must be able to show
runs a cloud service, data center, CDN, managed service or marketplace, above small-enterprise size NIS2 A right to audit their suppliers, where appropriate. Documented results that what was delivered meets its security requirements. Outsourced development falls under the same rules.
sells a software product into the EU Cyber Resilience Act Regular security tests. A machine-readable bill of materials. Reporting from 11 September 2026, for products already on the market.
is a bank or an insurer DORA, live since January 2025 Unrestricted rights to inspect and audit any supplier of a critical function. The supplier joins their penetration tests.

In each case the duty is your client's. They discharge it with evidence about the software. Somebody has to produce that evidence, keep producing it, and fix what it finds.

The citations, and what these laws do not say

NIS2 reaches those categories only at medium size or above, under its article 2(1). The size cap lifts only for electronic communications, trust services, DNS and TLD registries. In Implementing Regulation (EU) 2024/2690, the contract term is annex point 5.1.4(e), and it applies “where appropriate”. An entity that judges it inappropriate must write down why, under article 2(2). Point 6.1.2(f) is different: it governs the entity's own buying process, not the contract. Points 6.2.1 and 6.2.3 cover outsourced development, and they bind the regulated entity, not its supplier.

The Cyber Resilience Act binds whoever puts a product on the EU market under their own name, wherever the team sits. Reporting runs on a 24-hour early warning and a 72-hour notification. The final report is due at 14 days for an exploited vulnerability, or one month for a severe incident. Support runs at least five years, or the expected use time if that is shorter. Rules for notifying assessment bodies started on 11 June 2026. Conformity assessment itself, and most of the rest, starts on 11 December 2027.

DORA covers insurance and reinsurance undertakings. The contract terms are article 30, and 30(3) for critical functions. They apply where you supply ICT services on an ongoing basis, not where you wrote code once. Not every financial entity is picked for penetration testing.

None of these laws names a correctness audit, and we will not pretend otherwise. A certified penetration test is an accredited firm's report, and it stays theirs. We produce the engineering evidence underneath one. This is a summary of the law in August 2026. It is not legal advice. Your client's counsel owns that call.

Back to the partner page · Terms · The engagement