NIS2 Recital 87
The competent authorities, in the context of their supervisory tasks, may also benefit from cybersecurity services such as security audits, penetration testing or incident responses.
NIS2 is a Directive: the binding obligations live in each Member State's transposing national law, and this is the EU Directive text those laws implement.
Source text: EUR-Lex, Official Journal HTML (CELEX 32022L2555). The parser was validated against the anchor articles verified in REP-08.