Is Your Online Marketplace an RDSP? Penetration Testing Under the NIS Regulations

Is Your Online Marketplace an RDSP? Penetration Testing Under the NIS Regulations

By EJN Labs · 20 Aug 2026 · 8 min read

If your online marketplace has 50 or more staff, or turnover above 10 million euros, it is likely a relevant digital service provider (RDSP) under the UK NIS Regulations 2018 and must register with the ICO. The regulations do not name penetration testing, but they require monitoring, auditing and testing as evidence of appropriate security. Marketplace engagements typically run five to twelve days, £6,000 to £16,800.

Why RDSP NIS penetration testing matters for online marketplaces

RDSP NIS penetration testing matters because a marketplace that lets consumers or traders conclude contracts with third-party sellers may be a relevant digital service provider under the Network and Information Systems Regulations 2018, bringing a registration duty, a security duty and the ICO as regulator.

It is a requirement that catches many marketplace operators by surprise.

The stakes are real: penalties of up to £17 million for the most serious failures, and a 72-hour incident reporting duty. This article explains who counts as an RDSP, what the regulations expect, and where penetration testing fits, without overstating the law.

Is your marketplace actually an RDSP? The applicability test

Your marketplace is in scope if it allows consumers or traders to conclude online sales or service contracts with traders, which is how the NIS Regulations define an online marketplace. Platforms hosting the transaction are in scope, while price comparison sites that redirect users elsewhere are generally out.

The regulations define three types of digital service in total: online marketplaces, online search engines and cloud computing services.

You are an RDSP, and must register with the ICO, if all of the following apply:

  • You provide one or more of the three digital service types, including an online marketplace.
  • You have a head office in the UK, or you have nominated a UK representative.
  • You are not a small or micro business, meaning you have 50 or more staff, or an annual turnover or balance sheet above 10 million euros.

Two warnings. First, growth pulls you into scope: cross the headcount or turnover threshold and the registration duty applies, whether or not the ICO has noticed. Second, smaller marketplaces are not off the hook commercially, because enterprise sellers, payment providers and insurers increasingly ask for equivalent evidence. The forthcoming Cyber Security and Resilience Bill is also expected to expand the NIS regime.

What the NIS Regulations expect: the security duty

Regulation 12 requires RDSPs to take appropriate and proportionate technical and organisational measures to manage risks to their network and information systems and to minimise the impact of incidents. The supporting framework breaks that security duty down into five defined elements.

The five elements are security of systems and facilities, incident handling, business continuity, monitoring, auditing and testing, and compliance with international standards.

To be straightforward about the legal position: the regulations never say “you must commission a penetration test”. The duty is risk-based. What the framework does require is monitoring, auditing and testing as a defined element of appropriate security, and you need to be able to evidence how you meet it. In our experience, an independent penetration test from a CREST-accredited firm is the evidence buyers most often accept, because it produces a dated, third-party record of what was tested, found and fixed. Automated scanning alone is much harder to defend as proportionate for a platform processing payments at scale.

The incident reporting duty reinforces this: an incident with substantial impact must be notified to the ICO within 72 hours, and the first questions afterwards are about the measures you had in place beforehand. A recent test report and remediation log answers them; an empty folder does not.

What to test in a marketplace estate

Marketplaces differ from single-vendor ecommerce: you run a multi-tenant platform where thousands of sellers hold valuable accounts and your APIs are consumed by sellers, integrators and mobile apps. A NIS-aligned scope usually covers four layers:

  • The marketplace application. Buyer and seller journeys, authentication and session handling, checkout and refund flows, seller onboarding, and above all tenant isolation: whether one seller can read or manipulate another’s orders, payouts or listings.
  • APIs. Order, catalogue, payment and integration APIs are where marketplace logic lives and where authorisation flaws cluster. Dedicated API penetration testing exercises these endpoints with the credentials an abusive seller or integrator would hold.
  • Cloud infrastructure. UK marketplaces commonly run on AWS, Azure or GCP. A cloud penetration test reviews identity and access management, storage exposure, segmentation and blast radius.
  • The external perimeter. Everything reachable from the internet: admin panels, staging environments, VPN endpoints and forgotten subdomains. External infrastructure testing attacks this surface the way an opportunistic attacker would.

How an engagement runs

A typical engagement starts with a scoping call: how many user roles the platform has, how sellers onboard, which payment providers are integrated, how many API endpoints are exposed and where the estate is hosted. We then agree scope, day count and test window under signed authorisation.

Testing is role-driven. We ask for test accounts at every privilege level, unauthenticated visitor, buyer, seller, and where agreed an admin user, because the highest-impact marketplace findings are almost always horizontal: one tenant reaching another tenant’s data. We test staging where it exists, or production under agreed safeguards, and flag findings that expose live data the day we confirm them.

You receive a report with an executive summary for your board and regulator and a technical section with reproduction steps for your engineers. Retesting of fixed findings is included, so your evidence shows closure, not just discovery. Our penetration testing checklist walks through what to have ready before a test starts.

What it costs and how scope drives the price

UK penetration testing is priced by effort: day rates at accredited firms typically run £1,100 to £1,400, and the day count depends on platform size, user roles, APIs and layers included. Typical ranges:

ScopeTypical effortTypical cost
Marketplace web application and APIs5 to 8 days£5,500 to £11,200
External infrastructure and perimeter3 to 5 days£3,300 to £7,000
Cloud configuration review3 to 5 days£3,300 to £7,000
Full estate: application, APIs, cloud and external8 to 12 days£8,800 to £16,800

These are typical ranges, not a quote; a large microservices estate will sit above them, a lean one below. Our guide to penetration testing costs in the UK breaks down the drivers; the fastest route to an exact figure is a scoped quote.

How EJN Labs approaches RDSP testing for marketplaces

EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. That matters for NIS evidence: a report from an accredited firm carries weight with the ICO, enterprise sellers and insurers.

For RDSP work we map the engagement to the duty: the report states what was tested against each layer of your estate, so it reads directly as evidence for the monitoring, auditing and testing element of Regulation 12. We prioritise the risks that define marketplaces, tenant isolation, payment and payout flows and API authorisation, and scope proportionately: the regulations ask for appropriate measures, not the largest test you can buy. If you are comparing suppliers, our guide to choosing a UK penetration testing provider sets out the questions worth asking, and our CREST penetration testing page explains the accreditation.

Frequently Asked Questions

Is my online marketplace an RDSP under the NIS Regulations?

You are likely an RDSP if your platform allows consumers or traders to conclude sales or service contracts with traders, you have 50 or more staff or an annual turnover or balance sheet above 10 million euros, and you have a UK head office or nominated UK representative.

Small and micro businesses are exempt from registration, though contracts with larger partners may still require equivalent security evidence.

Do the NIS Regulations require penetration testing for RDSPs?

Not by name. Regulation 12 requires appropriate and proportionate technical and organisational measures, and the supporting framework lists monitoring, auditing and testing as a defined element of those measures. The duty is risk-based, so each RDSP chooses how to evidence it.

An independent penetration test from a CREST-accredited firm is, in our experience, the most common form of that evidence, which is why in-scope marketplaces commonly commission one annually.

What does RDSP NIS penetration testing cost for an online marketplace?

Typically £6,000 to £16,800 depending on scope. Marketplace engagements typically run five to twelve days at UK day rates of £1,100 to £1,400. A focused web application and API test sits at the lower end, a full estate covering platform, cloud environment and external perimeter at the upper end.

Exact pricing depends on your platform, so request a scoped quote.

What happens if an RDSP fails to meet its NIS security duties?

The ICO can serve information and enforcement notices and issue penalties of up to £17 million for the most serious contraventions, since it enforces the regulations for RDSPs. RDSPs must also report incidents with a substantial impact on their service to the ICO within 72 hours.

A recent penetration test report and remediation record materially strengthens your position in any regulatory conversation.

How often should an RDSP test its marketplace platform?

Test annually as a minimum, and after any significant change such as a re-platform, a new payment integration, a major API release or a change of cloud provider. The NIS security duty is ongoing, so your testing evidence needs to stay current throughout the year.

Marketplaces ship code continuously, so many pair an annual full-scope penetration test with narrower retests of high-risk changes during the year.

Get NIS-ready evidence for your marketplace

If your marketplace is in scope, or heading that way, the first step is a scoped test mapped to the security duty. Request a penetration testing quote and speak to our UK-based testers.

Leave a Reply

Your email address will not be published. Required fields are marked *