NIS2 · Sector deep-dive
NIS2 for Managed Service Providers
ICT service management (business-to-business) is one of the new sectors NIS2 added to the Annex I list of high criticality. It covers managed service providers and managed security service providers — the companies that hold privileged access into everyone else's environments. Being listed in Annex I means a large MSP is an essential entity and a medium-sized one is an important entity.
Why MSPs were brought into scope
The reasoning is concentration of privilege. An MSP with fifty clients holds domain administrator rights, remote management agents and backup credentials across fifty organisations, several of which may be in-scope entities themselves. A single compromise of the provider's remote monitoring and management platform propagates downward automatically — which is precisely the pattern of the most damaging supply chain attacks of the last several years, where the tooling built to fix machines at scale was used to encrypt them at scale.
NIS2 answers this from both directions. It places MSPs and MSSPs directly in Annex I so they carry their own obligations, and it requires every in-scope customer to manage supplier risk under Article 21(2)(d), taking into account each direct supplier's vulnerabilities and cybersecurity practices. For most providers the second pressure arrives long before the first: customers start sending questionnaires and redlining contracts well ahead of any supervisory contact.
Where providers typically have the biggest gaps
- The management platform is the crown jewel and is not treated as one. RMM, PSA and backup consoles need the strongest identity controls in the business, tiered administration and hardware-backed MFA — not the same login policy as the helpdesk inbox.
- Shared technician credentials. Common local administrator passwords reused across customer estates remove any ability to contain a single compromise or to attribute actions during an investigation.
- No customer notification procedure. Providers know how to escalate technically but have no written commitment on when and how a customer is told, which leaves the customer unable to meet its own reporting clock.
- Undocumented subcontracting. Offshore NOC partners and specialist subcontractors with access that customers were never told about.
- Security sold, not practised. MSSPs in particular are held to their own marketing; supervisors and customers both expect the internal programme to match the service catalogue.
What this means for the Article 21 measures
- Access control and asset management — Article 21(2)(i) and (j). Individual named accounts per technician per customer, just-in-time elevation, privileged access workstations for the management platform, and full audit logging.
- Incident handling — Article 21(2)(b). A procedure that includes notifying affected customers with enough detail and speed for them to file their own early warning within 24 hours.
- Supply chain security — Article 21(2)(d). You are both an assessor and the assessed: evaluate your own tooling vendors and subcontractors, and be able to hand a customer the evidence pack they need for their file.
See the complete list on the Article 21 requirements page, and check the scope test on who NIS2 applies to before concluding you are below the threshold.
Documentation
The NIS2 Starter Kit doubles as the evidence pack your customers ask for: risk assessment, policy set, supplier register and incident procedure in editable form.
