Key takeaway: for a managed service provider, NIS2 arrives through two doors. The regulator's door, if you meet the size thresholds, and the customer's door, through every contract renewal and every supplier questionnaire. The second door opens first and opens more often. Providers who can answer that questionnaire in a day close renewals faster than providers who take six weeks and answer defensively.
Most sector guidance about NIS2 addresses the buyer: the hospital, the utility, the manufacturer. Comparatively little addresses the supplier that sits underneath all of them. That is a gap worth closing, because managed service providers occupy an unusual position in the directive. They are explicitly named as an in-scope sector, and they are simultaneously the archetypal third party that the supply chain measure was written about.
This article covers both. How the direct obligation works and how to tell whether it applies to you. How the indirect obligation reaches you through customers regardless of your size. What those customers are asking for, and which of their asks are reasonable. And how to build one evidence pack that serves the regulator, the customer, and the insurer at the same time.
Door one: you are an in-scope entity
Annex I of the directive lists the sectors of high criticality. Alongside energy, transport, banking, health, water and digital infrastructure sits ICT service management for business-to-business services, and within it managed service providers and managed security service providers. That placement is deliberate. A compromise of a provider with administrative access into dozens of customer environments is a systemic event, not a single-company incident.
Being in Annex I does not by itself put you in scope. The size rule in Article 2 still applies: the directive generally covers entities that qualify as medium-sized enterprises or exceed those ceilings, measured with the criteria in the annex to Commission Recommendation 2003/361/EC. That calculation counts headcount alongside turnover and balance sheet total, and it aggregates linked and partner enterprises. A 40-person provider that is majority owned by a large group is very likely counted with that group rather than on its own.
Where you land also determines your supervisory regime. Annex I entities above the medium-sized ceilings are generally essential entities, supervised ex ante under Article 32 with inspections, random checks and audits available without any prior indication of a problem. Medium-sized Annex I entities are generally important entities, supervised ex post under Article 33. For a growing provider this matters, because crossing a headcount or turnover threshold can move you from one regime to the other in a year in which nothing else about the business changed.
Do the calculation and write it down. Whichever answer you get, the artefact you need is the same: a dated scope determination showing the Annex I entry, the headcount and financial figures used, the treatment of linked and partner enterprises, and the conclusion. It answers the regulator, and it answers the first question on every serious customer questionnaire.
Door two: your customers' supply chain obligation
Article 21(2)(d) requires in-scope entities to take measures on supply chain security, including security-related aspects of the relationships between each entity and its direct suppliers or service providers. Recital and guidance material push entities to consider the specific vulnerabilities of each supplier, the overall quality of its products and cybersecurity practices, and its secure development procedures.
For a managed service provider this is the door that matters commercially, because it opens whether or not you are in scope yourself. A 20-person provider with no direct obligation still finds that its hospital customer has an obligation to manage it as a supplier. That obligation is discharged through contract terms, questionnaires, evidence requests and, increasingly, audit rights.
The uncomfortable dynamic is that customers under supervisory pressure push requirements down the chain faster than they negotiate them. Providers who have not decided in advance what they will and will not commit to end up signing terms in a renewal window that they cannot operationally meet. That is worse than a lost renewal, because a missed contractual notification deadline during a real incident becomes a liability question on top of a security question.
What customers ask for, and what to say
- Incident notification within a defined window. Reasonable, and you should offer it before they ask. Work backwards from their 24-hour early warning duty: a 24-hour commitment from you is useless to them. Offer twelve hours generally and six for incidents touching their production environment, and hold that line across all customers so the commitment is operable.
- MFA on all administrative access into their environment. Reasonable and non-negotiable in practice. Be ready to show enrolment figures for your own privileged accounts, including any break-glass accounts and how they are controlled.
- Named security contact and escalation path. Reasonable and cheap. A functional mailbox, a phone number, and a deputy, published in the contract schedule rather than buried in an onboarding email.
- Subcontractor disclosure. Reasonable. Customers cannot manage a chain they cannot see. Maintain the list, agree a notification period for changes, and resist open-ended consent rights that let a customer veto your operating model.
- Audit rights. Reasonable in principle, expensive in practice if every customer exercises them separately. Counter with an independent assessment report or certificate plus a bounded right to audit on cause, with notice and cost allocation defined.
- Access to your incident evidence. Reasonable for incidents affecting them, and worth scoping tightly. Commit to the facts relevant to their environment and timeline, not to your full internal forensic report, which will contain other customers' data.
- Flow-down of the customer's full NIS2 obligations. Not reasonable. You cannot assume another entity's regulatory duties by contract, and a clause that says you will "ensure the customer's NIS2 compliance" is unbounded. Offer specific, measurable commitments instead.
Build one pack, answer three audiences
The efficiency win for a provider is that the regulator, the customer and the cyber insurer want overlapping evidence. Build it once, in a form you can share without rewriting, and the supplier questionnaire stops being a two-week project each time.
The MSP evidence pack
- Dated scope determination and, if in scope, the classification decision and registration confirmation.
- Risk-management policy approved by the management body, with the approval date and minute reference.
- Privileged access model for customer environments: who can reach what, through which jump path, with which authentication, reviewed how often.
- Tenant separation statement: how one customer's compromise is prevented from reaching another, including in your own management tooling.
- MFA coverage report for privileged accounts, with the exception list, owners and review dates.
- Incident response plan with the customer notification commitment written into it, plus the last exercise report.
- Restore test evidence for your own platform and for any customer data you hold.
- Subcontractor register with tiering, the flow-down clauses used, and the change notification commitment.
- Secure development and change management evidence for any tooling or scripts you run inside customer environments.
- A standing answer document mapping the twenty most common questionnaire questions to the artefact that answers each one.
The three gaps we find most often at providers
Providers tend to be technically strong and evidentially thin, which is the opposite failure mode from their customers. Three gaps recur.
First, the management tooling is the crown jewel and is not treated as one. Remote monitoring and management platforms, deployment tools and script libraries reach every customer at once. They frequently sit outside the formal asset inventory, outside the change process, and on an authentication path that is more convenient than the one imposed on customer systems. Any risk assessment that does not treat the management plane as the highest-impact asset in the business is not describing the real risk.
Second, incident notification commitments are made in contracts and never wired into the on-call process. The service desk that detects the incident does not know that a six-hour customer clock started, because the clock lives in a contract schedule that operations has never read. The fix is to put notification windows into the runbook the on-call engineer actually opens, with the contact route per customer.
Third, the provider's own suppliers are unmanaged. Providers ask their customers to accept a subcontractor list while maintaining none themselves for the software vendors, cloud platforms and offshore teams they depend on. Article 21(2)(d) applies to your direct suppliers as much as to anyone else's, and it is the question a well-prepared customer will ask second.
Turning the obligation into a sales asset
Every in-scope customer has to demonstrate that it performs due diligence on its critical suppliers. A provider who arrives at the renewal with the evidence pack already assembled makes that demonstration easy, and gets to be the supplier the customer points at when the supervisor asks how supply chain security is managed. That is a genuine differentiator in a market where most competitors respond to questionnaires with a certificate number and a fortnight of silence.
The practical move is to publish a standard supplier assurance pack, refresh it on a fixed cycle, and lead with it in the sales conversation rather than waiting for procurement to request it. It shortens deals, reduces the volume of bespoke questionnaire work, and gives you a defensible position when a customer asks for terms you cannot meet, because you can show what you do commit to and why those numbers are the ones you can actually deliver.
Frequently asked questions
Are managed service providers in scope of NIS2?
Yes. Managed service providers and managed security service providers are named in Annex I of the directive under the ICT service management sector for business-to-business services. Being named in Annex I means the size thresholds still apply, so a provider that meets the medium-sized enterprise criteria is in scope as an entity in its own right.
Is an MSP an essential or an important entity?
It depends on size. Annex I entities that exceed the ceilings for medium-sized enterprises are generally essential entities; medium-sized Annex I entities are generally important entities. So a larger provider faces ex ante supervision under Article 32, while a medium-sized one faces ex post supervision under Article 33.
What if my MSP is too small to be in scope?
You are still reached indirectly. Article 21(2)(d) requires in-scope entities to manage supply chain security, including the security of their direct suppliers. A provider below the size thresholds has no direct obligation, but its in-scope customers do, and they discharge that obligation through contract clauses, questionnaires and audit rights.
What do in-scope customers ask MSPs for?
Most commonly: incident notification within a stated window that is short enough for the customer to meet its own 24-hour early warning, evidence of MFA on all administrative access into their environment, restore test results, subcontractor disclosure, a named security contact, and an audit or information right. Increasingly also a commitment to notify vulnerabilities in the provider's own tooling.
Do MSPs have to register under NIS2?
In-scope managed service providers register nationally like any other in-scope entity, and they are also named in Article 27, which means their data is forwarded to ENISA for the Union-level registry. Jurisdiction follows the main establishment rule, normally the place where decisions on cybersecurity risk-management measures are predominantly taken.
How fast should an MSP commit to notifying a customer of an incident?
Work backwards from the customer's obligation. They owe an early warning within 24 hours of becoming aware of a significant incident, and they need time to assess before they file. A notification commitment of 24 hours is therefore too slow to be useful. Twelve hours is a common negotiated position, and six hours for incidents affecting the customer's production environment.
Does ISO 27001 satisfy what customers ask for?
It answers a large part of the questionnaire and shortens the conversation considerably, but it does not answer the NIS2-specific questions. Certificate scope is the usual sticking point: a customer wants to know whether the specific service they buy, delivered from the specific location it is delivered from, sits inside the certified scope. Check the scope statement before quoting the certificate.
Answering customer questionnaires one at a time?
We help providers build the supplier assurance pack once: scope determination, privileged access model, notification commitments that operations can meet, and a standing answer document that turns a two-week questionnaire into a one-day response.
Book a provider readiness review