A managed service provider is in NIS2 twice. Once as an entity: Annex I lists "managed service providers" and "managed security service providers" under ICT service management, business-to-business, and the definitions in Article 6 are wide enough to take in most of the industry. And once as a supplier: Article 21(2)(d) makes every essential and important entity manage the security of its supply chain, and recital 86 singles out managed security service providers as the suppliers to be chosen with "increased diligence". The second reaches an MSP below the size threshold that the first does not. This article takes both, with the text, in the order they arrive.
The definitions take in most of the industry
Article 6(39): a managed service provider is "an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, via assistance or active administration carried out either on customers' premises or remotely". Article 6(40): a managed security service provider is "a managed service provider that carries out or provides assistance for activities relating to cybersecurity risk management". Recital 86 gives the examples for the second: "incident response, penetration testing, security audits and consultancy".
Two features of the definition matter. It is about what is done, not how it is sold: hosting, monitoring, patching, help desk, network operation, backup administration and identity management for customers are all "management, operation or maintenance" of their systems, whether billed as a retainer, a project or a subscription. And "assistance or active administration" covers the consultancy that touches the systems, not only the outsourcing that runs them; a penetration tester is an MSSP by recital 86's own list. A company that sells software the customer runs is a manufacturer under the CRA and not an MSP for that; a company that runs it for the customer is an MSP for that. The two Annex I rows are on the scope tool verbatim.
Size decides which kind of entity
Article 2(1) applies the Directive to an entity of a listed type that is at least a medium-sized enterprise under Recommendation 2003/361/EC: 50 staff or more, or above EUR 10 million in both turnover and balance sheet, counted for the enterprise with its partner and linked enterprises. An MSP or MSSP at that size is an important entity under Article 3(2). One above the medium ceilings, 250 staff or both EUR 50 million turnover and EUR 43 million balance sheet, is an essential entity under Article 3(1)(a), because both rows are Annex I types and Annex I types are essential by size alone: ex ante supervision under Article 32, a fine ceiling of at least EUR 10 000 000 or 2 % of worldwide turnover under Article 34(4). Below the small ceiling the company is outside the Directive as an entity, unless its member state identifies it under Article 2(2)(b) to (e), which a state may do for an MSP that is the sole provider of an essential service or critical for a sector. The seven ways to be essential are their own article.
One state, decided by the main establishment
Managed service providers and managed security service providers are in the list of Article 26(1)(b): jurisdiction goes to the member state of the main establishment in the Union, the place "where the decisions related to the cybersecurity risk-management measures are predominantly taken" (Article 26(2)), and a provider established outside the Union that offers services in it designates a representative in a member state where it does and is under that state's jurisdiction (Article 26(3)). An MSP with engineers in three states and customers in ten has one supervisor. The state's act names it; the act each state has communicated to the Commission is on the register page.
The same list is Article 27's: MSPs and MSSPs had to submit their name, sector, addresses, contact details, member states served and IP ranges to their competent authority for ENISA's registry by 17 January 2025, and must notify changes within three months.
The measures and the thresholds are uniform
Implementing Regulation (EU) 2024/2690 names managed service providers and managed security service providers in its Article 1, so for them the technical and methodological requirements of the Article 21(2) measures are the Regulation's Annex, 13 sections, the same in every state, and whether an incident is significant is decided by its Articles 3 and 10. Article 10 gives MSPs and MSSPs the four criteria cloud providers have: the service completely unavailable for more than 30 minutes; availability limited for more than 5 % of the service's users in the Union or more than 1 million of them, whichever is smaller, for more than one hour; the integrity, confidentiality or authenticity of stored, transmitted or processed data compromised by a suspectedly malicious action; or compromised with an impact on more than 5 % or more than 1 million of the users in the Union, whichever is smaller. Users are counted under Article 3(3) as contracted customers plus the natural and legal persons associated with business customers who use the service, which for an MSP means its customers' users. The mapping page places the 13 sections against ISO 27001; the clocks that a significant incident starts are their own article.
The Regulation's recital 3 says its Annex is written from ISO/IEC 27001 and 27002 among others. For an MSP that is also the answer to the supplier question below: the evidence the customer's due diligence asks for and the evidence the supervisor asks for are the same records.
The supplier every due diligence lands on
Article 21(2)(d) requires every essential and important entity to address "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers", and Article 21(3) tells them to take into account "the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures". Recital 85 names "managed security service providers and software editors" as the suppliers this is about; recital 86 says MSSPs "have however also themselves been the target of cyberattacks and, because of their close integration in the operations of entities pose a particular risk", so that customers "should exercise increased diligence in selecting a managed security service provider".
For an MSP this is the duty that arrives first and from every direction, whatever its own size: the questionnaire, the contract clause, the request for the certificate and the incident notification clause in the master agreement. An MSP with 30 staff and no duty of its own under the Directive has customers with a duty to assess it, and the assessment is against the same measures. The workable answer is the one that serves both: an ISO 27001 system with the Regulation's 13 sections mapped, a certificate from an accredited body, an incident procedure that meets the customer's contractual clock as well as the Article 23 one, and the evidence kept where a customer, a supervisor or an auditor can be shown it without a project.
What to do this quarter
Decide the row, the size class as counted and the state of main establishment, and write the determination down; the scope tool does it from five answers. Check the Article 27 registration and its date. Map the ISMS against the 13 sections and close the gaps. Put Article 10's four thresholds, the "became aware" rule and the customer notification clauses into one incident procedure. Prepare the supplier answer once, from the same records, for the next questionnaire.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 2(1) and (2), Article 3(1) and (2), Article 6(39) and (40), Article 21(2)(d) and (3), Article 23(4), Article 26(1) to (3), Article 27(1) to (3), Article 32, Article 34(4), Annex I point 9, recitals 84 to 86.
- Commission Implementing Regulation (EU) 2024/2690, recital 3, Article 1, Article 3, Article 10, Annex.
- Commission Recommendation 2003/361/EC, Annex, Articles 2 and 3.
This is not legal advice. The member state's act names the authority, the portal and the form, and may identify an MSP under Article 2(2)(b) to (e) whatever its size.