NIS2 for ICT service management (B2B)
A deliberate addition in NIS2. MSPs hold privileged access into their customers' networks and were largely outside NIS1 — a gap that supply chain attacks made untenable.
Which entities are covered
Managed service providers and managed security service providers.
Sub-sectors named in the annex
- Managed service providers
- Managed security service providers
Scope traps specific to this sector
Trap 1
You are in scope in your own right, and simultaneously the object of every customer's article 21(2)(d) programme. Expect security questionnaires as well as a regulator.
Trap 2
MSSPs are named separately: selling security does not exempt you from being assessed.
Trap 3
A one-person consultancy is normally below the size cap, but an MSP that is the sole provider of an essential service in a member state can be in scope regardless of size.
What else applies to you
Contractual obligations flowing down from customers subject to NIS2 or DORA.
NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.