Last updated: 4 October 2026
Quick answer: NIS2 services for MSPs are packaged offers that help SME clients scope their obligations, close gaps against the ten Article 21 risk-management measures, prepare for 24-hour incident reporting and answer supplier questionnaires. The strongest packages combine a fixed-scope readiness project with a recurring managed compliance or vCISO retainer.
Many of your SME clients have heard of NIS2 but do not know whether it applies to them. Some are directly in scope as medium-sized entities in a covered sector. Many more are not, yet still receive security questionnaires from larger customers who are.
That gap is a real service opportunity for managed service providers. This guide explains what NIS2 services for MSPs should include, how to scope clients, how to package tiers that SMEs can buy, and how to avoid the promises that create liability.
What are NIS2 services for MSPs?
They are repeatable advisory and managed services that turn the NIS2 Directive’s requirements into deliverables an SME can understand, budget for and evidence to a regulator or a customer.
The NIS2 Directive (EU) 2022/2555 had to be transposed into national law by 17 October 2024. It sets a baseline for 18 critical sectors, and the European Commission’s NIS2 overview confirms that medium-sized and large entities in those sectors must apply risk-management measures and meet incident notification rules.
A good NIS2 service line typically covers five areas:
- Scoping: is the client an essential entity, an important entity, or out of scope but in someone else’s supply chain?
- Gap assessment: where the client stands against Article 21 and the national law that applies to it.
- Remediation: policies, technical controls, supplier checks and training.
- Operations: incident handling and reporting support, risk register upkeep, evidence collection.
- Governance: board reporting and management training, which NIS2 makes a personal responsibility for leaders.
Why does NIS2 matter to your SME clients?
Because it reaches them in two ways: directly, if they are medium-sized or larger in a covered sector, and indirectly, through supply chain security duties placed on their customers.
Direct scope
Medium-sized entities in covered sectors generally fall in scope, and some entities are covered regardless of size. For those clients, the consequences are concrete. Under Article 34, Member States must set maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher.
Article 20 adds a governance layer. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Members of management bodies are also required to follow training.
Indirect scope through the supply chain
Article 21(2)(d) requires in-scope entities to address supply chain security, including their relationships with direct suppliers and service providers. In practice, a 20-person engineering firm that supplies a hospital or a utility will be asked to prove its own controls, even though it is not regulated itself.
In practice: ask every client for the last three security questionnaires they received. The recurring questions show which NIS2 controls their customers care about.
Are MSPs themselves in scope of NIS2?
Yes, in most cases. Annex I of NIS2 lists managed service providers and managed security service providers under ICT service management (business-to-business), so a medium-sized or larger MSP usually has its own obligations.
Article 6 defines a managed service provider as an entity that installs, manages, operates or maintains ICT products, networks, infrastructure or applications for customers, on site or remotely. A managed security service provider is an MSP that carries out or assists with cybersecurity risk management. The directive also gives MSPs specific treatment:
- Jurisdiction: under Article 26, MSPs fall under the Member State of their main establishment in the Union, usually where cybersecurity risk-management decisions are predominantly taken.
- Registration: under Article 27, MSPs had to submit their name, sector, addresses, contact details, Member States served and IP ranges to the competent authority by 17 January 2025, and must report changes within three months.
- Technical requirements: the Commission adopted an implementing regulation on 17 October 2024 that sets detailed technical and methodological requirements for providers including MSPs and MSSPs.
Clients will ask how you secure your own remote management tools and privileged access, so get your own house in order first.
How do you scope a client for NIS2?
Start with three questions: which sector and subsector does the client operate in, how big is it, and in which Member States does it provide services? The answers decide whether it is in scope and which national law applies.
Use this simple decision tree at the first meeting:
- Is the client’s main activity listed in Annex I or Annex II of NIS2? If no, go to step 4.
- Is it medium-sized or larger? Under the EU SME definition, medium-sized generally means 50 or more staff, or annual turnover and balance sheet above EUR 10 million. If yes, it is likely an important or essential entity. If no, check whether a size-independent rule or national designation applies.
- Which national law applies? Identify the Member States where it is established and provides services, then check the relevant national transposition and registration process.
- Does it supply an in-scope entity? If yes, it needs a supply chain readiness offer even if NIS2 does not apply directly.
Common mistake: relying only on the directive. Transposition has been uneven. In May 2025 the Commission sent reasoned opinions to 19 Member States for failing to fully transpose NIS2, and on 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice, asking for financial penalties. Deadlines and registration portals therefore differ by country. Our NIS2 transposition tracker by Member State shows where each country stands.
How should MSPs package NIS2 services for SMEs?
Package NIS2 as three tiers: a fixed-scope readiness project, a recurring managed compliance service and a premium vCISO retainer. SMEs buy outcomes they can explain to their board, not article numbers.
| Tier | Typical buyer | What is included | Commercial model |
|---|---|---|---|
| 1. NIS2 readiness | Any SME unsure of its position | Scoping, national law check, registration support, gap assessment against Article 21, prioritised roadmap | Fixed-fee project |
| 2. Managed NIS2 compliance | In-scope important entities and key suppliers | Policy set, risk register, supplier assessments, incident playbook, quarterly evidence review, board report | Monthly retainer |
| 3. vCISO for NIS2 | Essential entities or clients with complex supply chains | Named vCISO, management training, incident reporting support, audit and inspection preparation, cross-framework alignment with ISO 27001 or DORA | Monthly retainer with defined hours |
| Add-on: supplier readiness | Out-of-scope SMEs in a regulated supply chain | Questionnaire answers, core policies, evidence pack aligned to customer requests | Fixed fee or small retainer |
Keep your statement of work explicit: you design, operate and evidence; the client’s management body decides, signs off and remains accountable.
If you want to run all four tiers from one console, with every client in its own workspace, you can book a partner demo and see how Enactia for MSPs handles multi-client NIS2 delivery.
Which Article 21 measures map to which deliverables?
Each of the ten minimum measures in Article 21(2) should map to at least one named deliverable and one piece of evidence.
| Article 21(2) measure | MSP deliverable | Evidence to keep |
|---|---|---|
| (a) Risk analysis and information system security policies | Risk assessment and information security policy | Approved policy, risk register |
| (b) Incident handling | Incident response plan and playbooks | Tested plan, incident log |
| (c) Business continuity, backup and crisis management | Backup, recovery and continuity plan | Restore test results |
| (d) Supply chain security | Supplier inventory and assessments | Completed assessments, contract clauses |
| (e) Secure acquisition, development and maintenance, including vulnerability handling | Patch and vulnerability management | Scan reports, patch records |
| (f) Assessing effectiveness of measures | Quarterly control review | Review reports, KPIs |
| (g) Cyber hygiene and training | Awareness programme and management training | Attendance records |
| (h) Cryptography and encryption | Encryption standard | Configuration evidence |
| (i) HR security, access control and asset management | Joiner, mover, leaver process and asset register | Access reviews, asset list |
| (j) Multi-factor authentication and secured communications | MFA rollout and secure communications setup | MFA coverage report |
For practical control detail, ENISA published technical implementation guidance in June 2025 to support the implementing regulation.
Much of this overlaps with ISO 27001. If a client already has an ISMS, map existing controls first rather than rebuilding. A cross-framework control mapping approach lets you reuse the same evidence for NIS2, ISO 27001 and customer questionnaires.
How do you deliver incident reporting under NIS2?
Agree in advance who detects, who decides and who notifies. Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month.
A 24-hour clock only works if the process is written and rehearsed. Your service should include:
- A severity matrix that helps the client decide whether an incident is significant.
- Pre-drafted early warning and notification templates for the relevant national CSIRT or authority.
- A link to GDPR breach handling, because many cyber incidents also involve personal data and trigger a separate 72-hour notification to the data protection authority.
Tools that combine both workflows help. Incident and data breach management with timers for each deadline keeps the NIS2 and GDPR clocks visible side by side.
How do you run supplier and risk management at scale?
Standardise. Use one risk methodology, one supplier questionnaire and one reporting format across all clients, then tailor the risk appetite and thresholds per client.
- Risk register: keep each client’s risks, owners and treatment plans in a structured risk management workspace rather than spreadsheets.
- Supplier assessments: send the same core questionnaire, map answers to Article 21, and track remediation. A vendor and third-party risk management module makes this repeatable.
- Policies: maintain a master policy set, then publish client-branded versions with version control through policy management.
Common mistake: selling a “NIS2 certificate”. NIS2 itself does not create a single EU-wide certificate for organisations. Some national frameworks use conformity schemes, but you should describe your output as evidence of alignment, not certification, unless an accredited scheme applies.
Is NIS2 about to change?
Possibly, but not yet. On 20 January 2026 the Commission proposed targeted amendments to NIS2 aimed at simplifying compliance and refining scope, as noted on its NIS2 policy page. At the time of writing the proposal is still being negotiated by the European Parliament and the Council, so current national obligations apply unchanged.
Key takeaways
- NIS2 reaches SMEs directly if they are medium-sized or larger in a covered sector, and indirectly through supply chain duties.
- Most MSPs are in scope themselves, so secure your own operations first.
- Package NIS2 as readiness, managed compliance and vCISO tiers, plus a supplier readiness add-on.
- Map each of the ten Article 21 measures to a deliverable and evidence.
- Always check the national law, because transposition and registration differ by country.
Frequently asked questions
Do small businesses need to comply with NIS2?
Most small and micro businesses are not directly in scope, because NIS2 generally applies to medium-sized and large entities in covered sectors. Some entity types are covered regardless of size, and Member States can designate others. Small firms can still be asked to prove their security by customers who are in scope, so supply chain readiness is often worth doing.
Is my MSP an essential or important entity under NIS2?
Managed service providers are listed in Annex I of NIS2. Large MSPs are generally essential entities and medium-sized MSPs are generally important entities, although national law and designations can change this. Check the transposition law in the Member State where your main establishment is, because that state has jurisdiction over you.
What should a NIS2 readiness assessment include?
It should confirm scope and the applicable national law, review the client against each of the ten Article 21 measures, check governance and management training, test incident reporting readiness against the 24-hour, 72-hour and one-month deadlines, and finish with a prioritised, costed roadmap the management body can approve.
Can an MSP submit NIS2 incident reports for a client?
An MSP can prepare and often submit reports on the client’s behalf if national rules and the contract allow it, but the legal obligation stays with the client. Agree the authority to notify in writing, name the decision makers, and keep evidence of when the client became aware of the incident.
How is NIS2 different from ISO 27001?
NIS2 is law with fines, management liability and incident reporting deadlines. ISO 27001 is a voluntary, certifiable standard for an information security management system. The controls overlap heavily, so an ISO 27001 programme is a strong foundation, but it does not cover NIS2 registration or reporting duties by itself.
Turning NIS2 into a repeatable service
NIS2 gives MSPs a clear reason to move from reactive support to structured, recurring compliance services. Scope carefully, package in tiers, map every deliverable to Article 21 and keep evidence in one place. Enactia, the GRC platform for vCISO and vDPO services, lets partners deliver this across many clients from a single white-label console.
To discuss your NIS2 service line, contact us or book a partner demo.
This article is for general information and is not legal advice.
