Essential entity with proactive BSI supervision
Annex I means the highest sanction tier and active BSI supervision. Cyber incidents in MSP infrastructure can hit thousands of customers simultaneously, hence the strict classification.
Annex I of the German NIS-2 implementation act covers Managed Service Providers and MSSPs as essential entities. From 250 employees or 50 million euros revenue, the obligations apply directly. Additionally NIS-2 requirements come from customer contracts, because customers classify you as a critical supplier. The Cybervize platform covers your own ISMS plus a multi-tenant platform for your customers.
Book the NIS-2 risk check
Managed service providers (MSPs), MSSPs and IT service providers typically fall under NIS-2 Annex I as providers of managed services once they exceed the size thresholds — and via the supply-chain clause are additionally exposed indirectly through their NIS-2-obligated clients. Four consequences of this classification for MSPs and IT firms. Sector alone is not enough: classification as managed service provider, MSSP or digital infrastructure provider follows from the concrete activity per NIS2UmsuCG plus size thresholds. The legally binding evaluation remains a matter for specialised counsel.
Annex I means the highest sanction tier and active BSI supervision. Cyber incidents in MSP infrastructure can hit thousands of customers simultaneously, hence the strict classification.
IT service providers must meet their own cybersecurity obligations AND prove to customers that they support those customers' NIS-2 obligations. Customer security questionnaires become routine.
MSPs manage several customers on shared infrastructure. NIS-2 requires strict data isolation, cross-sector risk assessment and consolidated incident reporting.
Every NIS-2-affected customer must include you in their risk analysis. Assessments, contractual requirements and audit rights become standard. Whoever delivers evidence fast wins mandates.
Five NIS-2 minimum measures per §30, translated into MSP practice.
Risk register evaluating customer tenants separately but consolidated. Concentration risks with cloud providers, sub-suppliers and third-party software documented.
Sub-supplier inventory (e.g. cloud providers, tooling vendors, specialists), contractual requirements, concentration-risk heatmap. Customers demand this transparency in security questionnaires anyway.
MFA and just-in-time access for admin accounts in customer environments. Privileged access management as hygiene. Particularly critical in multi-tenancy.
Incident response plan with three layers: own infrastructure, individual customer tenants, sector-wide incidents with domino effect. BSI report plus customer notification with documented escalation thresholds.
BCM plans with customer SLA as input. RTO commitments must be backed by BCM tests. Restart sequence on multi-tenant incident documented.
The Cybervize platform covers ISMS, BCM, TPRM and assessment in one solution. For MSPs, multi-tenancy and co-branding options additionally allow you to pass the platform on to customers.
Free 30-minute initial call with an indicative NIS-2 classification, top-5 gaps and a path recommendation.
Learn more Service 02ISMS, compliance and evidence from a single platform. Multi-entity, multi-country, AI-supported.
Learn more Service 03Platform plus permanent CISO function. For organisations without an in-house CISO.
Learn more Service 04Gap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreSelf-check available
Free, no signup, around 5 minutes. Detailed evaluation by email if desired.
Industry experience in IT services and MSSP structures from 25 years of ISMS practice at PwC, Deloitte and KPMG. The Cybervize platform is built multi-tenant, with strict data isolation and co-branding options. Partner sales is a dedicated line.
Free risk check with indicative NIS-2 classification, own and customer supply-chain requirements, path recommendation. Ideally with CISO or compliance plus management board present.
Book the NIS-2 risk checkThe ten regulated sectors the Cybervize platform runs in.
Learn moreStructured NIS-2 compliance: gap assessment, roadmap, and implementation in 12 weeks.
Learn moreFree self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
70% of SMEs treat NIS2 as a compliance checkbox. But organizations that see it as a strategic lever can turn regulatory requirements into operational excellence and genuine resilience.