Cybervize
NIS-2 for IT service providers and MSPs

ICT service management is Annex I. Plus supply-chain pressure from customers.

Managed service providers and MSSPs are covered as providers of managed services, as are providers of cloud computing and data centre services. Company size decides how strict the obligations are. NIS-2 requirements also reach you through customer contracts, because customers classify you as a critical supplier. Our vCISO leads the implementation of the information security obligations for your own organisation and runs your ISMS in OdySecure, the security platform by Cybervize.

Book the NIS-2 risk check

NIS-2 classification: IT service providers

Classification
Annex 1 to the German BSIG ("Anlage 1"), digital infrastructure: MSPs (6.1.10), MSSPs (6.1.11), cloud computing services (6.1.4), data centre services (6.1.5)
Wichtige Einrichtung
from 50 employees, or annual turnover and annual balance sheet total each above €10M
Besonders wichtige Einrichtung
from 250 employees, or annual turnover above €50M and balance sheet total above €43M
Reporting deadlines
initial report 24 hours, follow-up 72 hours, final report one month
Obligations
10 minimum measures under § 30 BSIG
On top
NIS-2 requirements via customer contracts
Financial customers
contractual duties under Article 30 DORA; the carve-out in § 28 Abs. 6 Nr. 1 BSIG applies to your customer, not to you

Standard case under § 28 of the German BSIG. "Wichtige Einrichtung" is the standard tier, "besonders wichtige Einrichtung" the stricter tier; the figures are annual values. Calculating them in annual work units, attributing partner and linked enterprises, special cases and the final classification under German law all require a case-by-case legal review. MSPs and MSSPs sit in Annex 1 as providers of managed services and managed security services. The reporting deadlines require a significant incident (§ 32 BSIG).

Cybervize building blocks for IT service providers

Your vCISO works with OdySecure: ISMS, BCM, TPRM and assessment on one data foundation. For MSPs, multi-tenancy and your logo in the reports also let you pass the platform on to customers.

Self-check available

NIS-2 maturity check: 30 questions, 10 §30 BSIG measures, instant traffic light

Free, no signup, around 5 minutes. Detailed evaluation by email if desired.

Start the check
More about NIS-2 for IT service providers and MSPs

What NIS-2 means in practice for IT service providers

Through the supply-chain clause, managed service providers (MSPs), MSSPs and IT service providers are also exposed indirectly to the obligations of their NIS-2-regulated clients. Five consequences of this classification for MSPs and IT firms. Sector alone is not enough: classification as managed service provider, MSSP or digital infrastructure provider follows from the concrete activity under Annex 1 to the German BSIG plus size thresholds. The legally binding evaluation remains a matter for specialised counsel.

01

The stricter tier from 250 employees, with proactive BSI supervision

From 250 employees, or at annual turnover above €50M and annual balance sheet total above €43M, a "wichtige Einrichtung" becomes a "besonders wichtige Einrichtung" (the stricter tier): highest sanction level, active BSI supervision. Cyber incidents in MSP infrastructure can hit thousands of customers simultaneously, hence the sector’s strict classification.

02

Dual obligation: own ISMS plus customer evidence

IT service providers must meet their own cybersecurity obligations AND prove to customers that they support those customers' NIS-2 obligations. Customer security questionnaires become routine.

03

Multi-tenancy as a security requirement

MSPs manage several customers on shared infrastructure. NIS-2 requires strict data isolation, cross-sector risk assessment and consolidated incident reporting.

04

Supply-chain position makes you a supplier risk source

Every NIS-2-affected customer must include you in their risk analysis. Assessments, contractual requirements and audit rights become standard. Whoever delivers evidence fast wins mandates.

05

DORA at your customer does not cover your own classification

§ 28 Abs. 6 Nr. 1 BSIG (section 28(6) no. 1 of the German BSIG) exempts financial entities under Article 2(2) DORA from core BSIG duties. There, financial entities are points (a) to (t); ICT third-party service providers sit in point (u). Group IT companies, spun-off security operations centres and platform providers are therefore classified under § 28 BSIG in their own right, and carry the DORA requirements on top, via the customer contract. Where the customer is a financial entity, the contractual pressure comes from Article 30 DORA, not from the NIS-2 supply chain.

What applies to IT service providers, and what sits in the catalogue

Anyone operating services for others is audited twice: by their own regulator and by every customer. The evidence goes by different names and asks for the same things. In OdySecure it sits in one catalogue.

  • BSI C5:2026The German criteria catalogue for cloud services, audited to ISAE 3000.174 records, reference
  • ISO/IEC 27001The shared language of the management system.123 records, reference
  • NIS2 Implementing RegulationTechnical implementing rules for certain digital services.49 records, full catalogue
  • SOC 2Audit criteria for service providers, attestation rather than certification.44 records, reference
  • Cyber Resilience ActSecurity requirements for products with digital elements.44 records, full catalogue
  • ISO/IEC 27017Security controls specifically for cloud services.7 records, reference

The NIS2 Implementing Regulation applies directly to certain digital services, regardless of size thresholds. That classification is set out below.

Full catalogue with depth and type of assurance

Five minimum measures with IT service provider examples

Five NIS-2 minimum measures per §30, translated into MSP practice.

01

Risk analysis for multi-tenant environments

Risk register evaluating customer tenants separately but consolidated. Concentration risks with cloud providers, sub-suppliers and third-party software documented.

02

Security in your own supply chain

Sub-supplier inventory (e.g. cloud providers, tooling vendors, specialists), contractual requirements, concentration-risk heatmap. Customers demand this transparency in security questionnaires anyway.

03

Multi-factor authentication for privileged access

MFA and just-in-time access for admin accounts in customer environments. Privileged access management as hygiene. Particularly critical in multi-tenancy.

04

Multi-channel incident response

Incident response plan with three layers: own infrastructure, individual customer tenants, sector-wide incidents with domino effect. BSI report plus customer notification with documented escalation thresholds.

05

Business continuity with customer SLA reference

BCM plans with customer SLA as input. RTO commitments must be backed by BCM tests. Restart sequence on multi-tenant incident documented.

Why Cybervize fits IT service providers

OdySecure is built multi-tenant, with strict data isolation; your logo appears in the generated reports. Partner sales is a dedicated line.

Multi-tenant
strict data isolation per tenant
16 roles
RBAC with fine-grained permissions
Your logo
in the generated reports
Audit-ready
evidence towards BSI and customers

Frequently asked questions from IT service providers

No. Classification applies to the legal entity, not to the group. § 28 Abs. 6 Nr. 1 BSIG exempts financial entities under Article 2(2) DORA, which are points (a) to (t) there. DORA lists ICT third-party service providers separately in point (u). An IT company does not hold its parent’s supervisory status, so the carve-out does not reach it. Group membership does not help with the size thresholds either: § 28 Absatz 4 Satz 1 BSIG adds the figures of partner and linked enterprises. Sentence 2 drops that attribution only where you are independent of those enterprises in the design and operation of your information systems, which is a question of fact and has to be evidenced case by case.

With financial customers the contractual pressure does not come from the NIS-2 supply chain but from Article 30 DORA. Your customer has to anchor specific content in the contract: service description and locations of data processing, access and audit rights, termination and exit arrangements, rules on subcontracting, and participation in their resilience testing. They also keep a register of information on their ICT contractual arrangements, which your details feed into. That is a different axis from the supply chain clause in § 30 BSIG, and it does not replace your own NIS-2 duties.

Most likely yes. ICT service management (MSPs and MSSPs) falls under Annex I. From 50 employees, or when turnover and balance sheet total each exceed 10 million euros, you are usually an important entity. Essential entity follows from 250 employees, or annual turnover above 50 million euros and a balance sheet total above 43 million euros. The legally binding evaluation remains a matter for counsel. We provide the expert classification in the risk check.

NIS-2-affected customers must include you in their supply chain risk analysis. Expect: security questionnaires with similar depth to NIS-2 obligations, audit rights in contracts, incident reporting obligations, termination and exit clauses for critical outsourcing. Whoever delivers structured answers fast wins mandates.

Yes. OdySecure is built multi-tenant. You can resell as a partner, co-sell with Cybervize or offer it in co-branding. Strict data isolation per tenant, separate permissions, separate audit trail.

Incidents affecting multiple tenants need cross-sector assessment and parallel reporting obligations. A single cyber incident in MSP infrastructure can simultaneously trigger the BSI report under § 32 BSIG, notifications to every affected NIS-2 customer and possibly data-protection notifications. Structured incident response with documented escalation paths becomes mandatory.

NIS-2 gap assessment as a fixed price from 4,500 euros. Audit-ready in 8 to 14 weeks. Or a vCISO mandate from €3,600/month that fills the role. Partner models for simultaneous customer delivery are priced separately. The risk check gives you the exact cost estimate.

Classify NIS-2 for IT service providers in 30 minutes

Free risk check with indicative NIS-2 classification, own and customer supply-chain requirements, path recommendation. Ideally with CISO or compliance plus management board present.

Book the NIS-2 risk check

In scope? How you get to a provable security posture

If the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.

Book a vCISO callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT