Skip to main content
NIS2

NIS2: a guide for IT service providers

Who NIS2 covers, what it concretely requires, the incident notification deadlines — and how an IT service provider turns all of it into an offer.

L'équipe Vigicap7 min read

The NIS2 directive changes the nature of the conversation between an IT service provider and its clients. Until now, security sold on the fear of an incident. From here on it sells on a legal obligation, with penalties expressed in figures and accountability that reaches all the way up to the company's leadership.

For a provider, that is a change of status: you are no longer the supplier of a firewall, you become the counterpart on a governance subject. This article goes through what the directive actually imposes, and what that opens up as a service opportunity.

What is the NIS2 directive?#

NIS2 is Directive (EU) 2022/2555 of 14 December 2022. It replaces the first NIS directive of 2016, judged too undemanding and too unevenly applied from one member state to the next.

Three major differences with NIS1:

  • The scope explodes. NIS1 targeted a few hundred operators per country. NIS2 covers eighteen sectors and reaches down to medium-sized companies.
  • Accountability becomes personal. Management bodies must approve the risk-management measures and can be held liable for failing to do so.
  • The supply chain enters the scope. The security of suppliers and service providers becomes an explicit obligation of the client — which concerns you directly.

The deadline for transposing the directive into national law was 17 October 2024. The precise arrangements, the thresholds for application and the compliance timetable are then a matter for each member state: that is the point to check against your own national source before making any contractual commitment.

Who is covered by NIS2?#

NIS2 crosses two criteria: sector of activity and company size.

The sectors. Annex I lists the sectors described as "highly critical": energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space.

Annex II adds the "critical" sectors: postal services, waste management, chemicals, food, manufacturing (medical devices, electronics, machinery, vehicles), digital providers, research.

The point many providers miss: "ICT service management (business-to-business)" is an Annex I sector. Managed service providers and managed security service providers are named in it explicitly. If you are an MSP above a certain size, you are not only your clients' adviser on NIS2 — you are potentially a regulated entity yourself.

Which size thresholds bring a company into NIS2?#

Two categories. Either criterion is enough: the headcount, or the turnover and balance sheet together.

CategoryHeadcountTurnover / balance sheet
Essential entity≥ 250 employeesOr turnover > €50M and balance sheet > €43M
Important entity≥ 50 employeesOr turnover > €10M and balance sheet > €10M

The distinction is not cosmetic: essential entities are subject to proactive supervision (checks without prior suspicion), important entities to reactive supervision (a check triggered by an indication of a failure).

Note that some entities fall under NIS2 whatever their size — in particular providers of public electronic communications networks, trust service providers, and entities whose failure would have a systemic impact.

What are the ten measures of Article 21?#

Article 21 requires "appropriate and proportionate technical, operational and organisational measures". It lists ten of them:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity — backups, disaster recovery, crisis management
  4. Supply chain security
  5. Security in acquisition, development and maintenance
  6. Policies to assess the effectiveness of the measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Cryptography and encryption policies
  9. Human resources security, access control, asset management
  10. Multi-factor authentication, secure communications, emergency communications

Not one of those ten lines is a technical surprise. The difficulty is not knowing what to do — it is proving that you do it, documented and dated. That is precisely where a service provider creates value.

What are the NIS2 incident notification deadlines?#

This is the most operational obligation, and the one that catches organisations out. Three deadlines run one after another once a significant incident becomes known: an early warning at 24 hours, an incident notification at 72 hours, a final report at one month.

StageDeadlineContent
Early warning24 hoursSuspicion of a malicious act, possible cross-border impact
Incident notification72 hoursSeverity assessment, indicators of compromise
Final report1 monthDetailed description, root cause, measures applied

Twenty-four hours means a ruined weekend if the process does not already exist. A client who discovers this obligation during the incident has already lost. A provider's value plays out here, beforehand: in having a channel, a notification template and a named owner.

What is company leadership accountable for under NIS2?#

Article 20 is the one to read out to the board, not to the IT department. Management bodies must approve the risk-management measures, oversee their implementation, and undergo regular training in cybersecurity.

That changes who you are talking to. The subject stops being arbitrated by the IT manager out of whatever budget is left over; it becomes an agenda item for the company's leadership, whose own liability is now engaged.

What penalties does NIS2 carry?#

For essential entities: up to €10M or 2% of worldwide turnover, whichever is higher.

For important entities: up to €7M or 1.4%, on the same logic.

Beyond the fine, authorities can suspend a certification or temporarily bar an individual from holding management functions. It is that last provision that usually moves the room.

What does NIS2 change for an IT service provider?#

Three things, and none of them is technical.

You are inside your clients' scope. Obligation 4 — supply chain security — means that your regulated clients have to assess their suppliers. You are a supplier. You are going to receive questionnaires, evidence requests, new contractual clauses.

There are two ways to take it: absorb a growing administrative burden, or turn it into a commercial argument. A provider able to answer in 48 hours with a structured file wins tenders against a competitor who takes three weeks.

Compliance becomes a recurring service. Compliance is not a project, it is a state to maintain. Measures have to be reassessed, incidents logged, evidence refreshed, training renewed. That describes a monthly subscription exactly, not a one-off engagement.

It is the most profitable transition available to a provider today: moving from unpredictable project revenue to recurring revenue backed by a legal obligation the client cannot trade away.

The diagnostic becomes the way in. You do not sell a compliance programme cold. You sell a measured gap. A diagnostic that produces a score, a prioritised list of gaps and a costing turns an abstract discussion into a quote.

That is the principle behind the 42 cyber hygiene measures published by ANSSI, France's national cybersecurity agency: a short, concrete framework that a company owner understands, and which covers most of what Article 21 expects.

Where do you start, concretely?#

  1. Qualify your portfolio. Sector, headcount and turnover for each client. In a day you will know who is an essential entity, who is important, and who is out of scope.
  2. Deal with your own case first. If you fall into the "ICT service management" sector, start with yourself. It is also your best commercial demonstration.
  3. Standardise the diagnostic. A reusable questionnaire, a score that compares from one client to the next, a report in your own branding.
  4. Industrialise the evidence. The obligation that costs the most is traceability. An evidence vault attached to each measure beats a shared folder.
  5. Write the incident procedure before the incident. The 24 hours are not negotiable.

If you are also preparing clients for certification, the logical next step is ISO 27001, whose Annex A overlaps heavily with Article 21.

TopicsNIS2complianceregulationMSP