Written by the NIS2Compass Team ·
MSPs, managed services providers and IT consultancies are directly NIS2-obliged per §28 (6) BSIG from 50 employees, and simultaneously act as suppliers in their customers' §30 No. 4 audits. Dual evidence duty, two angles, one platform: NIS2Compass delivers the own implementation and the subject knowledge for customer questions.
Sector
Annex 1, "Digital Infrastructure and ICT Service Management (B2B)". MSPs, MSSPs and managed services providers are explicitly named.
Size
50+ employees or > €10M annual revenue. All essential entities fall under §30 BSIG.
Supply-chain special case
Even below 50 employees, you can land in customer audits as a supplier (§30 No. 4 BSIG). Customers demand evidence, contracts add NIS2 clauses.
You are liable with your own §30 duty AND are an audit object for your customers. Two evidence duties at the same time.
OEMs, corporates and NIS2-obliged customers send assessments. You must respond within days, without your own process.
§32 BSIG on customer infrastructure: does the MSP or the customer report? Without contractual clarity, duplicate or missing notifications.
An MSP with 80 employees has two tasks at the same time: their own NIS2 implementation and answering customer questions. NIS2Compass covers both from one platform. The NIS2 Guide structures 124 implementation steps for the own organisation. The supplier templates (security policy, inventory, vendor assessment questionnaire) serve internally as evidence and can be used mirrored as response templates for customers. The Knowledge Hub delivers the subject-matter argumentation, for internal training as well as customer meetings.
NIS2 Guide
8 chapters, 124 substeps: the own obligation
Supplier templates
Inventory, assessment, contract clauses
40+ expert articles
Argumentation base for customer conversations
MSPs are affected from two perspectives: as a customer of cloud and software vendors, you must assess your own suppliers. As a supplier for your customers, you must in turn provide evidence.
Particularly tricky for MSPs: your own risk analysis must include customer environments, since incidents there may fall back on the MSP.
MSPs often have high turnover and privileged access in customer systems. Onboarding and offboarding processes are the number one test subject in customer audits.
| Kriterium | NIS2Compass | Klassische Beratung | ISMS-Tool | Selbstumsetzung |
|---|---|---|---|---|
| Monthly cost | €29 | €700-1,200/day | €200-2,000/month | €0 |
| NIS2 expertise built-in | yes | yes | partial | no |
| German templates | yes (45+) | tailored (expensive) | mostly English | no |
| Suitable for customer projects | yes | licensing per project | internal use only | - |
| Onboarding | 10 minutes | days to weeks | hours + setup | months |
| Flexibility on customer requests | high | slow | rigid | full workload |
Your own compliance and customer requests from a single platform.