NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
HomeIndustriesIT Service Providers & MSPs

NIS2 for IT Service Providers and MSPs

Written by the NIS2Compass Team · Last updated: April 2026

MSPs, managed services providers and IT consultancies are directly NIS2-obliged per §28 (6) BSIG from 50 employees, and simultaneously act as suppliers in their customers' §30 No. 4 audits. Dual evidence duty, two angles, one platform: NIS2Compass delivers the own implementation and the subject knowledge for customer questions.

  • Structured NIS2 implementation path for your own organisation
  • Supplier templates for customer audits and questionnaires
  • 40+ expert articles as argumentation base with customers
  • No new compliance officer needed (€100k+/year)
Try Pro · €29/monthBlog: Am I affected by NIS2?
Hosted in Germany·GDPR-compliant·cancellable monthly

Are you as an IT service provider affected by NIS2?

Sector

Annex 1, "Digital Infrastructure and ICT Service Management (B2B)". MSPs, MSSPs and managed services providers are explicitly named.

Size

50+ employees or > €10M annual revenue. All essential entities fall under §30 BSIG.

Supply-chain special case

Even below 50 employees, you can land in customer audits as a supplier (§30 No. 4 BSIG). Customers demand evidence, contracts add NIS2 clauses.

Detailed assessment in the blog: „Am I affected by NIS2?"

Typical NIS2 challenges for MSPs and IT service providers

Multi-tenant liability

You are liable with your own §30 duty AND are an audit object for your customers. Two evidence duties at the same time.

Customer questionnaire wave

OEMs, corporates and NIS2-obliged customers send assessments. You must respond within days, without your own process.

Incident notification grey area

§32 BSIG on customer infrastructure: does the MSP or the customer report? Without contractual clarity, duplicate or missing notifications.

How NIS2Compass helps IT service providers

An MSP with 80 employees has two tasks at the same time: their own NIS2 implementation and answering customer questions. NIS2Compass covers both from one platform. The NIS2 Guide structures 124 implementation steps for the own organisation. The supplier templates (security policy, inventory, vendor assessment questionnaire) serve internally as evidence and can be used mirrored as response templates for customers. The Knowledge Hub delivers the subject-matter argumentation, for internal training as well as customer meetings.

NIS2 Guide

8 chapters, 124 substeps: the own obligation

Supplier templates

Inventory, assessment, contract clauses

40+ expert articles

Argumentation base for customer conversations

Which §30 BSIG obligations apply to IT service providers?

§30 No. 4

Supply chain security

MSPs are affected from two perspectives: as a customer of cloud and software vendors, you must assess your own suppliers. As a supplier for your customers, you must in turn provide evidence.

§30 No. 1

Risk analysis and security concept

Particularly tricky for MSPs: your own risk analysis must include customer environments, since incidents there may fall back on the MSP.

§30 No. 7

Personnel, awareness, training

MSPs often have high turnover and privileged access in customer systems. Onboarding and offboarding processes are the number one test subject in customer audits.

More in the blog: NIS2 and ISMS tools, NIS2 explained simply for IT managers, NIS2: getting started quickly and correctly.

NIS2Compass in comparison for IT service providers

Comparison NIS2Compass vs. classic consulting, ISMS tool and self-implementation for IT service providers
KriteriumNIS2CompassKlassische BeratungISMS-ToolSelbstumsetzung
Monthly cost€29€700-1,200/day€200-2,000/month€0
NIS2 expertise built-inyesyespartialno
German templatesyes (45+)tailored (expensive)mostly Englishno
Suitable for customer projectsyeslicensing per projectinternal use only-
Onboarding10 minutesdays to weekshours + setupmonths
Flexibility on customer requestshighslowrigidfull workload

Frequently asked questions on NIS2 for MSPs

Ready for NIS2 as an IT service provider?

Your own compliance and customer requests from a single platform.

Try Pro · €29/monthBlog: Am I affected by NIS2?
cancellable monthly·no setup fee·Hosted in Germany

Official sources

  • §28 BSIG in full text (German)
  • §30 BSIG in full text (German)
  • BSI guide on NIS2 regulation (German)
  • BSIG Annex 1 (German)