Managed service providers spent the NIS1 years as suppliers to regulated entities. NIS2 changes that: MSPs and MSSPs are now listed by name in Annex I, among the sectors of high criticality, and are one of the eleven categories whose technical requirements the Commission spelled out in Implementing Regulation (EU) 2024/2690. This article sets out the exact wording, the size rule that decides who is in scope, what the implementing regulation adds at a high level, how obligations flow down to and from your clients, and what a provider should be able to prove.
Not legal advice
This is a security engineer's reading of the texts cited, not legal advice. Whether your company is an essential or important entity depends on your actual activity, your size and national identification; use ANSSI's self-assessment on messervices.cyber.gouv.fr/nis2 and consult counsel. Darkmoon does not certify compliance.
Annex I, point 9: the line that names you
Directive (EU) 2022/2555, Annex I "Sectors of high criticality", sector 9 "ICT service management (business-to-business)", lists two types of entity: "Managed service providers" and "Managed security service providers". Article 6 defines a managed service provider around the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or other network and information systems for customers, on the customer's premises or remotely, and a managed security service provider as a managed service provider whose services relate to cybersecurity risk management. In plain terms: if you run your clients' infrastructure, endpoints, identity or security operations for them, you are of a listed type.
Being of a listed type is necessary but not sufficient. Two more tests apply: size, and whether a Member State identifies you regardless of size.
The size rule, verbatim
Article 2(1): "This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union." The Recommendation's thresholds make this concrete.
- An entity of a listed type is in scope when it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover and balance-sheet total above €10 M.
- Essential entities are the large ones: 250 staff or more, or turnover above €50 M and balance sheet above €43 M (Article 3(1)(a)). A medium-sized MSP is an important entity (Article 3(2)).
- Article 2(1), second sentence, switches off Article 3(4) of the Recommendation's Annex: the usual exception for partner and linked enterprises does not apply, and group data may have to be consolidated.
- Size does not matter in the cases of Article 2(2): sole provider of an essential service in a Member State, significant impact on public safety, security or health, systemic or cross-border risk, specific national or regional importance. A small MSP that administers the IT of a region's hospitals can be identified on that basis.
Supervision differs with the category: essential entities face ex-ante and ex-post supervision, important entities ex-post supervision. Maximum fines are set by national law at least at €10 M or 2 % of worldwide turnover for essential entities and at least €7 M or 1.4 % for important ones (Commission FAQ). In France these amounts are not in force; see below.
What Implementing Regulation 2024/2690 adds
For eleven categories of digital entities, including managed service providers and managed security service providers, the Commission adopted Implementing Regulation (EU) 2024/2690 on 17 October 2024. It does two things. First, it lays down the technical and methodological requirements of the Article 21(2) measures for those entities, in an annex that follows the ten points of Article 21(2): a policy on the security of network and information systems and a risk-management framework; incident handling; business continuity and crisis management; supply-chain security; security in acquisition, development and maintenance, including vulnerability handling; policies and procedures to assess the effectiveness of the measures, including testing; cyber hygiene and training; cryptography; human-resources security, access control and asset management; multi-factor authentication and secured communications; and environmental and physical security. Second, it specifies when an incident is considered significant for each category, which triggers the Article 23 reporting timelines (early warning within 24 hours, notification within 72 hours, final report within one month).
Two points matter for an MSP reading the annex. The requirements are written as outcomes to be documented, reviewed at planned intervals and after significant incidents; a paper policy without evidence of review is the gap an authority will find first. And the effectiveness section expects the entity to decide how, how often and by whom its measures are tested, and to act on the results. The Regulation does not name a penetration test or a frequency. A validated test is one of the natural ways to produce that evidence.
Supply chain: obligations flow in both directions
Article 21(2)(d) requires every essential and important entity to address "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers". For an MSP this cuts twice.
- Downstream, to you. Your clients that are NIS2 entities (hospitals, utilities, banks via DORA, public administrations, manufacturers in Annex II) must assess you as a supplier. Expect questionnaires, contractual clauses, audit rights and requests for test evidence, whether or not you are in scope yourself.
- Upstream, from you. Your own suppliers, the RMM vendor, the backup platform, the PSA tool, the identity provider, the data centre, are your supply chain, and their security is your Article 21(2)(d) duty.
The concentration risk is real. CERT-FR cites, via CERT-Bund, the October 2023 Akira ransomware on an IT provider serving 72 German municipalities and 20,000 workstations, with 1.7 million inhabitants affected and recovery still incomplete months later (CERT-FR). ANSSI's 2025 panorama notes data exfiltrations that followed the compromise of a service provider (ANSSI). An MSP's privileged access is the attacker's shortest route to many victims at once.
What an MSP or MSSP should be able to prove
| Article 21(2) point | What it asks | What a penetration test can evidence |
|---|---|---|
| (d) supply chain | Security of relationships with suppliers and service providers | Tested exposure of the RMM, PSA, backup and identity tooling you depend on |
| (e) acquisition, development, maintenance | Vulnerability handling and disclosure | Confirmed vulnerabilities with evidence, tracked to remediation and retest |
| (f) effectiveness | Policies and procedures to assess the effectiveness of measures | Dated, reproducible test reports across the provider's own estate and tenant boundaries |
| (i) access control, asset management | Who reaches what, and what exists | Attack paths from a technician account to client tenants; an infrastructure graph of hosts and paths |
| (j) multi-factor authentication | MFA or continuous authentication where appropriate | Attempts against legacy protocols and consoles that bypass MFA |
The MSP-specific scope is the control plane: RMM and remote-support consoles, privileged credential vaults, the technician identity tenant, VPN and edge devices, ticketing and email, backup consoles, and the boundaries between client tenants. The question a test answers is whether one compromised technician account or one exposed console reaches more than one client. Darkmoon qualifies each finding as EXPLOITED, CONFIRMED or UNCONFIRMED with the evidence kept, maps the estate as a graph of hosts, paths and relationships, and in Pro produces CVSS 3.1, MITRE ATT&CK and ISO 27001 mappings with recurring campaigns, so the Article 21(2)(f) record is a series rather than a single date. The platform is self-hosted by default and its Privacy Gateway tokenizes client hostnames, IPs and credentials before anything reaches the model (see Inside the Privacy Gateway), which matters when the estate under test is your clients'.
French status as of 4 October 2026
France has not completed transposition. The bill "relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité" was adopted by the Sénat in first reading on 12 March 2025 and is scheduled for public session at the Assemblée nationale on 7 October 2026; the law is not promulgated (legislative file). ANSSI already offers pre-registration and an eligibility self-test on messervices.cyber.gouv.fr/nis2, and published the Référentiel Cyber France (ReCyF) on 17 March 2026 (ANSSI). ANSSI's director general has announced a progressive approach to sanctions over three years after transposition, with exceptions for registration and incident notification; that is an announced approach, not a legal text. Deadlines and fines in France are therefore not in force today. The practical reading for an MSP: register when the portal opens, map which of your clients are listed types, and start building the evidence base now, because your clients' supplier questions will not wait for the Journal officiel. Our NIS2 guide tracks the status.
Where to start
The MSP and MSSP page details the exposures, the surfaces and the tests for a provider, and the partner programme for firms that want to run Darkmoon across their client base, from one to a hundred machines per key. For a provider that wants its own estate tested first, with the legal framework, scoping and debrief handled by ASC-IT's experts, Pentest on Demand is a flat €799 per engagement, indicative and adjusted to the final scope.
See the proof, not just the write-up: the Pro remediation benchmark (fixes retested against the exploit) · how Darkmoon compares to other AI pentest tools.
← All articles