NIS2
NIS2 for managed service providers: the dual role
Under NIS2, MSPs carry a dual obligation: as a rule they are regulated themselves, and at the same time they bear responsibility within their clients' supply chain. Anyone selling cybersecurity as a service must first be able to demonstrate it in-house.
Why NIS2 is a dual role for MSPs
NIS2 affects managed service providers on two levels at once. That makes the situation more demanding than for an ordinary company, but it also opens up a clear market position.
- Direct scope. MSPs and MSSPs are generally regarded as “important entities” and must meet the NIS2 obligations for their own operations — risk management, technical measures, reporting obligations, management liability.
- Responsibility in the supply chain. As soon as an MSP serves clients subject to NIS2, it becomes part of their supply chain. Those clients are obliged to assess the security of their suppliers and to secure it contractually.
In short: anyone selling security as a service must first be able to evidence it in-house.
Level 1: the MSP as a regulated entity
As an entity within scope, the MSP must implement the core obligations. These include documented risk management, technical and organisational measures in line with the state of the art, functioning patch and vulnerability management, and established reporting and response processes.
What matters is verifiability: it is not enough for patches to be applied — the status must be demonstrable at any time. This is exactly where the RMM becomes the central system of evidence.
Level 2: the MSP as part of the client’s supply chain
NIS2 explicitly extends responsibility into the supply chain. A client subject to NIS2 must assess its service providers, bind them contractually and keep track of their security posture. For the MSP, that means:
- Audit readiness. Asset, patch and risk evidence must be deliverable per client on request.
- Contractual hardening. Security requirements, reporting channels and response times become part of the contracts.
- Inherited cloud risk. If the MSP uses a US-operated RMM, every managed client shares in its jurisdictional exposure.
The MSP thus becomes an audited link in a chain — and a weak link endangers the clients’ compliance too.
Why the RMM becomes the pivotal point
The RMM is the tool with the deepest reach into every managed estate: it inventories assets, distributes patches, executes scripts and documents incidents. For an MSP, it is therefore both the largest attack surface and the most important system of evidence.
From this follows a simple requirement: the RMM must generate the right evidence on a per-tenant basis — and it must not itself fall under foreign jurisdiction.
OneLog for the MSP subject to NIS2
As a sovereign RMM designed for NIS2 requirements, OneLog is built precisely for this dual role:
- EU-sovereign. Operated in the STACKIT Sovereign Cloud, headquartered in Germany, no US cloud exposure — the supply chain risk is not passed on to clients.
- Per-tenant evidence. Asset inventory, patch status and risk documentation can be generated per client, mapped to the NIS2 obligations, instead of being compiled manually for each audit.
- Autonomous remediation. Defined incidents are resolved end-to-end by AI agents — keeping patch and response status robust across many tenants.
- Certified operation. ISO 27001:2022, TOMs under Art. 32 GDPR published — the foundation for meeting both your own obligations and your clients’ supplier assessments.
OneLog is being trialled in an ongoing proof of concept at a KRITIS (German critical infrastructure) hospital under real operating conditions. For MSPs, that means an RMM that meets their own NIS2 obligations while serving their clients’ audit requirements — from a single sovereign source.
Frequently asked questions
- Are MSPs themselves affected by NIS2?
- As a rule, yes. Managed service providers and managed security service providers usually fall within scope as “important entities”, provided the thresholds are met. The final classification depends on the business model and on national implementation.
- What does the supply chain obligation mean for an MSP?
- Clients subject to NIS2 must assess the security of their suppliers and secure it contractually. The MSP thereby becomes an audited part of the supply chain and must be able to deliver asset, patch and risk evidence on request.
- Why does the RMM's data location matter for an MSP?
- The RMM has deep access to every managed client estate. If this control layer sits under US jurisdiction, the CLOUD Act exposure is passed on to every client. An EU-sovereign RMM closes this gap for the entire supply chain.
- Can an MSP automate NIS2 evidence?
- Yes. Asset inventory, patch status and incident documentation can be generated from the RMM on a per-tenant basis instead of being compiled manually for each client. That substantially reduces the effort per audit.
See OneLog in your environment
Monitors and maintains your IT remotely and fixes many incidents automatically — hosted in the EU, with no dependency on US cloud providers. NIS2 requirements are built in from the start.