← All posts
Compliance ·2026-07-16 ·9 min read

NIS2 for MSPs: what the directive means for your clients (and how to prove it)

The EU's NIS2 Directive (2022/2555) is now transposed into national law across the union — in the Netherlands as the Cyberbeveiligingswet. For MSPs it is the single biggest compliance conversation of the year, because two things are true at once: many of your clients are newly in scope, and you as their IT provider are often part of their supply chain.

Who is actually in scope?

NIS2 covers "essential" and "important" entities above the size threshold (roughly 50+ staff or €10M+ turnover) across 18 sectors — energy, transport, health, digital infrastructure, manufacturing, food, waste, and more. Crucially, it also reaches managed service providers and managed security service providers directly. If you run other organisations' IT, you are in scope regardless of your own size in several member states.

What Article 21 requires

Article 21(2) lists the risk-management measures every in-scope entity must have. In practice these map to controls you already recommend:

  • Risk analysis and information-system security policies
  • Incident handling and business continuity / backup
  • Supply-chain security
  • Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Policies to assess the effectiveness of measures
  • Basic cyber hygiene and training
  • Cryptography and encryption
  • Access control, asset management, and multi-factor authentication

The directive is deliberately outcome-based — it does not hand you a checklist of registry keys. That is the gap MSPs have to bridge: turning "appropriate technical measures" into concrete, evidenced controls you can show a regulator or an auditor.

The hard part: evidence

Regulators and cyber-insurers increasingly ask the same question — "show me." Saying you enforce MFA and disk encryption is not enough; you need per-device evidence that the control is actually applied, and a trend that shows it staying applied.

This is exactly where a posture assessment earns its keep. When every check on every endpoint is mapped back to a NIS2 Article 21 sub-measure, a scan stops being a list of technical findings and becomes a compliance artifact: "these 42 devices, 96% coverage of the access-control measures, here are the three gaps and their owners."

How Argus helps

Argus maps every automated check to CIS Controls v8, NIST CSF 2.0, ISO 27001:2022 and NIS2 Article 21 sub-measures. You get a per-client coverage percentage per framework, a drill-down to the specific failing controls and the devices behind them, and a branded PDF you can hand to the client, their auditor, or their insurer. Re-scan next month and the trend line proves the measures are holding.

That turns NIS2 from a threat into a service line: a recurring, evidence-backed compliance report your clients will pay for because they genuinely need it.

See your own clients' security posture in minutes.

Request a trial →