Skip to content
CyberNIS2

Glossary

MSP / MSSP

Managed service providers (IT outsourcing) or managed security service providers (remote SOC), subject to NIS 2 from their very first employee due to their privileged access to client infrastructure.

MSPs (Managed Service Providers) and MSSPs (Managed Security Service Providers) are providers of managed IT services (full IT outsourcing) or managed security services (SOC monitoring, remote threat detection). Because of their privileged access to client infrastructure, NIS 2 treats them as a major source of systemic vulnerability and brings them into scope from their very first employee.

MSP vs. MSSP

MSPMSSP
Core activityFull IT outsourcing, IT maintenance, systems administrationManaged security: SOC, intrusion detection, incident response
ExamplesIT provider for SMEs, network outsourcingOutsourced SOC, 24/7 monitoring service

Why NIS 2 targets them as a priority

An MSP or MSSP often has administrator access to the systems of dozens or hundreds of clients at once. A successful attack against a single MSP can therefore compromise its entire client base in a cascade — a systemic risk demonstrated by the 2021 Kaseya VSA attack.

Key obligations

  • Mandatory registration with ANSSI.
  • Strengthened security measures on remote administration tools.
  • Incident notification within 24 hours if their systems are compromised or if client access is exposed.