NIS2 / KSC · ICT service providers · MSP · MSSP

NIS2 for ICT service providers and managed services.
Documentation is only the beginning.


Managed service providers (MSPs) and managed security service providers (MSSPs) are listed in the Polish KSC Act under the ICT service management sector. If you manage your clients’ systems, infrastructure or security, you need to put in order your own risk, access to client environments, incidents, service continuity and subcontractors.
The KSC/NIS2 deadlines are already running: registration, implementing risk management measures and preparing for the audit require action, not just documentation.
BCMLogic Next lets you maintain these areas in a single GRC system – with owners, deadlines, change history and the evidence you need for the audit.

What is changing
NIS2/KSC for ICT service providers: three things to put in order
NIS2 covers a wider group of ICT service companies and changes how cybersecurity is managed: self-assessment, management accountability and system, process and supplier risk become part of a single process.

Change 1
You classify yourself – and you register yourself
Not every IT company is automatically an MSP or MSSP. What matters is your actual service model: whether you continuously manage the installation, administration, operation or maintenance of a client’s products, networks, infrastructure or applications – or provide managed security services.
⚠ Registration within 6 months

Change 2
Management is accountable, not the IT department
Management approves risk management measures and is personally accountable for them. For a service provider, this is above all about access decisions: privileged accounts, RMM, remote administration and security tools can grant broad access to client environments. You need to know who has access, to what, on what basis and how quickly it can be revoked.
✓ Personal liability

Change 3
The scope is the whole organisation: IT, client services and suppliers
ICT service providers themselves depend on cloud, RMM, ticketing systems, EDR/XDR, software vendors and subcontractors. A failure or breach at any one of them can affect many clients at once.
✓ IT + services + supply chain
Scale of liability

Fines are only one dimension of NIS2 risk.

EUR 10 million
or 2% of annual turnover, whichever is higher. Maximum fine for an essential entity.
300%
of remuneration – personal fine for the head of the entity.
24 h / 72 h
early warning and full notification of a significant incident. Final report – within one month.

A fine does not require an incident. Penalties may also result from failing to meet obligations relating to registration, risk management, reporting or audit. Details in the FAQ.

Map of obligations
Five areas you need to maintain and be able to demonstrate
Audits and inspections quickly come down to specifics: who approved the risk, when the plan was tested, which actions are open, how the supplier was assessed and where the change history is.
1
Classification and registration
Self-identification, entry in the KSC register and keeping data and contact persons up to date.
2
Risk management and security measures
Risk assessment of IT systems and services delivered, security measures, business continuity and regular reviews.
3
Supply chain
Assessment of ICT suppliers and subcontractors and control of security requirements and third-party access.
4
Incident handling
Incident classification, meeting the required reporting deadlines and documenting decisions, communication and post-incident actions.
5
Management oversight, training and audit
Management oversight, training, security audit, and planning and monitoring of corrective actions.

Timeline
Deadlines counted from the Act’s entry into force
3 Apr 2026
The KSC Act implementing NIS2 enters into force. All further deadlines are counted from this date.
3 Oct 2026
+6 months
Registration in the KSC register (S46 system) and appointment of a cybersecurity contact person. The nearest deadline for most ICT service companies.
3 Apr 2027
+12 months
Full implementation of the information security management system and statutory measures – including documentation and approval by the management board.
3 Apr 2028
+24 months
First security audit for essential entities – then at regular intervals. From this point on, fines become a real prospect.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, plan testing, supplier assessments, board and staff training.

Legal basis: Directive (EU) 2022/2555 (NIS2) and the Polish Act on the National Cybersecurity System (KSC). Annex I to the KSC Act covers the “ICT service management” sector, including managed service providers (MSPs) and managed security service providers (MSSPs). Specific classification depends on the services actually provided and the rules in Article 5 of the KSC Act.
Sector specifics
One incident at a provider can affect many clients at once
In managed services, a single administration tool or privileged account can connect the provider to many client environments. An incident, compromised access or a failure of a key platform can therefore have a cascading effect.
Managed IT
Managed Service Provider (MSP)
Ongoing administration, operation and maintenance of a client’s networks, infrastructure, applications or workstations – on site or remotely.
Managed Security
Managed Security Service Provider (MSSP)
Security monitoring, SOC, EDR/XDR management, incident response and vulnerability management for clients. A compromise of the provider hits the protection layer itself.
Administration
Remote management of client environments
RMM, remote desktop and privileged accounts give access to many environments at once – one of the most frequently exploited supply chain attack vectors.
Cloud operations
Cloud and infrastructure management
Cloud environments and management platforms can be a shared dependency for many clients, so their availability, redundancy and contingency plans must be considered.
IT outsourcing
Ongoing ICT support and maintenance
Help desk, system maintenance and support delivered on a continuous basis. The client’s dependence on service availability translates directly into business continuity requirements.
MSP supply chain
Tool vendors and subcontractors
Managed services depend heavily on platform, tool and integration vendors and on subcontractors – hence the focus on supply chain oversight.
What this means in practice: risk assessments and continuity plans must cover your own infrastructure as well as administration tools, access to client environments and dependencies on suppliers and subcontractors. More details in the FAQ.
BCMLogic Next for ICT service providers
A GRC system for ICT service providers, MSPs and MSSPs
BCMLogic Next connects risks, services, BIA, incidents, suppliers, actions and deadlines. Security, compliance, service management and service owners all work on one up-to-date dependency model.

🔄
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
We can migrate your existing documentation into the system or start with wizards that guide users step by step.
⚠️
System and service risk assessment
Risk assessment for services delivered, administration tools, infrastructure and access to client environments – with owners, actions and change history.
Step-by-step wizard
📋
Policies and procedures
Templates, approval workflows, version history and audit trail.
Ready-made templates
🔄
Business continuity plans
BIA, BCP and DRP for critical services – e.g. unavailability of RMM, SOC, cloud, the ticketing system or a key supplier – with tests and exercise history.
RMM, SOC and cloud failure scenarios
🚨
Incident management
Incident handling with 24 h / 72 h deadlines, classification and a clear course of action.
24 h / 72 h timer
🏭
Suppliers and supply chain
Register and risk assessment of cloud, software vendors, RMM/PSA tools, subcontractors and other suppliers that affect the services you deliver.
Supplier and subcontractor register
✅
Audit readiness
Compliance status, approval and review history, and reports that support audit preparation.
Report for the auditor
Note for the largest entities – the CER Directive:
Some ICT service organisations may also be subject to critical entity resilience requirements. The scope should be verified separately; details are in the FAQ.
Online demo
Want to see how it works in practice?
Explore BCMLogic Next with demo data or book a 30-minute meeting and walk through a managed service provider (MSP) or managed security service provider (MSSP) scenario with us.
🖥

Online demo environment
Ready-made demo data: risks, incidents, business continuity and NIS2 compliance.
📞

A short meeting with our team
30 minutes for a system walkthrough and questions about your organisation and where you are in your NIS2 preparations.

Request demo access or book a 30-minute meeting →

FAQ · NIS2 and GRC for ICT service providers

Frequently asked questions about NIS2/KSC for MSPs, MSSPs and ICT service providers

A brief guide to classification, ISMS, service continuity, suppliers and audit preparation.
Is my IT company an MSP or MSSP under the KSC Act?
Not every IT company is automatically an MSP or MSSP under the KSC Act. You need to check the actual scope of services provided, how the client environment is managed and the classification rules in Article 5 of the KSC Act.
What should an MSP/MSSP risk assessment include?
The risk assessment should cover your own infrastructure and tools (RMM, PSA, SOC, EDR/XDR), privileged accounts and access to client environments, dependencies on cloud, software vendors and subcontractors, and the impact of an incident that could affect many clients at once.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
We have ISO 27001 or an ISMS. Do we need to build everything from scratch?
No. Existing materials can be migrated to the platform by your team, BCMLogic or a partner. The goal is not to recreate documentation, but to keep risks, plans, actions and evidence in a single GRC system.
Does BCMLogic Next replace a NIS2 consultant or integrator?
It does not have to. BCMLogic Next can act as the platform that maintains the results of a project delivered by an external consultant or integrator. It lets you keep working with risks, documentation, suppliers, incidents and tasks after the implementation ends.
How does BCMLogic Next support audit preparation?
The platform keeps a history of changes, approvals, reviews, tests and actions. As a result, the information needed for an audit does not have to be gathered from multiple spreadsheets, documents and systems every time.
How should privileged access to client environments be managed?
Keep a register of access to client environments: who has access, to which systems, on what basis and through which tools. Multi-factor authentication, least privilege, periodic reviews and the ability to revoke access quickly are key. In BCMLogic Next these risks can be linked to actions, owners and review dates.
Can an ICT service provider also be subject to the CER Directive?
Some ICT service companies may also be subject to critical entity resilience rules. Their status needs to be verified separately. BCMLogic Next can be used to manage requirements and evidence for multiple regulations in one environment.
How should a managed services provider approach business continuity?
First, identify critical services and their dependencies: network, systems, locations, staff and suppliers. BCMLogic Next links BIA, risks and continuity plans, so a change in infrastructure or at a supplier is also reflected in plans and the risk assessment.
How should MSP/MSSP subcontractors and technology suppliers be managed?
Start with suppliers whose failure or breach could affect the service: hardware, software and cloud vendors, data centres, maintenance providers and subcontractors with privileged access. A GRC system lets you maintain risk assessments, requirements, actions and review dates together with service dependencies.

Next step
See how a GRC system for ICT service providers works
Explore the platform online or book a short demo based on services, risks and dependencies typical of an MSP or MSSP.