6 October 2026 · 10 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
Managed Security for NIS2: Which Article 21 Measures an MSSP or MDR Actually Covers
NIS2 makes management personally accountable for cybersecurity risk management and sets a 24-hour early-warning clock on significant incidents. Most essential and important entities cannot meet that without outsourced monitoring and response. This guide maps the service to the articles, and says what the contract must contain.
What NIS2 asks for that most organisations cannot staff
Directive (EU) 2022/2555, implemented in the Netherlands through the Cyberbeveiligingswet (Cbw), requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risk (Article 21), to report significant incidents on fixed clocks (Article 23), and it makes management bodies responsible for approving and overseeing those measures. Three of the Article 21 measures assume continuous capability: incident handling, business continuity, and monitoring the effectiveness of measures. A 24-hour early warning assumes somebody notices the incident within hours, at night, on a weekend.
For organisations without a security operations team, that capability is bought. The question is which service covers which obligation, and how to make the provider's duties enforceable so that your management body can demonstrate oversight.
Article 21(2) measures mapped to managed services
What an MSSP, MDR provider or SOC as a service typically operates per measure, and what stays with you.
| Article 21(2) measure | What a managed service covers | What stays with you |
|---|---|---|
| (a) Risk analysis and information-system security policies | Input: vulnerability data, incident statistics, exposure reports | The analysis, the policies, management approval |
| (b) Incident handling | Detection, triage, investigation, containment (MDR) or escalation (MSSP/SOC), evidence preservation | Decision authority, notification to authorities, communication |
| (c) Business continuity, backup, crisis management | Backup monitoring, recovery support, crisis-room participation | Plans, exercises, ownership |
| (d) Supply-chain security | Monitoring of supplier connections; the provider is itself a supplier under this measure | Supplier assessments, contracts including the provider's own |
| (e) Secure acquisition, development, vulnerability handling | Vulnerability scanning and management, patch verification, coordinated disclosure handling | Secure development, change control |
| (f) Policies to assess effectiveness of measures | Monitoring metrics, detection coverage reports, support for penetration tests and red team exercises | Independent testing programme, review cycle |
| (g) Basic cyber hygiene and training | Phishing simulation and awareness programmes where contracted | Policy, enforcement |
| (h) Cryptography policies | Certificate and key monitoring where in scope | Policy and implementation |
| (i) HR security, access control, asset management | Identity monitoring, privileged access alerting, asset discovery | Joiner/mover/leaver process, access decisions |
| (j) MFA, secured communications | MFA enforcement monitoring, anomalous sign-in detection | Rollout and exceptions |
Article 23: the reporting clocks a provider must support
NIS2 sets three deadlines for significant incidents. The provider does not report for you, but the contract must guarantee that you can.
24 hours: early warning
Within 24 hours of becoming aware of a significant incident, the entity submits an early warning indicating whether the incident is suspected to be unlawful or malicious and whether it could have cross-border impact. The provider must therefore detect, triage and escalate to a named person on your side fast enough to leave time for the decision. A detection SLA measured in hours, not days.
72 hours: incident notification
A notification with an initial assessment of severity, impact and indicators of compromise. The provider must deliver the facts: what happened, which systems, which indicators, what has been contained. Put the delivery time in the contract.
One month: final report
A detailed description, the root cause, the mitigation applied and any cross-border impact. The provider's incident report, evidence retention and post-incident analysis feed this. Agree the format up front.
Who is 'aware'
The clock starts when the entity becomes aware. Define in the contract when the provider's awareness becomes yours, and make sure escalation reaches a person with authority, not a shared mailbox.
What the managed security contract must contain for NIS2
Beyond the general contract checklist, these items make the service usable as NIS2 evidence.
- A mapping of the service to the Article 21(2) measures it operates, with the rest explicitly left with you
- Detection and escalation times that leave room for the 24-hour early warning, with a named escalation contact on your side
- Incident facts delivered within a committed time to support the 72-hour notification, in a format you can forward
- Evidence retention and a post-incident report that supports the one-month final report
- Provider assurance: its own ISO 27001 or SOC 2 report, because the provider is a supplier under measure (d)
- Reporting that your management body can review quarterly, since NIS2 holds management accountable for oversight
- Cooperation with independent testing (penetration tests, red team) to evidence measure (f)
- Data location and access, because sector supervisors may ask where logs and evidence are held
Essential versus important entities, and what it changes
Essential entities face proactive supervision and higher fines (up to EUR 10 million or 2 percent of global turnover); important entities face reactive supervision and up to EUR 7 million or 1.4 percent. The Article 21 measures are the same for both. In practice essential entities are expected to show more mature monitoring and faster containment, which usually means MDR with committed response rather than notification-only monitoring, and a tested incident process that includes the provider.
Whichever category you are in, the Dutch supervisors will look at evidence: that monitoring exists, that incidents were handled and reported on time, and that management reviewed the results. A managed service produces most of that evidence if the contract says it must.
How HackersHub delivers NIS2-aligned managed security
Our managed security and MDR programmes are scoped against Article 21 from the start: the proposal states which measures we operate and which stay with you, the detection and escalation times are set to fit the 24-hour early warning, and incident reports are written so they can be forwarded for the 72-hour and one-month filings. Quarterly reports are built for a management body, not a SOC analyst. And because we test environments for a living, the programme includes the independent testing evidence measure (f) expects.
Frequently asked questions
In scope for NIS2 and short on 24/7 capability?
We map the Article 21 measures to a programme, set the clocks to fit Article 23, and report in a form your management body can sign off. Talk to an expert.