NIS2 checklist for IT service providers
NIS2 is the EU directive that widened the set of organisations required to manage cyber risk and report incidents. For IT service providers it matters twice over: many are in scope directly, and almost all are pulled in indirectly through their customers' supply chain obligations.
Published August 7, 2026
This article is for information only and is not legal advice. NIS2 is implemented in national law by each EU member state, and what applies to you depends on your sector, your size and the country you operate in. Check your obligations with qualified legal counsel before relying on any of this.
What NIS2 actually is
NIS2 is Directive (EU) 2022/2555, which replaced the original NIS directive. It sets a baseline of cyber risk management measures and incident reporting duties for organisations in defined sectors, and it substantially widened both the list of sectors and the size of organisations covered.
A directive is not directly binding on companies. Each member state transposes it into national law, which means the details — the exact thresholds, the reporting channel, the supervisory authority, the penalties — depend on the country you operate in. The transposition deadline for member states was 17 October 2024, and the pace of national implementation has varied.
Two things are worth internalising. First, the obligations are about process, not products: the directive asks you to manage risk, not to buy a particular category of software. Second, management bodies are explicitly responsible for approving and overseeing the measures, which moves this off the IT team's desk alone.
Who is in scope
The directive distinguishes essential entities from important entities. Both must meet the same core security requirements; the difference is mainly in how supervision works — essential entities face proactive supervision, important entities largely reactive.
Scope is a function of sector and size together. The sectors are listed in the directive's annexes and include energy, transport, banking, health, water, public administration, digital infrastructure and ICT service management. Size thresholds generally bring in medium-sized organisations and above, with some sectors covered regardless of size.
Managed service providers and managed security service providers are named in the sector lists, which is a change from the previous regime. If you run other organisations' IT, you should assume you need to check your position properly rather than assume you are too small to be noticed.
The supply chain effect
Even where a provider is not directly in scope, NIS2 reaches them commercially. In-scope organisations must address supply chain security, including the security of their direct suppliers and service providers. Their most privileged supplier is usually whoever administers their endpoints.
In practice this arrives as a questionnaire, a contractual clause or an audit request. Customers start asking how you control access to their systems, how quickly you patch, what you log, and how fast you would tell them about an incident. Being able to answer with evidence rather than assurances becomes a commercial advantage well before it becomes a legal obligation.
That is the useful framing for a service provider: prepare because your customers will ask, not only because a regulator might.
A twelve-point checklist
These map to the risk management measures the directive sets out. It is a starting structure for a conversation with counsel and with your customers, not a compliance certificate.
- 1
Maintain a complete asset inventory
You cannot secure what you do not know about. Hardware, operating systems, installed software and owner, kept current automatically rather than in a spreadsheet that ages.
Where RMM tooling helps: This is core RMM function. Agents report inventory continuously, which turns the asset register into a live view instead of an annual exercise.
- 2
Patch and vulnerability management
A defined process for learning about vulnerabilities, deciding, deploying and verifying — with timescales that differ by severity, and evidence that they were met.
Where RMM tooling helps: Central approval queues, deployment rings and per-device verification. Severity-based SLA tracking turns "we patch regularly" into a number you can show.
- 3
Access control and multi-factor authentication
Least privilege for administrative accounts, MFA on anything that can reach customer systems, and a documented joiner-mover-leaver process.
Where RMM tooling helps: Role-based permissions in the console, SSO against your identity provider and enforced two-factor authentication for operators.
- 4
Monitoring and alerting
Detect abnormal states and act on them, with alerting that a human actually reads and a defined path from alert to owner.
Where RMM tooling helps: Sensors across utilisation, services, event logs and reachability, with notification channels into the tools your team already watches.
- 5
Logging and an audit trail
Know who did what and when, on both the endpoints and the management tooling itself, with retention long enough to reconstruct an incident.
Where RMM tooling helps: An append-only audit log of console actions with actor, object, timestamp and IP address, plus configurable retention.
- 6
Incident handling and reporting
A written procedure with roles, and awareness of the reporting clock: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month under the directive's scheme.
Where RMM tooling helps: Alerting and audit data shorten detection and reconstruction. The process, the decision and the notification itself remain human work.
- 7
Backup, recovery and business continuity
Backups that exist, are offline or immutable where it matters, and — the part usually skipped — restores that have actually been tested.
Where RMM tooling helps: An RMM is not a backup product and does not hold your data. It can monitor that backup jobs ran and alert when they did not, which is a genuine but partial contribution.
- 8
Endpoint hardening
Reduce what can execute and what can be attached: application control, removable media policy, and disabling what you do not use.
Where RMM tooling helps: Executable allowlisting and USB device control enforced by policy, with deviations visible centrally.
- 9
Encryption and secure communication
Encryption in transit and at rest where appropriate, and a policy that says which data falls into which category.
Where RMM tooling helps: Encrypted agent-to-server communication and code-signed agents so what you deploy is verifiably what you built.
- 10
Supplier and supply chain security
Assess the security of your own suppliers, and be ready to answer the same questions from customers. Contractual clauses about notification and access belong here.
Where RMM tooling helps: Indirect: an auditable toolchain and exportable evidence make you an easier supplier to assess.
- 11
Documentation and evidence
Policies written down, decisions recorded, and the ability to produce evidence on request. Undocumented good practice is invisible to an auditor.
Where RMM tooling helps: Reports and exports covering patch status, inventory and audit history, scheduled and delivered rather than assembled by hand.
- 12
Training, cyber hygiene and management accountability
Regular awareness training, and management bodies that approve the measures and understand them well enough to oversee them. The directive puts this responsibility explicitly on management.
Where RMM tooling helps: None. This one is organisational and no tool substitutes for it.
What tooling can and cannot do
No software makes an organisation NIS2-compliant, and any vendor who tells you otherwise is selling something. Compliance is a state of your organisation — its processes, its documentation, its governance — assessed against national law.
What good tooling does is make several of the required measures cheap enough to actually sustain, and make the evidence a by-product of doing the work rather than a separate project. Inventory, patch status and audit history are the clearest examples: they are hard to maintain by hand and straightforward to produce automatically.
The honest division of labour is that tooling covers the technical measures and produces evidence; you own the process, the decisions and the reporting. Start with the checklist above, work out which points you cannot currently evidence, and fix those first.