EU directive · NIS2

    From uncertainty to strategy.
    Your MSP's NIS2 roadmap starts here.

    NIS2 places MSPs and MSSPs in sectors of high criticality. The risk is not only regulatory, it is commercial. MSPs that help customers navigate NIS2 win business. Those that ignore it lose it.

    What is NIS2?

    NIS2 (Network and Information Security Directive 2) is an EU cybersecurity directive that entered into force in January 2023 and had to be transposed by member states by October 2024. Each country implements it through national law. It widens the range of organisations that must meet security and incident reporting requirements, and for the first time it explicitly names IT service providers (MSPs and MSSPs).

    • Medium-sized and large MSPs are directly in scope. Smaller MSPs are affected through their customers' requirements on suppliers.
    • Your customers' compliance may depend on YOUR compliance
    • Non-compliance means regulatory and financial risk, for both you and your customers
    • MSPs that offer NIS2-aligned services gain a significant competitive advantage

    What NIS2 requires

    This is what your customers need to understand and get help with, and where MSPs can offer services.

    Who is in scope

    Medium-sized and large organisations in 18 sectors, including energy, transport, water, health, digital infrastructure, manufacturing and IT services. Some organisations are in scope regardless of size.

    Registration

    Organisations in scope must register with their supervisory authority.

    Management accountability

    Management must approve and oversee risk management measures and take cybersecurity training.

    Incident reporting

    Significant incidents are reported in three steps: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.

    Penalties

    Up to EUR 10 million or 2% of global turnover for essential entities, and EUR 7 million or 1.4% for important entities.

    Strategic Collaboration

    Gridheart and MCF, together for stronger cybersecurity

    Gridheart works with the Swedish Civil Defence Agency (MCF, formerly MSB) and CERT-SE to strengthen MSPs' ability to meet NIS2 and raise the security level of Swedish small and medium-sized businesses.

    Purpose

    Strengthen MSPs' ability to meet the EU's NIS2 directive and raise SMBs' security posture.

    Training & Workshops

    Development of materials and seminars for increased knowledge and experience sharing between MSPs.

    New Security Services

    Sellable solutions that strengthen protection against ransomware and cyber threats - services MSPs can package and sell to their customers.

    Result

    MSPs become the first line of defence, strengthening Sweden's digital resilience. This collaboration positions Gridheart partners at the forefront of Nordic cybersecurity.

    NIS2 Guides & Resources

    Download our free resources to understand NIS2 requirements and start your compliance journey.

    NIS2 Report

    A comprehensive guide for MSPs covering NIS2 requirements, challenges, and a step-by-step implementation roadmap.

    Download PDF

    Article 21.2 Breakdown

    Summary of the ten risk management measures in NIS2 Article 21(2) (a-j), the core requirements your MSP must meet.

    Download PDF

    Security Assessment Tool

    A checklist-based tool built on the full version from MCF (formerly MSB), adapted for MSPs.

    Download PDF

    Incident Reporting Guide

    Practical guidance on reporting significant incidents under the Swedish Cybersecurity Act and NIS2: deadlines (24 hours, 72 hours, one month), what to report and a checklist for MSPs.

    Download PDF

    What Gridheart provides for NIS2

    Free NIS2 Compliance Guide

    A practical PDF guide covering what NIS2 means for MSPs, step-by-step compliance roadmap, and how to turn compliance into a sellable service.

    Free 1:1 Consultation

    A 30-minute session with a Gridheart NIS2 specialist to assess your current position and plan next steps.

    Case Study: From Uncertainty to Strategy

    How Gridheart helped a Swedish MSP navigate NIS2 requirements with practical tools and guidance.

    Read the case study →

    Does the customer have production or control systems?

    Many organisations in scope of NIS2 have OT environments with their own requirements.

    Read about OT security

    Frequently asked questions

    NIS2 is an EU cybersecurity directive that each country implements through national law. It sets requirements for risk management, management accountability and incident reporting for organisations in 18 sectors.

    Get your free NIS2 guide + a 30-minute consultation

    One of our colleagues with NIS2 expertise will get back to you shortly.