The classic trap
Many essential and important entities believe they escape NIS 2 because they outsourced their IT to an MSP, a hosting provider or an integrator. Recital 83 closes that escape route: NIS 2 liability stays with the regulated entity, regardless of who technically operates the servers. The ILR sanctions the designated entity, not its provider, and requires proof that risk-management measures apply to the complete perimeter, including outsourced parts.
The 'real perimeter' test: what the ILR looks for during inspections
- Does the systems inventory include assets hosted at the MSP, in public cloud, and at technical subcontractors?
- Do the contractual clauses with the IT provider impose the same NIS 2 requirements (article 21) as those applicable to the entity?
- Does the provider deliver regular evidence (SOC 2 reports, scans, logs) that you can present to the ILR?
- Is the incident notification chain (article 23) contractualised so the MSP alerts you within a delay compatible with the 24h early warning?
- Does the cybersecurity RACI clearly distinguish what the provider does from what remains under your direct responsibility?
- Do you have an enforceable audit right on the provider, exercised at least annually?
The most frequent trap: an MSP contract signed 5 years ago vaguely mentioning 'security compliant with market standards', with no NIS 2 clause, no incident SLA, no audit right. Before the ILR, this is a clear fault of the entity, not the provider.
How Luxgap automates this risk
Our Luxgap Outsourced Perimeter Mapper eliminates the blind spot of outsourced IT by reconstructing, without declarative input, the totality of your real cyber perimeter, including what you have entrusted to your MSPs, hosting providers and integrators. The tool cross-references your supplier invoices in Odoo or SAP, your outbound DNS flows, your M365 and Azure tenants, your AWS accounts and your Defender logs to materialise the complete operating chain, and compares this perimeter against the NIS 2 clauses actually signed with each provider.
- Automatically detects each active IT provider via recurring payments, federated Azure AD access and outbound network flows toward third-party ASNs.
- Compares each MSP contract against the 10 measures of article 21 and lists missing clauses (24h notification, audit right, subcontracting chain, encryption, MFA).
- Continuously verifies the validity of ISO 27001, SOC 2 certifications and cyber attestations of each provider, with a 90-day expiry alert.
- Generates a pre-filled, legally enforceable NIS 2 addendum to be signed by non-compliant providers.
- Produces a timestamped, cryptographically sealed PDF report that demonstrates to the ILR that your outsourced perimeter is governed at the same level as your internal IS.
- Sends instant Teams or Slack alerts as soon as a new IT provider appears in your systems without a signed NIS 2 contract.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your perimeter. Request a personalised quote and our teams will prepare a demonstration on your real providers, with a free 48h white audit to measure the gap between your contractual perimeter and your real cyber perimeter.