The classic trap
Recital 86 targets a major blind spot: Managed Security Service Providers (MSSP) running your pentests, SOC, incident response or audits are themselves prime targets, and their privileged access makes them rare but devastating attack vectors (Kaseya, SolarWinds, CrowdStrike July 2024). The ILR expects essential and important entities to exercise increased diligence on these providers, beyond the standard article 21(2)(d) supply chain diligence. In short: an MSSP treated like any IT vendor becomes an aggravating factor in case of incident.
The diligence standard for an MSSP
Concretely, ILR and ENISA expect an assessment going beyond the classic vendor questionnaire. Must-have criteria:
- Opposable certifications: ISO 27001 covering the sold service scope (not the head office), recent SOC 2 Type II, ideally ENISA EUCS when available, PASSI for pentests.
- Technical segregation: named accounts with hardware MFA, dedicated bastion, client-side logging, secret rotation, documented least privilege.
- Transparency on their own posture: last pentest date on their own IS, disclosure policy for incidents affecting them, cyber insurance.
- Operations location: SOC operated from EU or adequate country, no subcontracting to high-risk jurisdictions without controls.
- Contractual clauses: incident notification within 24h to you (to allow your own 24h ILR notification), audit right, reversibility, exit plan.
- Subcontracting chain verification: who are THEIR critical sub-processors (cloud, EDR, threat intel) and their own NIS 2 compliance.
The Luxembourg-specific trap
The Luxembourg cyber market is highly concentrated: a few local MSSPs serve a significant share of the country's banks, funds and industries. This concentration creates a systemic risk recognised by ILR. Excessive concentration on a single MSSP becomes itself a risk to document in your article 21 analysis.
How Luxgap automates this risk
Our Luxgap MSSP Trust Radar turns the selection and continuous monitoring of your security providers into opposable evidence, aligned with the increased diligence standard of recital 86. The tool continuously aggregates public and contractual signals on each MSSP in your chain (certification status, public incident history via HIBP and ENISA bulletins, CERT alerts, contract expirations) and produces a dedicated risk score, separate from the generic vendor grid.
- Automatically collects ISO 27001 and SOC 2 certification scope of each MSSP via their trust portal and alerts if the service you purchase is not covered.
- Detects in real time any public mention of an incident affecting your MSSPs (CERT-EU, CISA, ENISA bulletins, OSINT) and triggers a risk review within 48h.
- Generates a concentration matrix visualising your group's actual dependency on each MSSP, weighted by service criticality, to document the systemic risk required by ILR.
- Pre-fills an increased diligence questionnaire aligned with ENISA and CSA STAR, with automatic scoring of answers and flagging of missing contractual clauses.
- Produces a timestamped PDF dossier per MSSP, opposable during an ILR inspection, demonstrating increased diligence under article 21 and recital 86.
- Monitors the declared subcontracting chain (SOC's cloud, EDR used, threat intel feeds) and alerts on NIS 2 coverage gaps.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a demonstration and our teams prepare a free 48h white audit of your current MSSP portfolio, with concentration scoring and identification of missing clauses before any engagement.