Short answer
Annex I lists ICT service management (business-to-business), including managed service providers and managed security service providers. Article 6 defines a as an entity providing services related to installation, management, operation, or maintenance of ICT products, networks, infrastructure, applications, or other network and information systems through assistance or active administration on customer premises or remotely. A is an MSP that performs or assists with cybersecurity risk-management activities.
The sector entry is only the first step. Article 2 generally covers an Annex I provider that qualifies as medium-sized under Recommendation 2003/361/EC or exceeds the medium-enterprise ceilings and has the required Union activity. Article 3(1)(a) generally makes an Annex I provider above those ceilings essential. A covered medium-sized MSP or MSSP that does not meet an essential-entity limb is important under Article 3(2). Small providers need a separate Article 2(2) special-case and national-law check before being treated as outside scope.
- Start with the legal entity, not the brand name or product line.
- Confirm the activity involves assistance or active administration of the customer's ICT environment or cybersecurity risk management, not only resale, staffing, or delivery of a product.
- Check whether the service is provided or carried out within the Union.
- Apply the size-cap and any Article 2 special-case rule before deciding the entity is outside NIS2.
- Classify the result as essential, important, outside current scope, or escalated for Member State legal review.
Are managed service providers in scope of the EU NIS2 Directive?
They can be. NIS2 Annex I includes business-to-business managed service providers and managed security service providers. Verify the Article 6 service definition, the Article 2 medium-or-larger size test or a size-independent special case, the Union activity, and the Article 3 tier. A provider above the medium-enterprise ceilings is generally essential; a covered medium-sized provider is generally important unless another essential-entity rule applies.
Article 6 defines managed service provider and managed security service provider, Article 2 supplies the size and special-case scope rule, and Annex I lists MSPs and MSSPs under ICT service management.
NIS2 Article 2 points to this Recommendation for the medium-sized enterprise size test used in the general scope rule.
Commission FAQ context confirms NIS2 replaced the old OES/DSP split with essential and important entity categories and lists ICT service management among high-criticality sectors.