
Compliance framing
NIS2 MSP ICT Supply Chain
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
European Union NIS2 managed-service supply-chain evidence for MSP script orchestration subprocessors.
European Union NIS2 programs evaluate ICT supply-chain subprocessors with transparency and security measures-Trustholm supplies vendor evidence; NIS2 outcomes remain entity and MSP program responsibilities.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
The NIS2 Directive strengthens cybersecurity risk management for essential and important entities across the European Union, and explicitly brings managed service providers and managed security service providers into scope when they provide ICT services to in-scope customers.
MSPs serving EU regulated clients may introduce Trustholm as an ICT supply-chain subprocess for signed script orchestration and audit export. Trustholm does not claim NIS2 certification, conformity assessment outcomes, or national transposition badges for the product.
NIS2 and national implementing laws expect in-scope entities to manage ICT supply-chain risk. Buyers typically require: subprocessors list at /trust/subprocessors, architecture overview, security questionnaire pre-fill, incident notification assumptions, and honest gap disclosure (WORM audit immutability backlog, native SIEM connector backlog).
Trustholm publishes Shipped/Gap evidence tables on the trust hub for vendor diligence files.
Technical measures that support Article-style security-of-networks narratives in customer assessments include schema-per-tenant isolation, JWT tenant binding for portal users, MFA options, signed PowerShell policy before execution, and exportable security audit trails separate from HTTP request logs.
Organisational measures-personnel access reviews, vulnerability management on customer endpoints, incident response execution-remain MSP and end-customer obligations.
NIS2 reporting obligations apply to in-scope entities under national law. Trustholm documents support escalation and notification terms in enterprise contracts; MSPs map those terms into customer IR playbooks and supervisory notification chains. Marketing pages cannot substitute for contractual incident schedules.
Include Trustholm vendor evidence when your customer or your own NIS2 program evaluates ICT subprocessors. Clarify complement positioning: many MSPs retain US RMM tools for patch and monitoring while using Trustholm for governed script execution evidence-reducing single-vendor dependency for privileged automation audit.
Pair this page with GDPR processor framing, DORA ICT risk content where financial clients apply, and /resources/digital-sovereignty-eu-msp-saas for residency questions. Trial evaluations should export audit evidence and capture IAM configuration within the first week.
Limitations: NIS2 outcomes depend on entity classification, member-state transposition, contract tier, and supervisory expectations-marketing pages cannot certify your compliance program.
Procurement tip: Attach EU vendor pack from /trust/downloads and subprocessors list before legal review cycles begin. Request enterprise DPA drafts via security@trustholm.com.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| Supply-chain security transparency | Subprocessors list, architecture overview, honest Shipped/Gap tables | Shipped | - |
| Privileged access and execution integrity | Portal MFA/RBAC, signed script policy, security audit export | Shipped | - |
| Incident notification terms | Enterprise contract schedules; support escalation documented at onboarding | Partial | - |
| NIS2 certification badge | Not claimed-entity and MSP program own NIS2 outcomes | Gap | - |
No. We supply ICT supply-chain vendor evidence-subprocessors, architecture, audit export, signing policy-not product-level NIS2 certification badges.
Managed service providers can be in scope when serving essential or important entities. Confirm classification with legal counsel; this page frames vendor evidence only.
Subprocessors list, architecture overview, security questionnaire pre-fill, EU vendor pack, and honest Shipped/Gap tables at /trust/downloads.
Complement positioning: retain incumbent RMM for patch/monitoring; use Trustholm for governed script execution and exportable audit-reducing privileged-automation dependency on a single US vendor.
Yes-security audit export provides attributable privileged-action records. Pair with your SIEM and IR procedures; native Sentinel connector remains backlog.
See /resources/digital-sovereignty-eu-msp-saas and EU vendor pack. Exact residency for your contract is confirmed during enterprise onboarding.