SDX Studio
Back to blog

NIS2 Enforcement Got Real. What That Means for MSSP Pipeline

Seifeldin Sabry·August 25, 2026·6 min read

For three years NIS2 was mostly a slide in a webinar. In 2026 it became something a buyer can be fined over, and that changes how useful it is as a go-to-market signal.

Two developments are worth an MSSP's attention.

Transposition is close to complete, and the stragglers are in court

By mid-2026, the large majority of member states had fully transposed the directive into national law. ECSO's transposition tracker is the reference worth bookmarking, because the picture keeps moving.

More significantly, on 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify complete transposition, requesting financial sanctions in the form of a lump sum plus daily penalties.

Whatever you think of the pace, that's the Commission demonstrating it will litigate over this directive. Member states treating the deadline as advisory now have a reason not to.

The first fines have landed

Enforcement has started at national level, with early penalties reported in several member states, Italy, Belgium, Hungary and Lithuania among them, in amounts ranging from tens of thousands to several hundred thousand euros.

The headline ceilings are what they always were: up to €10 million or 2% of global annual turnover for essential entities, up to €7 million or 1.4% for important entities. Management bodies have to approve and oversee the cybersecurity measures, and can be held personally liable, with national law able to bar individuals from management roles in serious cases.

The early fines are small next to those ceilings. That isn't the point. The point is that the number stopped being hypothetical, and that's exactly the moment a board stops deferring a decision.

Why this creates buyers you can reach

Regulation produces something outbound is unusually good at exploiting: a dated obligation held by an identifiable set of companies.

Three groups become reachable.

In-scope entities without the internal capability. Essential and important entities across energy, transport, health, digital infrastructure, public administration, waste, food, manufacturing and more. Plenty of them are mid-sized with no security team worth the name.

Suppliers to in-scope entities. This is the larger and less contested pool. NIS2 requires in-scope organisations to manage supply chain security, including the practices of their direct suppliers and service providers. An SME supplying IT services, software, components or logistics to a regulated entity inherits those requirements contractually, even though it isn't itself designated. It's being asked for evidence by its customer, not by a regulator.

Companies whose management just discovered personal liability. The individual-accountability provisions have a way of accelerating decisions that sat at budget level for a year.

The second group is where the volume is, and it's also where the messaging is safest, which brings me to the part that matters more than any of the above.

Don't make the classic mistake

The fastest way for an MSSP to lose credibility with a regulated buyer is to tell them they're in scope when they aren't.

Scope determination under NIS2 is genuinely fiddly. It depends on sector, on size thresholds, on national transposition choices that differ between member states, and on designations some regulators make individually. You won't resolve it from the outside with a firmographic filter, and a prospect who forwards your email to their general counsel and gets told it's wrong won't take the meeting.

So don't assert scope. Ask about position.

Not: you are an essential entity under NIS2 and must comply by [date].

Closer to: most suppliers to [sector] we speak to are being asked to evidence incident response and monitoring at contract renewal, whether or not they're directly in scope themselves. Where has that landed with you?

The second version can't be wrong, is true of the market, and invites the reader to tell you their situation instead of correcting yours.

A note for non-EU readers

If you sell into the UK or the US, the specific directive isn't your lever, but the mechanism is identical. Cyber insurance underwriting has become a de facto regulator. Enforced MFA across email, VPN, RDP and admin accounts is effectively universal, managed detection and response has moved toward a baseline expectation rather than a differentiator, and carriers increasingly want exported evidence rather than a checked box on a self-attestation form.

Same structure, different issuing authority. Somebody external has told your prospect to act by a date. Find those companies, reach them while the letter is still on the desk, and be accurate about what it says.

Turn this into pipeline.

Reading about demand doesn’t book meetings. A 45-minute call gets you an honest read on whether 6 qualified meetings is realistic in your market, and a written scope if it is.

Book a no-pressure call

Miss 6 qualified, attended meetings in 60 days and billing stops while we keep working.

  • MSSP Demand Is Outrunning MSSP Pipelines

    Managed security is one of the fastest-growing lines in IT services, and most MSSPs still grow by referral. The gap between those two facts is the whole opportunity, and it's closing.

    Market · 7 min read
  • Build an MSSP Offer a CFO Cannot Ignore

    Most MSSP offers are a list of capabilities and a monthly price. That asks the buyer to do the arithmetic, and buyers who have to do arithmetic do nothing. Here's how to build an offer that does it for them.

    GTM engineering · 9 min read
  • AI Changed the Attack. It Also Changed Your Sales Conversation.

    Generative tooling made targeted attacks cheap enough to run at volume, and put ungoverned AI inside your prospects' own networks. Both are commercial openings for an MSSP that can describe them precisely.

    AI · 7 min read