NIS2 and the Cyberbeveiligingswet
NIS2 for MSPs: showing access management at your clients
With the Cyberbeveiligingswet, the Dutch implementation of NIS2, the directive reaches an MSP in two ways: as an obligation of your own, and through your clients' questionnaires. Access management is in both. This is how you deliver the answer per client, without piecing it together again every time.
The short answer
NIS2 affects MSPs twice. Managed service providers are named in the directive themselves, as a sector under ICT service management, and depending on their size they may fall under the Cyberbeveiligingswet. And clients covered by the law have to assess their supply chain, which includes their IT partner. Access management is one of the topics that comes up. With Joinly you deliver it per client: an audit log of every change and an access review that puts the access someone has next to the access that belongs to their role.
Two ways NIS2 reaches you
The NIS2 directive names managed service providers explicitly, in Annex I under "ICT service management (business-to-business)". The Cyberbeveiligingswet is the Dutch implementation of the directive and is in force. Whether your MSP falls under it mainly depends on the size of your organisation.
Even if you do not fall under it yourself, you will notice it. Organisations that do fall under the law have to have the security of their supply chain in order, under Article 21. Their IT partner is one of the first suppliers they assess, and that happens through questionnaires and contract terms.
What your clients will ask
Article 21(2) mentions, among other things, human resources security, access control policies and asset management. In a supplier questionnaire that becomes very concrete. How are client environments kept apart? How are access rights managed? How do you know an employee who leaves can no longer get into anything? And can you show it?
For most MSPs the answer is currently spread across tickets, scripts and the memory of a few engineers. That is hard to explain to an auditor, and it costs time again with every questionnaire.
Access management per client, with the evidence to go with it
With Joinly, your client's HR system is the source for who has an account. Joiners, movers and leavers run automatically, and every change goes into that client's audit log: who, what, when and why, and whether it came from HR, a workflow, an administrator or the API.
With the access review you put, per client, the access someone has next to the access that belongs to their role. Where the two differ, you see it straight away. Segregation of duties stops anyone getting rights that should not go together. That report per client is your answer to the questionnaire, and the evidence your client needs for their own audit.

Joinly as a link in your own chain
Using Joinly adds a supplier to your own chain, so you are right to ask us the same question. Joinly is ISO 27001 certified, the data is stored in Amsterdam within the EU, and you can request the documents that go with a supplier assessment through the Trust Centre.
For your own organisation, Joinly works the same way as at your clients. Anyone who leaves your company loses their access on their last day.
NIS2 and the Cyberbeveiligingswet
Frequently asked questions
Does my MSP fall under the Cyberbeveiligingswet?
Managed service providers are listed as a sector in the NIS2 directive. Whether you fall under it mainly depends on the size of your organisation. Have that checked for your own situation; the Dutch government and the NCSC publish the criteria.
What do clients under NIS2 ask of their IT supplier?
Clients have to assess the security of their supply chain. In practice they ask how client environments are kept apart, how access rights are managed, how quickly access is revoked after someone leaves and whether you can show it.
What is supply chain responsibility under NIS2?
Organisations covered by NIS2 are also responsible for the risks that come in through their suppliers. They have to assess those suppliers and agree security terms with them. An IT partner with admin access is one of the most important links in that chain.
What is an access review?
An access review puts the access someone actually has next to the access that belongs to their role. Differences come to the surface, so you can correct them or account for them. In Joinly you do this per client.
How do I know a former employee at my client can no longer get into anything?
Joinly closes the account, sessions and licence on the end date recorded in HR, and records that in the client's audit log. That log is your evidence.
Is Joinly itself ISO 27001 certified?
Yes. The data is stored in Amsterdam, within the EU. You will find the certificate and the other documents for a supplier assessment through the Trust Centre.
- Joinly for MSPsFor an MSP, every joiner and leaver at a client is a ticket, a checklist and work that is hard to bill for. Joinly picks up those changes from your client's HR system and handles accounts, groups, licences and access automatically. For all your clients, from one login, with each client in its own environment.
- Onboarding and offboardingAn onboarding checklist per client and an offboarding ticket that arrives too late: for most MSPs, that is the work that comes back most often. With Joinly it starts as soon as your client records an employee in HR, and it follows the whole lifecycle.
- Account management as a serviceFor many MSPs, account management is work that disappears into the contract: it has to be done, it takes time and nobody sees it. With Joinly it becomes a service with a clear outcome and a price that moves with your client.
- Multi-tenant identity managementYou probably have tenant management sorted already. What most MSPs do not do from one place is keep track of who should have an account at each client. That is where Joinly sits alongside your existing tooling.
Account management for your clients as a standard service?
In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.
Book an introduction