Skip to main content
Joinly by KoppelHet

NIS2 and the Cyberbeveiligingswet

NIS2 for MSPs: showing access management at your clients

With the Cyberbeveiligingswet, the Dutch implementation of NIS2, the directive reaches an MSP in two ways: as an obligation of your own, and through your clients' questionnaires. Access management is in both. This is how you deliver the answer per client, without piecing it together again every time.

The short answer

NIS2 affects MSPs twice. Managed service providers are named in the directive themselves, as a sector under ICT service management, and depending on their size they may fall under the Cyberbeveiligingswet. And clients covered by the law have to assess their supply chain, which includes their IT partner. Access management is one of the topics that comes up. With Joinly you deliver it per client: an audit log of every change and an access review that puts the access someone has next to the access that belongs to their role.

Two ways NIS2 reaches you

The NIS2 directive names managed service providers explicitly, in Annex I under "ICT service management (business-to-business)". The Cyberbeveiligingswet is the Dutch implementation of the directive and is in force. Whether your MSP falls under it mainly depends on the size of your organisation.

Even if you do not fall under it yourself, you will notice it. Organisations that do fall under the law have to have the security of their supply chain in order, under Article 21. Their IT partner is one of the first suppliers they assess, and that happens through questionnaires and contract terms.

What your clients will ask

Article 21(2) mentions, among other things, human resources security, access control policies and asset management. In a supplier questionnaire that becomes very concrete. How are client environments kept apart? How are access rights managed? How do you know an employee who leaves can no longer get into anything? And can you show it?

For most MSPs the answer is currently spread across tickets, scripts and the memory of a few engineers. That is hard to explain to an auditor, and it costs time again with every questionnaire.

Access management per client, with the evidence to go with it

With Joinly, your client's HR system is the source for who has an account. Joiners, movers and leavers run automatically, and every change goes into that client's audit log: who, what, when and why, and whether it came from HR, a workflow, an administrator or the API.

With the access review you put, per client, the access someone has next to the access that belongs to their role. Where the two differ, you see it straight away. Segregation of duties stops anyone getting rights that should not go together. That report per client is your answer to the questionnaire, and the evidence your client needs for their own audit.

De toegangsevaluatie in Joinly: feitelijke naast bedoelde toegang

Joinly as a link in your own chain

Using Joinly adds a supplier to your own chain, so you are right to ask us the same question. Joinly is ISO 27001 certified, the data is stored in Amsterdam within the EU, and you can request the documents that go with a supplier assessment through the Trust Centre.

For your own organisation, Joinly works the same way as at your clients. Anyone who leaves your company loses their access on their last day.

NIS2 and the Cyberbeveiligingswet

Frequently asked questions

  • Does my MSP fall under the Cyberbeveiligingswet?

    Managed service providers are listed as a sector in the NIS2 directive. Whether you fall under it mainly depends on the size of your organisation. Have that checked for your own situation; the Dutch government and the NCSC publish the criteria.

  • What do clients under NIS2 ask of their IT supplier?

    Clients have to assess the security of their supply chain. In practice they ask how client environments are kept apart, how access rights are managed, how quickly access is revoked after someone leaves and whether you can show it.

  • What is supply chain responsibility under NIS2?

    Organisations covered by NIS2 are also responsible for the risks that come in through their suppliers. They have to assess those suppliers and agree security terms with them. An IT partner with admin access is one of the most important links in that chain.

  • What is an access review?

    An access review puts the access someone actually has next to the access that belongs to their role. Differences come to the surface, so you can correct them or account for them. In Joinly you do this per client.

  • How do I know a former employee at my client can no longer get into anything?

    Joinly closes the account, sessions and licence on the end date recorded in HR, and records that in the client's audit log. That log is your evidence.

  • Is Joinly itself ISO 27001 certified?

    Yes. The data is stored in Amsterdam, within the EU. You will find the certificate and the other documents for a supplier assessment through the Trust Centre.

Account management for your clients as a standard service?

In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.

Book an introduction