When you hand a provider the keys to your infrastructure, you outsource the operations. You do not outsource the accountability. Regulators on both sides of the Channel have reached the same conclusion, and they are acting on it by regulating your providers directly.
In the EU, NIS2 lists ICT service management as a sector of high criticality, which puts managed service providers and managed security service providers under the directive by name (European Parliament and Council, 2022). In the UK, the Cyber Security and Resilience Bill, before the House of Lords at the time of writing, creates a relevant managed service provider category as drafted, and the government’s factsheet describes an RMSP as “a person who provides managed services in the UK (whether or not the person is established in the UK) and is not a small and micro enterprise” (Department for Science, Innovation and Technology, 2026). A provider’s registered office does not decide the question. If they manage systems for a UK customer, the Bill reaches them.
For a buyer, that is leverage. Your third-party risk process was built for a world where your providers were unregulated, and it can now be sharpened against duties your providers will owe a regulator. What should you be asking them?
Below are the seven questions we think belong in every supplier review, why each one matters to you, and what a substantive answer looks like. Sakura Sky operates managed services from United States and Netherlands entities, into the EU and, where customers ask, into the UK. That bracket in the UK definition is written for firms shaped like us, which is why we are answering these questions in public before they are put to us privately. For each question, we give you our own answer.
| # | Question | A substantive answer contains |
|---|---|---|
| 1 | Are you in scope, and can you show me the determination? | A dated, counsel-reviewed document |
| 2 | Who is your regulator and what is your local anchor? | A named authority and establishment or representative |
| 3 | If you are breached at 2am, what do I hear, and when? | A rehearsed pipeline with committed timings |
| 4 | What protects the systems you use to reach into my environment? | Controls mapped to published requirements |
| 5 | Can you show evidence, current, not just a certificate? | An evidence pack with a delivery SLA |
| 6 | What about your subcontractors? | A published list with flow-down terms, or an explicit none |
| 7 | Will you put your answers in the contract? | Yes, with stated limits |
1. Are you in scope, and can you show me the determination?
Why it matters: scope is the question everything else hangs off. A provider that has not worked out whether these regimes apply to it has not started on any of the duties that follow. The UK category as drafted covers ongoing management of IT systems, infrastructure, networks or applications with access into customer environments; software sold as a product is out, managed cloud operation is in, and it makes no difference whether access is on-premises or remote (Department for Science, Innovation and Technology, 2026). NIS2’s size cap captures medium and large providers, and Article 2(2) reaches smaller ones in defined cases, sole providers of an essential service among them (European Parliament and Council, 2022, Art. 2(2)).
A good answer is a dated, documented determination, made with counsel, that names which services fall where.
Our answer: the EU side is settled. Our Netherlands establishment is our main establishment, which places us under Dutch jurisdiction rather than the representative route. The UK side is open, deliberately in step with a Bill that is still moving: we are mapping our managed services against the RMSP definition with counsel, against a measure that has not commenced for anyone. That mapping publishes on this site once the Lords committee stage has settled the RMSP definition it depends on, and before the measure commences. If you are evaluating us before then, ask for the working analysis and we will share it under NDA.
2. Who is your regulator, and what is your local anchor?
Why it matters: when something goes wrong, you want a regulator with a domestic address for your provider, and a provider that knows who it is. Under the Bill as drafted, an RMSP will have three months from commencement to register with the Information Commission, and an RMSP based overseas must also appoint a UK representative (Department for Science, Innovation and Technology, 2026). In the EU, jurisdiction follows the provider’s main establishment if it has one in the Union, or a designated representative if it does not, feeding the registry that ENISA maintains (European Parliament and Council, 2022, Arts. 26 and 27).
A good answer names the authority and the anchor. A provider that cannot tell you which regulator it answers to, in a regime designed to give it one, is telling you something.
Our answer: in the EU our anchor is our Netherlands establishment, with the Dutch regime applying from the Cyberbeveiligingswet’s entry into force on 15 August 2026 (Rijksoverheid, 2026). In the UK we have mapped the representative route and will appoint and register within the statutory window once the RMSP measure commences.
3. If you are breached at 2am, what do I hear, and when?
Why it matters: both regimes are denominated in hours, though the clocks differ. Under NIS2, a significant incident triggers an early warning to the authority within 24 hours of awareness, an incident notification within 72, and a final report within a month; recipients of the service must, where appropriate, be notified without undue delay of significant incidents likely to adversely affect service provision (European Parliament and Council, 2022, Art. 23). Under the UK Bill as drafted, the provider owes its regulator an initial notification within 24 hours and a full report within 72, with the NCSC sighted in parallel, and after the full report it must identify which customers were likely affected and notify them with reasons (Department for Science, Innovation and Technology, 2026). If your provider’s incident plan ends at its own regulator, you are an afterthought in it.
A good answer describes a rehearsed pipeline: detection, triage, a named decision-maker, and a customer notification path with committed timings, tested against the clock, with the date of the last test.
Our answer: we treat the 24-hour notification as an engineering requirement. Our position, argued in our engineering series, is that evidence has to fall out of operations while they run: decisions and detections logged as they happen, so a regulator-grade statement of what we know can be produced from the pipeline in minutes. Customer notification rides the same pipeline, and we put the commitment in the contract. These clocks are new for everyone, including us: our first notification tabletop against the tighter of the two regimes runs in September 2026, ahead of any UK commencement date, with the exercise record going into the evidence pack and the drill repeating quarterly.
4. What protects the systems you use to reach into my environment?
Why it matters: your provider’s management plane, the workstations, bastions, credential vaults and monitoring systems it uses to administer your infrastructure, is an attack surface you imported when you signed. It is what both regimes’ security duties attach to, and for MSPs and MSSPs serving the EU the required measures are no longer abstract: Commission Implementing Regulation (EU) 2024/2690 fixes the technical requirements, directly applicable with no transposition needed (European Commission, 2024).
A good answer covers privileged access controls, session accountability, credential management, and monitoring of the management plane itself, mapped to those published requirements.
Our answer: this sits in our security practice. Least-privilege access with short-lived credentials in place of long-lived secrets, administrative paths isolated from general infrastructure, and monitoring that treats our own management plane as the highest-value target in our estate. We map those controls to the Implementing Regulation’s requirements and share that mapping under NDA on request. Sentinel governs the AI and agent layer of the same estate.
5. Show me the evidence, not just the certificate
Why it matters: an annual certificate tells you a control existed on audit day. Ask for it, and then ask what happens on the other 364. These regimes are built around demonstrable, continuing security measures and reporting duties measured in hours, and a provider whose evidence is assembled annually cannot answer an hours-denominated question.
A good answer is continuous: control evidence generated by the systems themselves, current, and shareable with you under NDA with a committed turnaround.
Our answer: evidence automation is what our Praxis solution exists for, and we operate the same pipeline against our own estate. Controls emit their own evidence as they operate, assembled into customer-ready packs on demand. Ask us for the pack, under NDA, scoped to the services you are evaluating, and we will return it within [N] business days.
6. What about your subcontractors?
Why it matters: your provider has providers. NIS2 makes supply chain security an explicit component of the required risk-management measures (European Parliament and Council, 2022, Art. 21(2)(d)), and the UK Bill’s reporting fields as drafted include whether an incident was caused by a separate incident at another regulated entity. Small subcontractors exempt from the UK’s RMSP measure can still be designated as critical suppliers. If your provider cannot map its own dependency chain, its answers to every question above have a hole in them.
A good answer is a current, published subcontractor inventory with flow-down of security obligations in subcontracts, and a stated position on which sub-processors touch your environment. An explicit, dated statement that none are used is equally good. Silence, or “we would have to check”, is the answer to score.
Our answer: none. We do not subcontract delivery. Managed services are run end to end by our own engineers, and the environments we manage sit in our customers’ own cloud tenancies, so no third party of ours holds access into your systems. Were that ever to change, our standing commitment applies: sub-processors are engaged only with customer prior approval, bound by terms no less protective than our own.
7. Will you put your answers in the contract?
Why it matters: everything above is conversation until it is a clause. Notification timings, evidence access, subcontractor disclosure, and cooperation with your own regulatory reporting duties all belong in the agreement. If you are a regulated entity, an incident at your provider can start your reporting clock as well as theirs, which is what makes the cooperation clause load-bearing.
A good answer is yes, with limits the provider can state up front.
Our answer: yes, with the limits stated up front. Notification timings, evidence access and sub-processor disclosure go into the agreement as commitments, and we will negotiate them. Where a proposed clause reaches past what we can operationally guarantee, a timing that depends on your detection stack rather than ours, for instance, we will say so at the table and propose the version we can meet. A provider that agrees to everything in the MSA has told you how seriously it takes the MSA.
Put it in your questionnaire this quarter
None of this waits for Royal Assent. The UK Bill will commence in phases through secondary legislation and its edges may still move, but the EU requirements for managed providers are in force now, and the direction on both sides is settled. Add these seven questions to your third-party risk questionnaire, ask them at renewal, and weight the answers by their specificity. Providers who have done the work will answer quickly and in writing. Providers who have not will answer with adjectives.
We have packaged the seven questions, the UK and EU reporting timelines, and a scoring rubric as a printable scorecard: The Managed Provider Scorecard. It is ungated; hand it to your third-party risk team.
If you want to put the seven questions to us directly, send us your questionnaire. We will return written answers with the evidence pack. And if you would rather not run this process alone across a full supplier estate, that is what our Managed GRC service is for.
Disclosure: Praxis, Sentinel, and the Managed GRC Services line referenced in this article are Sakura Sky offerings, and Sakura Sky provides managed services of the kind discussed. The descriptions of our own practices and regulatory scoping reflect their status at the date of this article and should not be relied on as a statement of any entity’s compliance status. Statements about our contracting positions describe our general approach and are subject to the terms of each engagement.
Not legal advice. This article offers general commentary on the UK Cyber Security and Resilience Bill and Directive (EU) 2022/2555 (NIS2) for a buyer and operations audience. The UK Bill is before Parliament at the time of writing and its provisions, including all duties described here as drafted, may change before and through secondary legislation. This is not legal advice and is not a substitute for counsel. Readers must obtain independent legal advice on how these regimes apply to their specific circumstances.
References
Department for Science, Innovation and Technology, 2026. Cyber Security and Resilience (Network and Information Systems) Bill: factsheets. Updated 30 June 2026. GOV.UK. Available at: https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets [Accessed 11 August 2026].
European Commission, 2024. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant. Official Journal of the European Union, L 2024/2690. Available at: https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj [Accessed 11 August 2026].
European Parliament and Council, 2022. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). Official Journal of the European Union, L 333, 27 December. Available at: https://eur-lex.europa.eu/eli/dir/2022/2555/oj [Accessed 11 August 2026].
Rijksoverheid, 2026. Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht. 7 July. Available at: https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht [Accessed 11 August 2026].

