The Managed Provider Scorecard: Supplier Assurance Under NIS2 and the UK Cyber Security and Resilience Bill
Highlights:
- Seven scored questions, each with a description of what a substantive answer contains: an artefact, a date, or an NDA offer, never an adjective.
- Side-by-side reporting timelines: the NIS2 24-hour early warning, 72-hour notification, and one-month final report against the UK Bill's 24-hour initial notification, 72-hour full report, and post-report customer notification duty, as drafted.
- A scoring rubric that turns supplier answers into a comparable number across your provider estate.
- Four what-to-do-if playbooks: your provider notifies you of an incident, your provider cannot show a scope determination, your provider refuses contractual commitments, and the incident that may start your own regulatory reporting clock.
- Regime-agnostic by design: the same controls-first questions hold as further jurisdictions regulate managed providers.
Overview
Your providers are becoming regulated entities: NIS2 places managed service providers and managed security service providers under the directive by name, and the UK Cyber Security and Resilience Bill, as drafted, reaches any provider managing systems for UK customers, wherever that provider is established. Supplier assurance built for unregulated providers is now leaving leverage on the table.
Seven questions, scored: The scorecard organises supplier review around seven questions: scope determination, regulatory anchor, the 2am call, management-plane security, evidence discipline, subcontractors, and contractual commitment. Each question ships with a description of what a substantive answer contains and a three-point scoring scale, so answers become comparable across your provider estate rather than a folder of prose.
The clocks, side by side: One timeline diagram covers both regimes: awareness, 24-hour early warning or initial notification, 72-hour notification or full report, customer notification on each regime’s distinct trigger, and the EU’s one-month final report. Built for the third-party risk lead who needs to know what their provider owes, to whom, and when.
What to do if: Four short playbooks for the moments the questionnaire cannot cover: when a provider notifies you of an incident, when a provider cannot produce a determination, when a provider will not contract on its answers, and when your provider’s incident may be your reportable event.
Who This Scorecard Is For
- CISOs and heads of resilience whose critical operations run through managed providers.
- Third-party risk and procurement teams refreshing supplier questionnaires for a regulated-provider world.
- General counsel and compliance leads deciding which supplier answers belong in the contract.
- Managed providers themselves who want to know what their regulated customers are about to start asking.