NIS2, DORA, CIR 2024/2690: what the law actually asks of an MSSP
Three European texts now name managed security providers as a regulated class, put a clock on incident classification, and require exactly the monitoring a decision layer provides. The precise wording, the dates, and what is vendor folklore.
Regulatory pages on security-vendor websites tend to be a list of logos and a promise of compliance. This one is the wording, the dates and the traps, because a European MSSP is now a regulated entity in its own right and deserves better than folklore.
NIS2 names you
Directive (EU) 2022/2555 — NIS2 — brings roughly 160,000 entities into scope and, in Annex I, explicitly includes ICT service management (business-to-business). Managed security service providers are not merely vendors to regulated entities; they are regulated entities. Article 23 sets the reporting rhythm: a 24-hour early warning, a 72-hour notification, a final report within a month. Article 34 sets the sanctions: up to ten million euros or two percent of turnover for essential entities, seven million or 1.4 percent for important ones.
The trap is transposition. As of this writing France has no operational NIS2 regime in force — the loi résilience is unpromulgated, and in July 2026 the Commission referred France, Ireland, Spain and the Netherlands to the Court of Justice over the delay. What French entities are preparing against is ANSSI's Référentiel Cyber France, published in March 2026, and the MonEspaceNIS2 portal. Any vendor telling you the French law is live is wrong; any vendor telling you to wait is also wrong, because the referential is what the audit will use.
CIR (EU) 2024/2690 is the binding requirement to run a SIEM
The strongest citation for what a security operations platform must do is not analyst commentary. It is Commission Implementing Regulation (EU) 2024/2690, which applies directly to managed security service providers and legally mandates procedures and tools "to monitor and log activities on their network and information systems to detect events" — covering traffic, user lifecycle, authentication, all privileged access, configuration and backup access — and requires that logs be retained and "protected from unauthorised access or changes."
That is a binding legal requirement to operate exactly what a SIEM with tamper-evident retention provides, naming MSSPs as the regulated class. One caution: the regulation sets no retention period. The six-to-twelve-month figures circulating in vendor decks are vendor claims, not law.
DORA's clock starts at classification
Regulation (EU) 2022/2554 — DORA — has applied to financial entities since 17 January 2025 with no transition. Its reporting timeline, per the delegated regulation of 2025, runs four hours from the moment an incident is classified as major, and at most twenty-four hours from awareness; an intermediate report at seventy-two hours; a final report within a month. In November 2025 the European supervisory authorities designated the first nineteen critical ICT third-party providers, including the three US hyperscalers.
Note the asymmetry with NIS2. NIS2's clock starts at awareness; DORA's starts at classification. That is a direct product argument for automated, evidenced classification — the moment a case is triaged and its severity and business impact are recorded is the moment the four hours begin, and the decision trace is the evidence that the classification was made when it says it was.
The Cyber Resilience Act binds the vendor too
Regulation (EU) 2024/2847 — the CRA — turned its reporting obligations on manufacturers on 11 September 2026: actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT with a 24-hour early warning. Full essential requirements and CE marking follow on 11 December 2027. This binds Seculogik as a manufacturer, not only our customers, and it is why every release ships with a software bill of materials, a published disclosure policy and advisory format, and updates that are cryptographically signed, applied only by your administrator, and rolled back automatically if the platform fails its own health check afterwards.
What the platform does with all this — and does not
Seculogik produces the evidence and the reports a regulated entity needs: compliance scorecards for NIS2 and DORA alongside NIST CSF, ISO 27001 and GDPR; an evidence pack that labels each control implemented, gap or insufficient and says on its own cover that it is a self-assessed coverage signal rather than an attestation; a tamper-evident audit trail kept separately for each client; SLA clocks that record when a case was acknowledged and resolved; and a decision trace that records when it was classified, on what evidence, and what would have changed the outcome.
That last one is the difference between a report and a defence. When a regulator or a client asks why an incident was called major four hours in, the answer is already written down, with a timestamp nobody edited afterwards.
What it does not do — deliberately — is run the notification workflow or file with an authority on your behalf. The legal act stays with the entity that carries the liability. We considered building the deadline lifecycle and struck it, because a product that appears to have filed for you is a product that lets a report go unfiled.
What we will not tell you
We hold no ANSSI qualification, no CSPN, no SecNumCloud. A readiness assessment is on our roadmap; a claim is not. It is worth knowing that there is no ANSSI-qualified SIEM in existence today, and that running on a qualified host is not the same as being qualified — a distinction worth applying to every vendor you shortlist, including us.
Sovereignty on its own is also not a business model, and we would rather say so than sell it as one. It is a qualifier: necessary for a European MSSP that cannot ship client telemetry to a US model endpoint, and worth nothing without a product that actually reduces the queue.
What a European MSSP can put in front of an auditor today, on Seculogik: the telemetry never leaves its jurisdiction; the AI runs on your own box unless an administrator says otherwise, and every call that does leave is on a ledger nobody can edit; every decision carries a timestamped trace; and the vendor behind the platform is a European entity bound by the same regulations you are.