NIS2, DORA and the CRA: Does Your MSP Cyber Insurance Still Cover Your Risks?

Abstract umbrella form lines and triangles, point connecting network on blue background.

Picture the call every MSP owner dreads. A compromised RMM tool, ransomware pushed to 40 clients overnight, a regulator asking for an early warning within 24 hours—and then, a few weeks later, a letter from your insurer explaining which parts of the claim it won’t be paying.

None of that requires a dramatic new threat. It only requires a policy written for the risks of 2021 meeting the rulebook of 2026. Over the last two years, NIS2, DORA and the Cyber Resilience Act have changed who MSPs answer to, what they promise in contracts and who in the business is personally on the hook. Yet many MSP insurance policies, including cyber and E&O (AKA professional indemnity) cover, haven’t kept pace with all of it, and the gaps tend to show up at the worst possible moment.

So here’s a practical look at where the new exposures sit, where cover commonly falls short, and a checklist to take into your next renewal.

The rulebook changed—your policy probably didn’t

You know the headline acts. What’s worth pausing on is how each one changes the shape of an MSP’s liability, rather than just adding another audit to the calendar.

NIS2
Managed service providers and MSSPs sit in scope in their own right, and in-scope clients are now obliged to scrutinize their supply chain—which means you. National rollout has been uneven: Germany’s implementing act took effect on December 6, 2025, with no transition period, while on July 8, 2026, the Commission referred Ireland, Spain, France and the Netherlands to the EU Court of Justice over incomplete transposition. The Commission has also proposed targeted NIS2 amendments as part of a January 2026 cybersecurity package, so expect more movement.

DORA
Applying since January 2025, DORA rarely hits MSPs directly. It arrives through the contract: financial-sector clients must push detailed ICT third-party terms down to their providers, from audit and access rights to exit plans and incident cooperation.

The Cyber Resilience Act
Since September 11, 2026, manufacturers have had to report actively exploited vulnerabilities and severe incidents, with a 24-hour early warning and a full notification within 72 hours, through ENISA’s Single Reporting Platform. The rest of the CRA follows on December 11, 2027. If you package, white-label or ship your own tooling, check whether you’ve quietly become a “manufacturer.”

The new Product Liability Directive
Often missed in MSP conversations, this one brings software into a strict liability regime. Member states must transpose it by December 9, 2026, and it covers products placed on the market after that date. It’s mainly a consideration for MSPs who build or substantially modify software, but it’s exactly the kind of exposure that many professional indemnity policies were never priced for.

GDPR remains the baseline, and the AI Act adds another layer for MSPs deploying or reselling AI tools. Taken together, the trend is clear: more reporting clocks, more contractual commitments and more personal accountability.

 

Where the new risks actually land

It helps to sort the new exposures into three buckets, because each one tends to fall under a different policy—or between them.

Regulatory exposure
Fines, supervisory audits, investigation costs, and the scramble to meet notification deadlines. NIS2 penalties for important entities can reach €7 million or 1.4% of global turnover, and €10 million or 2% for essential entities. Even where a fine never arrives, the legal and forensic bill for responding to a regulator can be substantial.

Contractual exposure
This is the quiet one. Clients facing NIS2 supply-chain duties or DORA third-party rules are rewriting MSA terms: tighter SLAs, audit rights, notification windows shorter than the law requires, uncapped or high-capped indemnities. Every one of those clauses creates liability your business has agreed to take on, which is not the same thing as liability the law imposes—and insurers treat the two very differently.

Personal exposure
NIS2 Article 20 requires management bodies to approve cybersecurity risk measures, oversee their implementation and undergo training, and it allows member states to hold them personally liable for infringements. Some national laws go further. In Germany, for example, managing directors must approve and monitor security measures and attend regular training. Temporary bans from management roles are on the table in serious cases. For owner-operated MSPs, where the board is two or three people who also run the help desk, this lands very close to home.

Are MSPs covered? The usual gaps

Most MSPs carry some mix of cyber, tech E&O or professional indemnity, and D&O. The problems tend to appear where those policies meet—or where none of them quite reaches.

Fines may simply be uninsurable
Many policies cover regulatory fines only “where insurable by law,” and in a number of EU countries that’s a short list. Insurance transfers financial risk; it doesn’t replace compliance, and it won’t shield a director from personal sanctions or a management ban. Defense and investigation costs are often coverable, though, so check those sublimits separately.

The contractual liability exclusion
E&O policies commonly exclude liability you’ve assumed under contract beyond what you’d owe anyway. The new generation of NIS2- and DORA-driven MSAs, with their indemnities and liquidated damages, can sail straight into that exclusion.

D&O that’s silent on cyber
Unless cyber-related management liability is affirmatively covered, insurers may decline claims against directors that stem from a cyber incident. Some wordings also carve out failures of oversight, which is precisely what NIS2 makes actionable.

Aggregation and systemic limits
One compromised management tool can mean dozens of client claims from a single event. Watch for aggregate limits sized for a single-client breach, and for “systemic event” or related-claims language that funnels everything into one limit.

War and state-actor exclusions
Market-standard cyber war exclusions have narrowed cover for attacks attributed to state actors. With supply-chain attacks on MSPs a favorite technique for state-backed groups, read how attribution works in your wording.

Warranties you can’t stand behind
Proposal forms now ask detailed questions about MFA, EDR, privileged access, and immutable backups. If an answer was optimistic—say, MFA on “all” admin accounts except the legacy one nobody remembered—an insurer can argue misrepresentation and walk away from the claim.

Clocks that don’t line up
NIS2 expects an early warning within 24 hours. Your policy may require you to notify the insurer first, use its panel of incident responders, or get consent before engaging lawyers and PR. If your incident plan only follows one of those sets of rules, you risk breaching the other.

The MSP insurance checklist

Take this into your next renewal meeting—or better, run through it a couple of months before.       

  • Map your regulatory footprint. List which rules apply to you directly and which reach you through clients (NIS2 supply chain, DORA third-party terms, CRA if you ship product). Do it per country you operate in.
  • Read your policies side by side. Cyber, E&O/PI and D&O together, looking for overlaps, gaps and conflicting conditions.
  • Check regulatory cover in detail. Defense and investigation costs, notification costs, and fines “where insurable”—with a clear view of what that means in your jurisdictions.
  • Test your contracts against your E&O. Pull your five largest client MSAs and ask your broker whether the indemnities and SLA penalties would be covered or excluded as contractual liability.
  • Confirm D&O affirmatively covers cyber, including claims arising from management’s oversight of cybersecurity.
  • Stress-test aggregation. Ask how a single incident affecting many clients would be treated, and whether your aggregate limit could absorb it.
  • Understand the war exclusion. Know who decides attribution and what happens to your claim while that’s argued.
  • Verify every control you’ve declared. MFA, EDR, backups, privileged access, patching cadence—if it’s on the proposal form, make sure it’s actually deployed everywhere you said it was.
  • Align incident response with both regulator and insurer. One plan that meets the 24-hour early warning and the policy’s notification and panel conditions.
  • Match limits to what clients now demand. Many MSAs specify minimum cover levels; check you still meet them.
  • Document board oversight. Minutes, approvals, and training records. They support compliance and provide a defense if things go wrong.

Working with brokers and underwriters

A generalist broker who places your office insurance is unlikely to spot a contractual liability clash in a DORA-driven MSA. Look for a broker with a genuine technology and cyber practice, ideally one that already places cover for other MSPs and can tell you what the market is paying out on—and declining.

Treat renewal as part of your compliance cycle, not a separate admin task. The evidence underwriters want (control maturity, incident plans, board oversight) overlaps heavily with what NIS2 supervisors and your clients’ auditors ask for, so build it once and use it three times.

Good controls are also a commercial lever. Underwriters increasingly price on verified security posture, and MSPs that can demonstrate strong identity, detection, and backup practices are in a better position to negotiate terms, limits, and exclusions—not just premiums.

The rules are still moving—check the latest

Everything above reflects the position as of October 2026, and this is not a stable landscape. NIS2 transposition is still incomplete in several member states, the Commission has proposed amendments to NIS2, the CRA’s main obligations are still to come, and national Product Liability Directive laws are landing on different timetables. Insurance wordings and market practice are shifting just as quickly.

Before you act on any of this, check the current position for the countries you operate in and talk to your broker and legal advisers. This article is general information, not legal or insurance advice.

Good places to start:

•             NIS2 Directive overview—European Commission, including the 2026 proposed amendments

•             NIS2 transposition in EU countries—European Commission

•             National NIS2 transposition measures—EUR-Lex

•             Digital Operational Resilience Act (DORA)—EIOPA, with links to the regulation and technical standards

•             Cyber Resilience Act and CRA reporting obligations—European Commission

•             Product Liability Directive (EU) 2024/2853—EUR-Lex

Q&A

Does cyber insurance cover NIS2 fines?
Sometimes, and only where the law allows it. Many policies cover fines “where insurable,” and several EU countries treat administrative fines as uninsurable. Investigation and defense costs are more commonly covered.

We’re a small MSP. Do we really need D&O?
If you’re in scope for NIS2, management can be held personally accountable for cybersecurity oversight. For owner-managed businesses, D&O with affirmative cyber cover is worth a serious conversation with your broker.

Our client wants us to sign a DORA-compliant contract. Will our E&O cover it?
Not automatically. Check whether the indemnities and penalties you’re agreeing to fall within the contractual liability exclusion before you sign.

Does better compliance mean cheaper insurance?
Often, though not always in premium terms. Strong, verifiable controls tend to improve your negotiating position on limits, exclusions, and conditions, and they reduce the risk of a declined claim.

Does the CRA apply to MSPs?
Only if you act as a manufacturer, importer, or distributor of products with digital elements—for example, by shipping your own software or white-labeling hardware or software under your brand. Pure service delivery generally falls outside it, but bundled products deserve a closer look.

Get the full picture at MSP GLOBAL

Regulation, liability and insurance are converging fast, and the MSPs that come through it best will be the ones comparing notes early. At MSP GLOBAL you can hear from the experts and fellow MSPs who are working through exactly these questions—and leave with a clearer view of where your own gaps are.

Register for free.

Miles Kendall Avatar

This might also interest you