For IT service providers: stay compliant, and help your clients do the same.

Run your own ISO 27001 and NIS2 programme, answer customer questionnaires once and give every client a workspace of its own. EU-hosted, public prices, cancel any time.

At a glance

  • Your company: ISO 27001, NIS2 and CyFun as recurring controls, and a trust page for your customers.
  • Your clients: a workspace per client, on the plan that fits them.
  • Your plan: Pro for up to five people, Enterprise for larger teams.

On this page

  1. NIS2 applies to MSPs twice
  2. Your own programme
  3. Your clients’ programmes
  4. Which plan fits

NIS2 applies to MSPs twice

Managed service providers and managed security service providers that serve business customers are in Annex I of NIS2, under ICT service management. From medium size you are an entity yourself: you register, take the Article 21 measures and report significant incidents. Implementing Regulation (EU) 2024/2690 spells out the technical measures for you.

You are also a supplier. Clients in scope must secure their supply chain under Article 21(2)(d), so they send you questionnaires and contract clauses. Dazr helps you on both sides.

Your own programme

  • ISO 27001, NIS2 and CyFun as recurring controls with owners, evidence and reminders, and an incident register that counts down the 24-hour, 72-hour and one-month NIS2 deadlines.
  • One trust page with your security answers and documents: share one link instead of filling in every questionnaire. On Enterprise, sensitive answers wait for your approval.
  • Policies your whole team acknowledges: policy readers are free from Pro, up to 2,000 per workspace.
  • A login for your certification body: time-limited and read-only, from Pro.
Acknowledgements for the information security policy: who confirmed which version and when, and who is still pending
Four of six people confirmed this version.

Your clients’ programmes

Every client gets a workspace of its own, with its own frameworks, registers, plan and invoice, so client data never mixes.

  • Set it up together. The client creates the workspace and invites your consultants as admins or members. Or you create it for the client and transfer ownership later.
  • Client data stays apart. Each sign-in address belongs to one workspace, so your consultants use an address per client, for example an alias.
  • Review without editing. A client on Pro or Enterprise can give you a time-limited, read-only auditor login for reviews and internal audits.
  • Reports your clients can share. The PDF audit trail carries the client’s company name on Pro and is fully white-label on Enterprise.
ISO 27001 Statement of Applicability with applicability, justification, implementation status and an approved version
The Statement of Applicability: applicability, justification and implementation per control, with the approved version.

Which plan fits

WhoPlanWhy
Your company, up to five people in DazrPro, €99 a monthFive frameworks such as ISO 27001, NIS2 and CyFun, the trust page, an auditor login and free policy readers
Your company, more than five people in DazrEnterprise, €499 a monthUp to 999 users, every framework, a gated trust page, the REST API and webhooks
A small client with one person on complianceFree or BasicOne or two of ISO 27001, GDPR and NIS2, from €0
A client in NIS2 scopePro or EnterpriseVendor register, auditor login and frameworks such as CyFun for Belgium

Every workspace is billed on its own, monthly or yearly, excl. VAT, and can be cancelled at any time. Compare every plan.

Sources: Directive (EU) 2022/2555, Implementing Regulation (EU) 2024/2690.

Questions from IT service providers, answered.

Can one sign-in manage several client workspaces?

Each sign-in address belongs to one workspace, which keeps client data apart. Give your consultants an address per client, for example an alias, or ask the client for a time-limited, read-only auditor login.

Is there a white-label version?

On Enterprise the PDF audit trail is white-label, with your logo, footer and signing officer. A white-label option for MSPs and consultancies is available on request on the Custom tier.

Where is client data stored?

In the European Union. Every client has a workspace of its own, and workspace records are encrypted at rest with AES-256-GCM at the application layer.

Start with your own workspace.