Managed Security Service Providers in Germany: A Structured Selection
Trusted Advisor for IT & Telecommunications Sourcing
Outsource security, keep responsibility
Managed security service providers at a glance
An MSSP shifts the operation of security, not the responsibility for it.
The German market for managed security services has become hard to read. System integrators, vendors, carriers and specialist providers sell very different things under the same label. Anyone looking to outsource part of their enterprise IT security is rarely comparing like with like. This article maps the market, names the criteria that actually matter in day-to-day operation, and shows where the line runs between a purchased service and your own accountability.
Key takeaways:
- A managed security service provider (MSSP) takes over operation, monitoring and response for clearly defined security services, usually through a security operations centre with round-the-clock cover.
- The German NIS2 implementation act has applied since 6 December 2025 with no transition period. Around 29,500 entities are in scope, and supply chain security is an explicit obligation.
- Comprehensive managed security packages for mid-sized companies frequently range between 1,000 and 5,000 euros per month, while managed detection and response is usually billed per monitored endpoint.
- Responsibility stays with executive management under Section 38 BSIG. A contract moves tasks, never liability.
The solution: Treat MSSP selection as a sourcing project with a written requirements profile, not as a product purchase. Defining service boundaries, response times and escalation paths before signing gives you comparable offers and an operation that holds up under pressure.
What this article covers: definition and scope, the typical service catalogue, the make-or-buy calculation, what NIS2 demands of service providers, a comparison of provider types in the German market, realistic costs and eight criteria for the selection.
Table of contents
- What is a managed security service provider?
- What does an MSSP actually deliver?
- Make or buy: when does an in-house SOC pay off?
- What NIS2 changes about provider selection
- Which provider types exist in the German market?
- What managed security services cost
- Why MSSP projects fail in practice
- Eight criteria for selecting an MSSP
- Conclusion: choosing an MSSP is a sourcing decision
- Frequently asked questions
What is a managed security service provider?
A managed security service provider, or MSSP, runs defined security functions of a company on a permanent, contractual basis. It does not deliver a product but an operating state: systems are monitored, anomalies are assessed, incidents are handled according to agreed rules.
The distinction from neighbouring models matters because it shapes the contract. A classic system integrator sells projects and licences and bills support by effort. A managed service provider (MSP) operates IT infrastructure, often including individual security components, but without dedicated analysis of attack patterns. An MSSP puts exactly that analysis at the centre and maintains the people, processes and tooling to deliver it.
Within the MSSP world, managed detection and response (MDR) has established itself as a separate model. MDR focuses on detection and response across endpoints, cloud and network, but frequently excludes the operation of security infrastructure. Anyone looking to outsource a firewall, a VPN or a SASE platform needs more than pure MDR.
What does an MSSP actually deliver?
Managed security is an umbrella term, not a scope of work. Only the service description tells you what you are actually buying. In practice, offers are assembled from these building blocks:
- Log collection and correlation (SIEM): events from firewalls, servers, cloud services and endpoints are consolidated into a single situational picture.
- Security operations centre (SOC): analysts assess alerts, separate false positives from genuine incidents and trigger the response.
- Detection and response (MDR, XDR): detection and active containment on endpoints, in identities and across cloud workloads.
- Operation of security infrastructure: firewalls, secure web gateway, zero trust network access, SASE platforms, email security.
- Vulnerability and patch management: regular scans, prioritisation by exploitability, tracking through to remediation.
- Incident response: forensics, containment and recovery in an emergency, frequently sold as a separate retainer.
- Compliance reporting: evidence for ISO 27001, BSI IT-Grundschutz or the reporting obligations under the BSIG.
Two building blocks are routinely overestimated. First, a SIEM without agreed use cases produces volume rather than insight. Second, incident response is rarely included in the base price. Clarify before signing whether a team turns up in an emergency or only a ticket appears.
Make or buy: when does an in-house SOC pay off?
Staffing an in-house security operations centre around the clock realistically requires eight to twelve full-time positions. The reason is arithmetic rather than technology: three shifts across seven days already amount to more than four full-time equivalents, before holiday, sickness, training and a second pair of eyes so that nobody analyses a night shift alone.
The labour market adds to this. Experienced security analysts are scarce and expensive, and attrition in shift operations is high. For most companies below roughly one thousand employees, a dedicated full-time SOC is therefore not economically viable, regardless of how strong the security requirement is.
The pragmatic middle ground is a hybrid model. The provider handles monitoring, first-level analysis and out-of-hours cover. The internal team keeps governance, prioritisation and the decision on disruptive interventions such as taking a production system offline. That model only works if both sides know in writing who decides what and when.
What NIS2 changes about provider selection
Germany’s NIS2 implementation act has applied since 6 December 2025, with no transition period. Around 29,500 entities with at least 50 employees or 10 million euros in annual revenue across 18 sectors are in scope, compared with only a few thousand operators previously supervised by the BSI.
The statutory registration deadline with the BSI expired on 6 March 2026. Because only around 18,500 entities had registered by the end of May 2026, the BSI communicated a grace period until 31 July 2026. That grace period is not a new deadline, it is leniency in enforcement. A missed registration alone can attract fines of up to 500,000 euros, while breaches of risk management and reporting duties can reach 10 million euros or 2 percent of global annual revenue.
Two consequences follow for MSSP selection. First, Section 30 BSIG explicitly requires supply chain security measures. Your provider therefore becomes part of your own risk management, and its certificates and processes belong in your documentation. Second, Section 38 BSIG anchors personal responsibility with executive management. You can delegate tasks, but the duty to supervise remains with you. We have broken down what this means for networks, sites and carrier supply chains in our article on NIS2 implementation for telecom infrastructure.
In practical terms: ask every bidder for a section on how they support you with reporting obligations. The 24-hour initial notification to the BSI is a process, not a form.
Which provider types exist in the German market?
The German MSSP market sorts into five provider types that differ in origin, pricing logic and closeness to the customer. No type is inherently better, but each suits a different requirement profile.
| Provider type | Strengths | Limits | Best fit for |
|---|---|---|---|
| System integrator with security practice | Knows your entire IT, single point of contact for operations and security | Security is often one business line among many, analytical depth varies widely | Companies that want IT and security bundled with one partner |
| Security specialist | Own SOC, mature processes, high analytical depth | Rarely operates the rest of the infrastructure, interfaces must be defined | Companies with their own IT that buy in detection and response selectively |
| Vendor MDR | Very tight integration with the vendor platform, fast time to value | Lock-in to one product ecosystem, later migration is costly | Environments already standardised on a single vendor |
| Carriers and ICT providers | Network and security from one source, strong on SASE and distributed sites | Endpoint and identity protection often delivered through partners | Companies with many sites and international connectivity |
| Global corporates and system integrators | Scale, worldwide presence, experience in regulated industries | Standardised processes, longer decision paths, higher entry sizes | Groups with international rollouts and dense regulatory requirements |
A note on market research: analyst houses such as ISG assess the German market regularly in dedicated studies for the mid-market segment. Such overviews help with the shortlist, but they do not replace testing against your own requirement profile.
What managed security services cost
Reliable list prices do not exist in this market, but typical ranges do. For mid-sized companies, comprehensive managed security packages frequently sit between 1,000 and 5,000 euros per month. MDR offerings are usually calculated per monitored endpoint and range from roughly 15 to 40 euros per endpoint per month, depending on provider and depth of service.
The billing model matters more than the entry price, because it determines how costs scale with your growth. Four logics are common: per endpoint, per user account, per data volume ingested into the SIEM, and a flat fee against a defined baseline. Volume-based models look cheap while few log sources are connected and become expensive as soon as cloud services are added.
Watch four line items that rarely sit in the base price: onboarding and integration, log retention beyond the standard period, incident response as a retainer, and additional hours for ad hoc analysis. These positions decide the real total cost of a contract.
Why MSSP projects fail in practice
Most disappointments come from vague agreements rather than weak technology. Five patterns recur.
The service boundary stays open. The provider detects an incident and reports it. Who isolates the affected system is written down nowhere. In an emergency, hours are lost clarifying responsibilities.
Alerts without a recipient. Notifications land in a mailbox that nobody reads at night or at the weekend. An escalation matrix with names, phone numbers and deputies belongs in the contract, not in a wiki.
Response times without a definition. A promised response within 15 minutes is worthless until it is clear whether that means the automated acknowledgement or human analysis.
The network is forgotten. Detection and response assume that sites, cloud access and remote connections are properly connected. Where connectivity is unstable, the SOC produces blind spots instead of security. Our article on highly available internet as the key to IT resilience explains why the underlay is the foundation of any detection strategy.
No exit planned. Contracts with 36-month terms and no agreed data export turn a provider change into a project. Clarify before signing in which format you get your logs and configurations back.
Eight criteria for selecting an MSSP
1)
Service boundary: where does detection end and response begin?
2)
Response times in the SLA, with a definition and a measuring point
3)
Location of the SOC, the data and the log storage
4)
Certifications with a traceable scope statement
5)
A named service delivery manager instead of an anonymous queue
6)
Integration into your existing network and cloud landscape
7)
Pricing model and cost drivers disclosed in full
8)
Exit scenario: data export, handover and notice periods
How SAVECALL helps with MSSP selection
SAVECALL is vendor-neutral and does not sell a security platform of its own. We translate your requirements into a testable profile, gather comparable offers and assess them against the eight criteria above. Useful starting points for the groundwork are our articles on the 12 most important IT security frameworks, on the question of when more cyber security becomes too much, and on your path to a SASE solution. With more than 80 carrier and vendor partnerships, we know the pricing logic, the contract traps and the real delivery capability of providers in the German market.
Conclusion: choosing an MSSP is a sourcing decision
The choice of a managed security service provider is not decided by platform feature lists. It is decided by clearly worded service boundaries, response times and escalation paths in the contract. Settling those points before the tender gives you comparable offers and an operation that still works at three in the morning. NIS2 raises the time pressure but changes nothing about the basic rule: the task can be delegated, the responsibility stays in house. Talk to us before you sign.

Written by
Frank Frommknecht
Key Account Consultant, SAVECALL
Has been guiding companies through the selection and optimisation of their connectivity solutions for more than 20 years. His focus: making complex telecommunications understandable from the customer’s point of view and finding the right solution strategically.
Sources
- Bitkom e. V.: Wirtschaftsschutz 2025, study report, 2025. bitkom.org
- Federal Office for the Protection of the Constitution: presentation of the Bitkom study Wirtschaftsschutz 2025, 2025. verfassungsschutz.de
- OpenKRITIS: NIS2 implementation act in Germany, 2026. openkritis.de
- SCHUTZWERK GmbH: NIS-2 registration by 31 July 2026, 2026. schutzwerk.com
Frequently asked questions
Frequently asked questions about managed security service providers
A managed security service provider (MSSP) runs all or part of a company’s IT security as an ongoing service. Typical elements are round-the-clock monitoring, alerting and response to security incidents through a security operations centre. Firewall, endpoint and cloud protection, vulnerability scanning and compliance reporting are usually part of the package. The difference to a classic reseller lies in the operating model: an MSSP does not sell products, it sells a contractually assured service with defined response times.
Pricing depends on scope, company size and data volume. For mid-sized companies, comprehensive packages frequently range between 1,000 and 5,000 euros per month. Managed detection and response is usually billed per monitored endpoint and ranges from roughly 15 to 40 euros per endpoint per month, depending on provider and depth of service. The billing model matters more than the list price: SIEM data volume, the number of log sources and separate charges for incident response shift total cost considerably.
Staffing an in-house security operations centre around the clock realistically requires eight to twelve full-time positions in shift operation, plus tooling, threat intelligence and cover for absences. For most companies below roughly one thousand employees this does not add up. A hybrid model is often the pragmatic answer: the provider handles monitoring and first-level analysis, while the internal team keeps governance, prioritisation and the decision on any disruptive intervention in production systems.
The German NIS2 implementation act has applied since 6 December 2025 with no transition period and covers around 29,500 entities. Two points affect provider selection directly. First, Section 30 BSIG explicitly requires supply chain security measures, which makes your MSSP part of your own risk management. Second, Section 38 BSIG places responsibility with executive management. You can hand over tasks, but you cannot hand over liability.
ISO 27001 is the minimum and should cover the provider’s own operations, not just individual data centres. An ISAE 3402 report or a SOC 2 report adds meaningful evidence on service quality, BSI IT-Grundschutz matters for regulated clients, and vendor partner levels indicate platform expertise. Scope is the critical detail: ask for the certificate as a document and check which locations and which services it actually names.
Basic monitoring can often be activated within a few days. A full rollout with SIEM integration, defined use cases, agreed escalation paths and tested response processes realistically takes four to twelve weeks. The time-critical part is rarely the technology. It is the clarification of responsibilities: who may take a system offline, who reports to the authorities, who decides at three in the morning. Settle these questions before signing.
Articles that may also interest you
Why
Telekom & IT-Sourcing.
Weltweit. Carrier-Unabhängig.
Auswahl & Betrieb weltweiter Connectivity- & Cloud-Infrastruktur. Ohne Vendor-Risiko & unnötige Kosten.
- 80+ Carrier weltweit
- EIN Dashboard
- EIN Ansprechpartner
- EIN SLA
- Min. 20% Einsparung



