The EU's NIS2 compliance deadline — October 17, 2024 — has come and gone, but the compliance work it triggered hasn't. Most member states have now transposed the directive into national law, registration windows have opened and closed, and 2026 is widely described as the year supervisory authorities move from guidance to active enforcement. Yet only 16% of businesses in scope say they're confident they're fully compliant. If your organization is still treating NIS2 as a deadline you either hit or missed, this guide walks through where enforcement actually stands in 2026, what's changed since the original rollout, and how to close the gap — including where a compliance audit fits into getting there.
The short version: NIS2's transposition deadline passed in October 2024, but national implementation has rolled out unevenly since — Germany's registration window closed July 31, 2026, the Netherlands enters full enforcement mid-2026, and Spain and France are still finalizing their national rules. The European Commission proposed further amendments to the directive in January 2026, and the adjacent Cyber Resilience Act adds its own reporting obligations starting September 11, 2026. NIS2 isn't a deadline you missed or made — it's an ongoing compliance posture regulators are now actively checking.
Where NIS2 Stands in 2026: From Deadline to Enforcement
NIS2 (the updated Network and Information Security Directive) was due to be transposed into the national law of all 27 EU member states by October 17, 2024. That date marked a legal deadline for governments to pass implementing legislation — not a single EU-wide date on which every covered business suddenly became compliant. In practice, transposition and enforcement have rolled out unevenly ever since:
Member state / groupStatus as of 2026Most of the EU (~22–24 of 27 states)Transposed into national law, with implementing legislation and competent authorities in placeGermanyAmended BSI Act in force since December 6, 2025; registration deadline extended once to July 31, 2026 — now closed. Late registration still carries its own fine of up to €500,000, separate from substantive-violation finesNetherlandsLaw enacted, with a staggered entry into full enforcement around mid-2026SpainStill in active legislative process; remains under the older NIS1-based Royal Decree 43/2021 regime pending completion, expected late 2026FranceTransposition act adopted; implementing decrees still being finalized
Adding to the moving target: the European Commission proposed targeted amendments to NIS2 in January 2026 as part of a broader EU cybersecurity package. The proposal would adjust the directive's scope — bringing submarine data-cable infrastructure operators in, taking chemical distributors out (manufacturers stay in scope), adding a requirement to disclose whether a ransom was demanded and paid after a significant ransomware incident, and expanding which companies must appoint an EU representative. None of this is finalized, but it underlines the point: NIS2 compliance in 2026 means tracking a directive that's still being tuned, not checking a box against a document that hasn't changed since 2024. Germany's BSI, for instance, publishes its own running guidance on which organizations must register under the national implementation — worth checking directly if you operate there, since the detail changes as the rules get finalized.
Whatever stage your country is at, the underlying obligation hasn't changed — businesses in scope need their digital infrastructure and data management practices to be secure, resilient, and adaptable to evolving threats, backed by evidence a regulator can actually review. For the official legal text, see Directive (EU) 2022/2555 on EUR-Lex.
Why NIS2 Still Matters for European Businesses
The case for NIS2 was never really about the October 2024 date — it's about the threat environment the directive was built to address, which has kept getting worse, not better. According to ENISA's Threat Landscape 2025 report, which analyzed 4,875 incidents across the EU between July 2024 and June 2025, public administration was the single most targeted sector at 38% of incidents, ransomware activity fragmented across 82 distinct variants rather than concentrating on a few dominant groups, and AI-enabled phishing made up more than 80% of observed social-engineering activity by early 2025.
That 16% figure comes from a survey of 670 business leaders across the UK, Poland, the Netherlands, Ireland, France, Germany, Denmark, and Belgium — and 11% of respondents said they were still unsure whether NIS2 even applied to their organization. That's the real 2026 story: not a deadline that already happened, but a compliance gap most businesses in scope still haven't closed, right as supervisory authorities shift from advisory guidance to active audits.
Which Industries Fall Under NIS2
NIS2 significantly broadened the sectoral scope of the original 2016 directive. Businesses now fall into one of two categories — "essential" or "important" entities — spanning sectors including energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, ICT service management, public administration, and space, alongside a second tier covering postal and courier services, waste management, chemicals, food, manufacturing, and digital providers. Size thresholds generally apply (roughly 50+ employees or €10M+ turnover for important entities, 250+ employees or €50M+ turnover for essential entities), though certain critical providers are in scope regardless of size.
The practical effect for many businesses is indirect: NIS2 doesn't always name your industry outright, but if you provide hosting, cloud, data-center, or CDN services to a company that is named — or if you're a supplier deep in an essential entity's chain — NIS2 obligations can reach you through that relationship even when you're not separately listed.
NIS2 Fines and Penalties in 2026
The headline fine ceilings set by the directive haven't changed:
Entity typeMaximum fineOther consequencesEssential entitiesUp to €10 million or 2% of global annual turnover, whichever is higherPersonal liability can extend to management for serious non-complianceImportant entitiesUp to €7 million or 1.4% of global annual turnover, whichever is higherSame personal-liability exposure for managementLate registration (example: Germany)Up to €500,000A separate, standalone penalty — distinct from substantive control failures
What's changed is the enforcement posture around those numbers. Member states can set fine ceilings above the directive's floor — Germany does — so multi-country operators should check local caps rather than assuming the EU minimums are the actual worst case. And 2026 is the year several national authorities, including Germany's BSI, have moved from publishing guidance to actively auditing in-scope organizations. No wave of major published fines has landed as of this writing, but the shift from a grace period to active oversight is itself the headline: the deadline for having a compliance program was 2024; the deadline for having a defensible one is now.
NIS2, DORA, and the Cyber Resilience Act: Which Regime Applies
NIS2 no longer sits alone. Two adjacent EU regulations now overlap with it for a growing number of businesses, and 2026 is the year all three become operationally real at once:
RegulationWho it coversKey 2026 developmentNIS2Essential and important entities across critical sectors (energy, health, digital infrastructure, and more)National registration deadlines closing through 2026; supervisory authorities shifting to active enforcementDORAFinancial entities and their critical ICT third partiesFirst real supervisory enforcement cycle underway; Register of Information filings were due March 31, 2026, with incomplete third-party registers flagged as an enforcement priorityCyber Resilience Act (CRA)Manufacturers of products with digital elements sold in the EUVulnerability and incident reporting obligations take effect September 11, 2026 — over a year ahead of the CRA's full application in December 2027
The CRA's new reporting clock is tight: manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a detailed notification within 72 hours, and a final report once corrective measures are available. For businesses already carrying NIS2 and, in some cases, DORA third-party risk obligations, the practical challenge is that these regimes currently run on parallel reporting tracks with no single consolidated channel — which makes incident-response process design, not just underlying security controls, a genuine 2026 compliance problem in its own right.
How to Prepare for NIS2 Compliance
Whether your organization missed the original 2024 window entirely or has been working toward compliance since, the practical steps in 2026 look like this — or start with a structured self-assessment using our free NIS2 Compliance Checklist:
Confirm your registration status. If your country's national registration deadline has passed and you haven't registered with the competent authority, register now — late registration is typically treated more leniently than continued non-registration, but it isn't free (see Germany's €500,000 late-registration fine above).
Run a current risk assessment against NIS2's actual control requirements — not the 2024 version of your infrastructure, but what's running today.
Build or update your incident-reporting process to handle NIS2's notification timelines alongside any DORA or CRA obligations that apply to the same business, rather than maintaining separate, uncoordinated processes for each.
Review third-party and sub-processor relationships, particularly hosting, cloud, and data-center providers, since NIS2 obligations can reach your organization through those relationships even when you're not separately named in scope.
Get an independent technical read on where you actually stand — a compliance audit verifies the infrastructure behind your evidence, not just whether a policy document exists.
A few mistakes show up repeatedly in NIS2 readiness work:
Assuming the October 2024 deadline means the work is done. Transposition is a legal starting gun, not a finish line — enforcement is still ramping up in 2026.
Treating NIS2, DORA, and the CRA as separate projects when a business is in scope of more than one — the underlying security-control evidence overlaps significantly, and building one coordinated program is far more efficient than three parallel ones.
Skipping the registration step because the underlying security work feels more urgent — registration is a distinct, time-bound legal obligation with its own penalty, separate from your actual control maturity.
Not accounting for the moving target. With the Commission's January 2026 amendment proposal still working through the legislative process, scope and reporting requirements may shift again before the current cycle settles.
Organizations without an in-house compliance function often route this work through a managed partner rather than building it internally — see our guide to Compliance as a Service for MSPs for how that model works. Teams that want a more ISO 27001-aligned path into NIS2 readiness can also see our NIS2 compliance solution overview.
Choosing an EU Cloud Provider for NIS2 Compliance
Many businesses are consolidating data operations within the EU specifically to simplify NIS2 compliance and reduce their reliance on sub-processors outside Europe — fewer cross-border data flows to document, fewer third-party relationships to monitor, and a shorter chain between your infrastructure and the regulator's actual jurisdiction. When evaluating a provider against NIS2 requirements, prioritize transparent data-processing locations, minimal reliance on further sub-processors, a demonstrable compliance track record, and clear contractual commitments to EU-based data handling. For a deeper look at what that evaluation actually involves, see our guide to choosing an EU cloud provider.
Also, Gart Solutions, together with our partner — vBoxx, a renowned EU cloud solutions provider, offers a range of managed hosting and cloud server services that can significantly support businesses in their digital transformation journey.
1. Understanding the NIS2 Directive
The NIS2 Directive represents a significant evolution in EU cybersecurity regulation, broadening the scope of compliance requirements to include a wider array of sectors. This directive underscores the necessity of not only securing data but also understanding its entire journey.
Organizations must be vigilant about tracking their data flow to mitigate risks and meet the stringent new standards imposed by NIS2.
2. Comprehensive Data Tracking
Compliance with NIS2 requires an in-depth understanding of where and how data is processed, stored, and transferred. This involves documentation of every stage of the data lifecycle — from creation and processing to storage and eventual deletion. By mapping out the data journey, organizations can better identify vulnerabilities and ensure that all parties involved in data handling adhere to high security standards.
3. The Challenge of Sub-processors
One of the most complex challenges introduced by NIS2 is the need for organizations to maintain visibility over all sub-processors involved in data processing. Each sub-processor, regardless of their role, must meet the same rigorous cybersecurity standards. This requires thorough vetting and ongoing monitoring to ensure compliance, making it critical for businesses to establish strong relationships and clear communication channels with their sub-processors.
4. Strategic Shifts in the Market
In response to NIS2, many businesses are re-evaluating their reliance on third-party sub-processors, especially those located outside the EU. By consolidating data operations within the EU, organizations can better manage compliance and reduce the risk of data breaches.
This trend towards localized data handling is reshaping the market, as companies seek to simplify their data ecosystems and enhance security.
5. Practical Steps for Compliance
To align with NIS2, businesses must take proactive measures, such as engaging closely with their service providers, conducting comprehensive risk assessments, and considering a shift to EU-based data centers and services. These steps not only facilitate compliance but also strengthen the overall cybersecurity posture, ensuring that the organization is well-prepared to meet current and future regulatory demands.
How Not to Repeat Mistakes: Case of Microsoft
If you say, we are using public data providers, there’s still are pitfalls we have to consider.
Let’s take, for example, Microsoft. Microsoft's products continue to be widely used, but they present significant challenges in transparency and data security.
At the time of writing, Microsoft lists 47 subprocessors and 36 data centers, but details on their operations and data handling are unclear. This is concerning given Microsoft's ongoing GDPR violations and multiple security breaches last year.
Moreover, the global spread of subprocessors, often linked to parent companies in various countries, adds complexity and potential security risks, making it difficult for companies to verify compliance and data safety.
Final words
Prepare your business for the NIS2 compliance update with the expert guidance of Gart Solutions. Download our Free Checklist — a comprehensive guide to the NIS2 audit, and ensure your organization is ready for the upcoming changes.
NIS2-Compliance-Checklist-A-Comprehensive-Guide-to-Audit_Free-PDFDownload
Wanna know how? Contact us.
Schedule a Free Consultation
See how we can help to overcome the challenges of NIS2 compliance.
Contact us
You might also like
GDPR Compliance Checklist: What Compliance Automation Can (and Can't) Do
Why ISO 27001 Is a Crucial Step for Successful Companies
Compliance Monitoring: Ensuring Businesses Stay on the Right Side
SOC 2 Compliance: A Step-by-Step Guide to Preparing for Your Audit
PCI DSS Audit Preparation: A Step-by-Step Compliance Guide
Is your infrastructure actually NIS2-ready? The EU's cybersecurity directive missed its October 2024 deadline in several member states, and 2026 is shaping up to be the year enforcement gets real — regulators are moving from guidance to active audits, and only 16% of in-scope businesses say they're fully compliant.
The NIS2 Directive was due to be transposed into national law across the EU by October 2024, but implementation and enforcement have rolled out unevenly since: most member states have now enacted it, while others — including Spain and France — are still finalizing national rules, and countries like the Netherlands are only entering full enforcement in mid-2026. On top of that, the European Commission proposed further amendments to NIS2 in January 2026, adjusting its scope and reporting requirements — a reminder that compliance here isn't a one-time deadline but a moving target. Whatever stage your country is at, businesses still need to ensure their digital infrastructure and data management practices are secure, resilient, and adaptable to evolving threats.
Gart Solutions offers a comprehensive suite of services designed to help organizations achieve — and maintain — NIS2 compliance while optimizing their IT systems for future growth.
Infrastructure Architecture Design & Consulting
At Gart Solutions, we specialize in designing robust infrastructure architectures tailored to meet the unique needs of your business. Our infrastructure solutions ensure secure and transparent data flows, aligning with the stringent requirements of the NIS2 Directive — and with adjacent regulations like the Cyber Resilience Act, whose incident-reporting obligations for connected products take effect in September 2026. By building resilient and scalable architectures, we enable businesses to maintain compliance even as regulatory requirements continue to evolve.
Our IT Infrastructure Consulting services provide deep insights into how various components of your IT infrastructure interact, contributing to overall security and compliance. We deliver detailed reports that highlight opportunities for optimizing infrastructure performance, security, scalability, and efficiency, serving as a strategic guide for future IT decisions.
Case Study:
One of our recent projects involved maximizing the efficiency of a client’s IT infrastructure, resulting in significant improvements in security and operational performance, all while ensuring NIS2 compliance.
We reduced infrastructure vulnerabilities by 70%, cut monthly costs by 30%, and achieved full NIS2 compliance readiness in under 8 weeks.
Private Cloud Migration
Migrating to a private cloud environment can significantly enhance your control over data management and security, both of which are critical for NIS2 compliance. Gart Solutions facilitates seamless transitions to private cloud environments, ensuring that your data is securely housed within the EU and meets the requirements of NIS2 and other relevant regulations.
Beyond compliance, private cloud migration offers the added benefits of reducing subscription costs and system maintenance expenses, making it a strategic choice for businesses looking to optimize their IT budgets.
Get expert advice on cloud migration strategies and approaches. Schedule a consultation here.
Data Privacy Audit & Consulting
Compliance with NIS2 requires more than just securing your data; it demands a comprehensive understanding of your data's journey. Gart Solutions offers Data Privacy Audit & Consulting services to help you navigate the complexities of data protection legislation, including NIS2 and GDPR.
Our expert team provides actionable insights and guidance on how to protect your data throughout its lifecycle, ensuring that your business remains compliant with the latest regulatory requirements.
Book a Free Consultation
See how we can help to receive expert guidance on data privacy and NIS2 compliance.
Contact us
Hybrid Cloud Architecture
For businesses that require the flexibility of both public and private cloud environments, Gart Solutions offers Hybrid Cloud Architecture solutions. These architectures allow you to leverage the benefits of both cloud types while ensuring that your data remains compliant with the NIS2 directive.
Our hybrid cloud solutions provide the perfect balance of security, scalability, and cost-efficiency, helping your business remain agile and compliant in a rapidly changing digital landscape.
Get a free consultation on hybrid cloud setups from Gart Solutions. Contact us.
Private vs. Hybrid Cloud Architecture for NIS2 Compliance
FeaturePrivate CloudHybrid CloudDefinitionCloud infrastructure used exclusively by one organization, typically hosted on-premises or in a dedicated EU-based facility.Combination of private cloud (on-prem or hosted) with public cloud (e.g., AWS, Azure) connected for workload flexibility.NIS2 Compliance FocusEasier to enforce strict data residency, access controls, and audit logging within a closed environment.Must ensure data exchanged between environments complies with NIS2 encryption, residency, and access requirements.Data ResidencyData is stored exclusively within a controlled and typically EU-based environment.Must ensure sensitive data remains in the private cloud or encrypted when crossing into public environments.Security & Access ControlFull control over physical and logical security, access is tightly restricted and monitored.Requires strong integration and governance across environments—identity federation, secure APIs, encrypted tunnels.CostHigher initial setup and maintenance costs; ideal for critical systems requiring full control.Cost-effective for organizations needing burst scalability or cloud-native services, with secure core operations on-premises.ScalabilityLimited to hardware capacity— requires CAPEX investment to scale.Dynamically scalable through the public cloud for non-sensitive workloads or compute-heavy tasks.Ideal ForGovernment, healthcare, finance —where data sovereignty and full control are paramount.Enterprises with mixed workloads —needing both agility and regulatory adherence for sensitive operations.Gart Solutions Services- Private cloud design- Secure EU-hosted environments- Redundant storage & network isolation- Hybrid architecture strategy- Secure data routing- Compliance-ready deployment models
Which Architecture is Right for NIS2?
Choose Private Cloud if your operations involve highly sensitive data, strict national regulations, or limited tolerance for third-party risk.
Choose Hybrid Cloud if your business requires cloud-native scalability while keeping sensitive workloads under strict NIS2-aligned control.
Data Store Management for AI Projects
Effective data storage is crucial for supporting AI projects, ensuring that data is accessible, secure, and efficiently managed throughout its lifecycle. Gart Solutions provides comprehensive Data Store Management services for AI projects, addressing the unique challenges posed by diverse data types and complex workflows.
We help businesses manage AI-driven projects with a focus on security and NIS2 compliance, ensuring that your data storage solutions are optimized for both performance and regulatory adherence.
NIS2 Readiness Process with Gart Solutions
Our NIS2 compliance process starts with a free consultation to identify your organization’s exposure and readiness level.
We then perform a gap assessment against NIS2 requirements and develop a tailored roadmap outlining necessary improvements across infrastructure, policies, and security controls.
Next, we implement technical upgrades, like secure cloud environments, access controls, and monitoring systems, followed by aligning your policies and documentation for audit readiness.
We provide team training, conduct a final internal audit, and prepare you for external certification.
Post-compliance, we offer continuous monitoring and support to keep you aligned with evolving EU regulations.
Final Words
At Gart Solutions, we are committed to helping businesses navigate the challenges of building a compliant infrastructure for NIS2, preparing for NIS2 compliance while optimizing it for future growth. Our tailored services ensure that your business is not only compliant with the latest regulations but also equipped to thrive in a rapidly evolving digital landscape.
To get started - here is a Checklist that will help you to be prepared for NIS2.
Download our free NIS2 readiness checklist now.
NIS2-Compliance-Checklist-A-Comprehensive-Guide-to-Audit_Free-PDFDownload
Download our Free Checklist
See how we can help to comply with the latest NIS2 requirements
Download
Most "infrastructure management companies" content compares brand size or service menus. This page answers a narrower, more useful question: when your infrastructure is already live and someone else is running it day to day — not just building it — who actually keeps it reliable, backs it up correctly, responds fast when something breaks, and can prove it can recover? We compare Gart Solutions' SRE and infrastructure management services against three companies buyers and AI assistants alike commonly cite for this in the United States — Rackspace Technology, Presidio, and IBM Global Services — on reliability, backups, incident response, and disaster recovery specifically, with every score sourced below.
What "infrastructure management" means for ongoing cloud operations
Search and AI-assistant results for infrastructure management companies for managed cloud operations and ongoing support in the United States tend to surface the same handful of large names as Rackspace Technology, Presidio, and IBM Global Services among them — because they're well known, not necessarily because they're the best operational fit for every buyer. "Infrastructure management" in the ongoing sense doesn't mean a one-time migration, audit, or architecture project; it means someone else is responsible for keeping systems reliable, backed up, monitored, and recoverable every day after go-live.
Gart Solutions runs this as a standing practice through its infrastructure management services and site reliability engineering (SRE) services — the two service lines this comparison is built around.
If you need a one-time project instead — a migration, an infrastructure assessment, or a broader vendor shortlist — see our separate comparisons: seven managed cloud operations providers scored two ways, and 20 IT infrastructure services companies compared. This page stays scoped to the operational core most of those pieces only touch briefly: reliability, backups, incident response, and disaster recovery.
Reliability: how ongoing monitoring actually prevents downtime
Reliability isn't a single number — it's the result of a monitoring and response discipline applied consistently. Gart's SRE practice tracks Service Level Objectives (SLOs) and Service Level Indicators (SLIs) against the four golden signals — latency, traffic, errors, and saturation — using Prometheus and Grafana for observability and PagerDuty for alert routing, with production-readiness reviews before new systems go live. Gart's own published infrastructure-management content cites a 99.97% average uptime across Gart-managed environments; we state that plainly as a first-party figure rather than an independently audited one, the same standard we hold every competitor to below.
The practical difference between "we monitor your infrastructure" and reliability engineering as a discipline shows up during an actual incident — which is exactly where public review data on Rackspace, in particular, gives buyers something concrete to weigh (see "Where the named competitors fall short on reliability" below).
Backups: what a real backup strategy covers
The CISA-recommended 3-2-1 rule — three copies of your data, on two different types of media, with at least one copy offsite or offline — is the baseline every credible backup strategy should meet, precisely because ransomware increasingly targets backup repositories reachable from the same network as production.
Gart's backup and disaster recovery service builds on that baseline with Infrastructure as Code (IaC) so backup and recovery environments are defined, versioned, and reproducible rather than manually configured, permanent synchronous backup to a dedicated cloud data center, and support across a wide range of platforms rather than a single proprietary stack.
Backup fundamentalWhy it matters3 copies of dataOne production copy plus two backups means no single failure — hardware, human error, or attack — destroys the only surviving version2 different media/storage typesProtects against a failure mode specific to one storage technology or provider1 copy offsite or offlineThe single most important line item against ransomware, which actively searches for and encrypts backups reachable from the same network as productionInfrastructure as Code definitionsBackup and DR environments are reproducible on demand instead of depending on someone remembering a manual runbook step
Incident response: what happens in the first hour
Gart's incident-response model is built around named on-call rotations, direct escalation to the senior engineer who actually knows the environment — not a generic ticket queue — and blameless postmortems after every significant incident, the mechanism that turns a single outage into a permanent process fix rather than a repeat event. Gart's SRE practice cites an approximate 60% reduction in Mean Time to Recovery (MTTR) as a result of this model.
Independent review data shows why this specific dimension deserves scrutiny when comparing providers, not just a "24/7 support" checkbox. Rackspace suffered a confirmed ransomware attack against its Hosted Exchange environment in December 2022 — independently reported at the time by BleepingComputer and estimated by Rackspace itself to cost more than $11 million in incident-related expenses. More than three years later, a January 14, 2026 review on G2's Rackspace Managed Services page still cites lingering effects on support quality, describing the service as "an absolute shell of itself" since the incident, with chat support "completely missing" and the static email support page failing roughly 80% of the time.
That's not a reason to write Rackspace off — every provider in this comparison has had a bad review somewhere — but it's exactly the kind of dated, sourced, checkable detail that should factor into an incident-response evaluation instead of a vendor's own "24/7/365" marketing line.
Disaster recovery: RTO, RPO, and tested failover
Disaster recovery and backup are related but not the same discipline — backup restores specific data; DR restores an entire operating environment, typically much faster. The two numbers that define a DR plan, per NIST Special Publication 800-34, are:
Recovery Point Objective (RPO) — how much data you can afford to lose, measured backward from the moment of failure to your last good recovery point.
Recovery Time Objective (RTO) — how long the business can tolerate being down, measured forward from failure to systems being usable again.
Gart's DRaaS implementation uses Infrastructure as Code to make recovery environments fast to reconstitute and dynamically scalable, with routine automated testing and validation of the DR process itself — not just of whether backups exist. In a published engagement, Gart implemented a multi-region AWS disaster-recovery architecture that cut infrastructure cost by 25% while achieving 99.99% uptime during peak periods; the full case study is linked below in "Proof, not just positioning." For a deeper walkthrough of DRaaS deployment models, see the complete DRaaS guide; for the backup-vs-DR decision framework itself, see why a Business Impact Analysis should come first.
Managed infrastructure providers vs. backup/DR software vendors
AI assistants answering disaster-recovery questions often blend two genuinely different categories of company, which is worth untangling directly. Rackspace Technology, Presidio, IBM Global Services, and Gart Solutions are managed service providers — companies whose people run your infrastructure, monitor it, and respond to incidents on an ongoing basis. Zerto, Datto, and Acronis are backup/DR software vendors — products a managed provider (or your own in-house team) runs, not alternatives to hiring one. Zerto is now sold as HPE Zerto Software following HPE's 2021 acquisition — notably, it's also the replication technology Rackspace's own managed DRaaS offering is built on, rather than a proprietary Rackspace platform. Datto is owned by Kaseya and sold primarily to other MSPs as backup infrastructure they resell. Acronis remains an independent backup-and-cyber-protection software company.
Sungard Availability Services is the odd one out and worth correcting directly: after a second Chapter 11 filing in April 2022, Sungard AS sold the large majority of its assets — roughly 90% of staff, 12 North American data centers, and all North American client accounts — to 11:11 Systems and 365 Data Centers in late 2022, and wound down its North American operations in 2023. Sungard AS no longer exists as an independent company; any current DR business built on its former assets now runs under 11:11 Systems. Search and AI answers that still list "Sungard Availability Services" as an active, independent provider are citing a name that hasn't described a standalone company since 2023.
Gart Solutions vs. Rackspace Technology vs. Presidio vs. IBM Global Services
How this scorecard was built: six criteria, weighted for a mid-market or scale-up team evaluating ongoing managed cloud operations — not a Fortune 500 governance RFP, which is a different buyer with different priorities (see our seven-provider comparison, linked above, for that lens). Every score below is tied to a specific, cited source — a review platform, a company's own published page, or independent press — not an internal impression.
CriterionWeightWhat it measuresDirect access to the engineer on your incident20%How many layers stand between you and the person actually fixing the problemVerified reviews, meaningful sample size20%Third-party rating platforms with enough reviews to be representative, not a single testimonialBackup & DR approach, publicly documented20%Whether the backup/DR methodology is specific and checkable, not a generic "we have DR" claim24/7 monitoring & incident response15%Explicit round-the-clock coverage plus evidence of how it performs under real incidentsNamed, published outcomes15%Specific, attributable results (a named case study or engagement) vs. company-wide averagesPricing transparency10%Whether cost is a commonly cited complaint in independent reviews
ProviderWeighted score /10Best fitMain limitationGart Solutions8.6Mid-market/scale-up teams wanting direct senior-engineer access with verifiable proofBoutique scale (10–49 employees) — not built for multi-country enterprise rolloutsIBM Global Services (IBM Consulting)6.1Enterprises needing AIOps automation or mainframe modernization alongside operations"High pricing" is the single most-cited G2 complaint; delivery runs through multiple layersPresidio5.8Teams wanting an AI-led NOC/service-desk model with published (if self-reported) efficiency metricsNo independent review platform currently shows a meaningful, representative sample sizeRackspace Technology5.7Buyers specifically wanting Zerto-based managed DRaaS bundled with broader hosting3.8/5 on G2 with pricing complaints, plus reviews as recent as January 2026 citing lingering support-quality impact from its 2022 ransomware incident
Full scoring detail: Gart scores highest on direct access (senior engineers reachable without a partner/account-manager layer), verified reviews (4.9/5 from 17 Clutch reviews), and named outcomes (25% cost reduction and 99.99% uptime in a published DR engagement). IBM Consulting scores second on the strength of a large, credible review sample (4.0/5 from 65 G2 reviews) even though "high pricing" is reviewers' most common complaint — see our full Gart vs. IBM Global Services head-to-head for the complete 8-criterion breakdown beyond just operations. Presidio publishes strong self-reported operational numbers (91% first-contact resolution, 99% of incidents resolved without client action, over $500M saved across managed cloud environments) but, as of this writing, doesn't have a public review platform with enough reviews to independently verify sentiment at scale — BC Partners' own portfolio page cites 6,660+ customers as its clearest published scale metric. Rackspace's G2 rating (linked above) reflects real strengths reviewers cite — reliable uptime, solid backup/email service — alongside real complaints about pricing (one reviewer cited a "near-400% price increase") and the incident-response aftermath described above; Rackspace's FY2025 revenue was $2,686 million, down 2% year over year.
Where the named competitors genuinely win
Multi-country enterprise footprint
IBM Consulting's ~160,000 consulting professionals across ~150 countries support simultaneous rollouts a boutique firm structurally cannot staff alone.[cite: 1]
AI-led NOC at large scale
Presidio's 24x7x365 service desk across 13 languages, with AI-assisted triage, is built for organizations with a large, geographically distributed support footprint.[cite: 1]
Bundled DRaaS with broad hosting
Rackspace's Zerto-based managed DRaaS is a genuine option for teams that want disaster recovery bundled with existing Rackspace-hosted infrastructure in one contract.[cite: 1]
Procurement requires an established global vendor
Some regulated industries and public-sector RFPs specify large, established providers as a formal requirement, independent of operational fit.[cite: 1]
Who Gart Solutions is the better fit for
Teams that already have infrastructure live and need an accountable ongoing operations partner, not another migration project.
Companies without an in-house SRE function that still need 24/7 monitoring, tested backups, and a real disaster recovery plan.
Buyers who've found large-provider support slow to reach or inconsistent after an incident, and want a named senior engineer instead.
Teams that want RTO/RPO set from an actual Business Impact Analysis rather than a generic template number.
Proof: Gart's published operations results
Multi-region AWS disaster recovery for an ESG AI platform
Gart implemented a multi-region AWS disaster-recovery architecture with Terraform-based infrastructure automation, cutting infrastructure cost by 25% while achieving 99.99% uptime during peak periods.
Read the full case study
$19,900 in savings from a centralized IT monitoring rebuild
For a global SaaS music platform, Gart implemented a centralized monitoring solution that improved infrastructure visibility and directly reduced avoidable AWS spend — the reliability discipline described above applied to a real environment.
Read the full case study
Questions to ask any infrastructure management company before you sign
What is my RPO and RTO for each critical system, in writing — not "we have disaster recovery" as a phrase?
When did you last actually test a full failover, not just confirm backups exist?
Who is the named engineer I reach during an incident, and how many people sit between me and them?
Can you show a specific, attributable outcome from a comparable engagement — not a company-wide average?
What happened the last time you had a major incident, and what changed afterward?
Get your infrastructure's real RTO/RPO baseline before you choose a partner
Gart Solutions runs infrastructure and SRE assessments that map your actual reliability, backup, and recovery gaps by system tier — then turns that baseline into a scoped remediation plan, not a generic sales pitch.
Book a free infrastructure assessment
You might also like
The Benefits of IT Infrastructure Outsourcing
IT Infrastructure Consulting Services
Top 30 Managed IT Service Providers for SMBs
Best Backup and DR Providers for Data Protection in Europe
Infrastructure Audit Services
Roman Burdiuzha
Co-founder & CTO, Gart Solutions · Cloud Architecture Expert
Roman has 15+ years of experience in DevOps and cloud architecture, with prior leadership roles at SoftServe and lifecell Ukraine. He co-founded Gart Solutions, where he leads cloud transformation and infrastructure modernization engagements across Europe and North America. In one recent client engagement, Gart reduced infrastructure waste by 38% through consolidating idle resources and introducing usage-aware automation. Read more on Startup Weekly.