Implementation

Fendix launches NIS2 Supply Chain implementations

NIS2
Legislation
Implementation
Information Security

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

At Fendix, we have started the first steps for implementing the NIS2 Supply Chain Certificate (formerly NIS2 Quality Mark). The NIS2 Supply Chain Certificate (NIS2 SC) is a label developed in response to the European NIS2 Directive. We spoke to our colleague Jelle, Senior Consultant at Fendix, to discuss how he experiences it.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
14.07.2026
Written by
Gijs
Nabuurs
Information Security Consultant & Marketing Specialist

What is a NIS2 Supply Chain certificate?

The European NIS2 directive emphasizes digital security and supply chain responsibility. In the Netherlands, this is being translated into the Cyber Security Act. Are you a NIS2-regulated organization? If so, not only must your organization be secure, but so must all organizations within your supply chain. With the NIS2 Supply Chain certificate , suppliers to NIS2-regulated organizations can demonstrate that their cybersecurity is in order.

 

The certification works with three levels:

 

  • SC10 (Basic) – the baseline measures for organizations with a lower risk profile
  • SC20 (Substantial) – for organizations with higher risks, where Operational Technology (OT) is also included
  • SC30 (High) – the highest level, for organizations in critical supply chains or where the impact of incidents could be significant

How does the implementation process work?

Jelle explained how we approach such a project at Fendix. The process is very similar to an ISO 27001 project, but with OT as a key addition for SC20 and SC30.

 

“We always start with a GAP analysis. This allows us to map out where the organization currently stands and where the gaps still lie," says Jelle.

At the organization where Jelle is currently active, there was no ISO 27001-certified ISMS implemented yet. Someone was hired to set up all the documentation, while we use the gap analysis to identify and prioritize the pain points.

 

“Once the risk analysis is complete, we get to work on drafting and implementing policies and measures. Think of technical solutions, processes, and clear responsibilities," Jelle explains.

According to the NIS2 Supply Chain High certificate (NIS2 SC 30), organizations must, for example:

 

  • use a procedure and a checklist to ensure that employees and contractors return company assets (such as laptops, phones, keycards, and keys) upon the termination or modification of their employment contract (1.8);
  • implement a procedure to ensure that access rights are granted, modified, and removed appropriately (1.14);
  • ensure that employees and contractors sign a non-disclosure agreement, stipulating that confidential information exchanged during the collaboration may not be disclosed to third parties (2.5);
  • logging and analyzing relevant events (4.11);
  • establishing and applying rules based on a risk assessment that clarify when stored and transmitted information must be secured with a specific form of cryptography (4.12).

 

OT components often require a great deal of extra attention because these systems are directly intertwined with business processes. Another key component is awareness and support. Digital security is not just an IT issue, but a matter for the entire organization. “Employees need to know what their role is and why certain measures are necessary,” says Jelle.

Another challenge

The implementation of the Dutch NIS2 Directive (Cybersecurity Act) will take effect on August 15, 2026. Because the introduction of NIS2 has been delayed, many organizations are taking a wait-and-see approach. “That is risky,” Jelle believes. “It means a sense of urgency isn't developing quickly enough within organizations.”

Why is this important?

A NIS2 Supply Chain certificate shows that you are taking digital security seriously. Customers, partners, and regulators are increasingly asking for demonstrable assurance. Without a plan B or an exit strategy, you are dependent, and if things go wrong, the consequences are not just technical, but also operational and reputational. The certification therefore helps you gain control over that responsibility step-by-step, at a level that suits your organization.

The first projects have started

At Fendix, we have already begun our first NIS2 supply chain implementations. Our consultants guide organizations through every step, from gap analysis to policy development, implementation, and maintenance. We have found that even organizations without ISO 27001 certification can make significant progress when provided with the right tools.

Want to learn more?

Would you like to know which level (SC10, SC20, or SC30) is right for your organization? Or perhaps you want to know where you currently stand and what you need to get started? We are happy to help.

 

Feel free to contact us below for a no-obligation consultation. Together, we can determine the best approach for your organization.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

thru
Mathijs
Download
Implementation

7 criteria for choosing the right ISO implementation partner

thru
Gijs
Download
Security Awareness

Create behavioral change and increase security awareness

thru
Ruben
Download