.avif)
Fendix launches NIS2 Supply Chain implementations
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

What is a NIS2 Supply Chain certificate?
The European NIS2 directive emphasizes digital security and supply chain responsibility. In the Netherlands, this is being translated into the Cyber Security Act. Are you a NIS2-regulated organization? If so, not only must your organization be secure, but so must all organizations within your supply chain. With the NIS2 Supply Chain certificate , suppliers to NIS2-regulated organizations can demonstrate that their cybersecurity is in order.
The certification works with three levels:
- SC10 (Basic) – the baseline measures for organizations with a lower risk profile
- SC20 (Substantial) – for organizations with higher risks, where Operational Technology (OT) is also included
- SC30 (High) – the highest level, for organizations in critical supply chains or where the impact of incidents could be significant
How does the implementation process work?
Jelle explained how we approach such a project at Fendix. The process is very similar to an ISO 27001 project, but with OT as a key addition for SC20 and SC30.
“We always start with a GAP analysis. This allows us to map out where the organization currently stands and where the gaps still lie," says Jelle.
At the organization where Jelle is currently active, there was no ISO 27001-certified ISMS implemented yet. Someone was hired to set up all the documentation, while we use the gap analysis to identify and prioritize the pain points.
“Once the risk analysis is complete, we get to work on drafting and implementing policies and measures. Think of technical solutions, processes, and clear responsibilities," Jelle explains.
According to the NIS2 Supply Chain High certificate (NIS2 SC 30), organizations must, for example:
- use a procedure and a checklist to ensure that employees and contractors return company assets (such as laptops, phones, keycards, and keys) upon the termination or modification of their employment contract (1.8);
- implement a procedure to ensure that access rights are granted, modified, and removed appropriately (1.14);
- ensure that employees and contractors sign a non-disclosure agreement, stipulating that confidential information exchanged during the collaboration may not be disclosed to third parties (2.5);
- logging and analyzing relevant events (4.11);
- establishing and applying rules based on a risk assessment that clarify when stored and transmitted information must be secured with a specific form of cryptography (4.12).
OT components often require a great deal of extra attention because these systems are directly intertwined with business processes. Another key component is awareness and support. Digital security is not just an IT issue, but a matter for the entire organization. “Employees need to know what their role is and why certain measures are necessary,” says Jelle.
Another challenge
The implementation of the Dutch NIS2 Directive (Cybersecurity Act) will take effect on August 15, 2026. Because the introduction of NIS2 has been delayed, many organizations are taking a wait-and-see approach. “That is risky,” Jelle believes. “It means a sense of urgency isn't developing quickly enough within organizations.”
Why is this important?
A NIS2 Supply Chain certificate shows that you are taking digital security seriously. Customers, partners, and regulators are increasingly asking for demonstrable assurance. Without a plan B or an exit strategy, you are dependent, and if things go wrong, the consequences are not just technical, but also operational and reputational. The certification therefore helps you gain control over that responsibility step-by-step, at a level that suits your organization.
The first projects have started
At Fendix, we have already begun our first NIS2 supply chain implementations. Our consultants guide organizations through every step, from gap analysis to policy development, implementation, and maintenance. We have found that even organizations without ISO 27001 certification can make significant progress when provided with the right tools.
Want to learn more?
Would you like to know which level (SC10, SC20, or SC30) is right for your organization? Or perhaps you want to know where you currently stand and what you need to get started? We are happy to help.
Feel free to contact us below for a no-obligation consultation. Together, we can determine the best approach for your organization.
.avif)

.avif)

















