Information Security

NIS2 Supply Chain: proof that your cybersecurity is on point

NIS2
Information Security
Implementation
Supply Chain

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The NIS2 directive requires organizations that fall under this legislation to ensure not only their own cybersecurity, but also that of their entire supply chain. This means that companies that deliver to NIS2 organizations must be able to demonstrate that they work digitally securely. On October 10, 2024, the Quality Innovation Foundation therefore officially launched the NIS2 Supply Chain Certificate (formerly NIS2 Quality Mark) in Europe.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
14.07.2026
Written by
Gijs
Nabuurs
Information Security Consultant & Marketing Specialist

Important update: Cyber Security Act takes effect on August 15, 2026

The Cyber Security Act, the Dutch implementation of the European NIS2 Directive, replaces the current Network and Information Systems Security Act (Wbni) and introduces stricter cybersecurity requirements for organizations across 18 essential and important sectors. These include energy, drinking water, digital infrastructure, healthcare, government, and transport. As of August 15, 2026, new obligations will apply to approximately 10,000 organizations in the Netherlands. And that is just the tip of the iceberg, as the law also extends through the supply chain. Are you a supplier to an organization covered by the act? Then you will be affected through your client. This is expected to involve tens of thousands of suppliers.

What is the NIS2 Supply Chain certificate?

The NIS2 Supply Chain certificate is a quality mark demonstrating that your organization meets the cybersecurity requirements of the NIS2 Directive (in the Netherlands: the Cyber Security Act). This mark helps you prove to clients and partners that you comply with the required security standards. The system consists of three levels: SC10 (basic level), SC20 (substantial level) and SC30 (high level), allowing organizations to implement measures tailored to their specific risks and business activities. The higher the level, the more requirements apply to your organization. As shown in the table below, an ISO 27001 certificate is more than sufficient to meet all levels of the NIS2 Supply Chain certificate (QM = SC).

1. Overview: NIS2 Supply Chain certificate vs. ISO 27001

Why is the NIS2 Supply Chain certificate important?

NIS2 places the responsibility for supply chain security on NIS2 organizations. They must ensure that their suppliers also implement the appropriate cybersecurity measures. For suppliers, this means they must be able to prove that their security is in order. The NIS2 Supply Chain certificate provides this assurance and makes NIS2 compliance demonstrable. The greater the impact of your services on clients, the more requirements you must meet.

The three levels of the NIS2 Supply Chain certificate

SC10 – Basic measures

This level focuses on fundamental security measures such as:

  • Cybersecurity policy with clear responsibilities.
  • Multi-factor authentication and strict access rights.
  • Incident management and monitoring.
  • Regular updates and malware protection.
  • Employee awareness and training.

Does your organization provide services to a NIS2-regulated company, but are you not subject to registration yourself? Then SC10 is usually sufficient to demonstrate that you have the basics of cybersecurity in order. This applies to most SMEs. Download here all requirements within the SC10.

SC20 – Comprehensive security

In addition to the SC10 requirements, extra measures apply such as:

  • Information classification and stricter data security.
  • Security requirements in supplier contracts.
  • Stricter monitoring and control of user accounts.
  • Encryption and secure communication channels.
  • Regular internal audits of security measures.

Does your organization provide ICT or OT services ? If so, your client may require SC20 or even SC30 . This depends on the risk and the impact of your service on the availability, integrity, and confidentiality (AIC) of their systems. Download here all requirements within SC20.

SC30 – Advanced cybersecurity

The highest level with additional control measures such as:

  • Management and security of OT systems.
  • Strict requirements for cloud services and suppliers.
  • Secure software development and application testing.
  • Procedures for digital forensic evidence.
  • Independent external security audits.

Does your organization fall directly under the NIS2 legislation and are you required to register? Then SC30 is the minimum requirement. In addition, supplementary certification, such as ISO 27001, NEN 7510, or IEC 62443, is strongly recommended. Download here all requirements within the SC30.

How long does a certification audit take?

The table below shows how long a certification audit for the NIS2 Supply Chain certificate takes (QM = SC). Do you already have ISO 27001 or NEN 7510 certification? If so, you will be exempt from specific requirements already covered by those standards. The certificate is valid for 3 years and is issued by the Stichting Kwaliteitsinnovatie, which also publishes the certificate in a central register.

2. Overview: audit time in hours per organization

How can we help?

Do you want to know where your organization stands and what steps are needed to comply with the Cyber Security Act or to obtain the NIS2 Supply Chain certificate ? Or would you like immediate insight into your cybersecurity status and to be prepared for NIS2 requirements? Feel free to contact us and discover how we can help you. 🚀

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

NIS2

Cybersecurity Act effective August 15, 2026: what you need to know

thru
Henry
Kennisartikel
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

thru
Mathijs
Download
Legislation

Does the Cyber Security Act (NIS2) apply to me?

thru
Mathijs
Download