New: ISO 42001 and NIS2 Supply Chain are available in the Compliance Tool.Explore standards and requirements →Careers
NIS2 Supply Chain

NIS2 Supply Chain: demonstrate security across your supply chain.

Are clients setting security requirements for your organisation? First establish which services, risks and evidence are central to the request, then choose the appropriate level.

Customer requirements, certification scheme and legislation

A client may set security requirements for suppliers even when the supplier itself is outside the scope of the legislation. Ask which scheme, level, scope and type of assessment the client accepts. The scheme owner describes NIS2 Supply Chain as an approach with three levels.

Assess the legal scope separately through the requirements check and current official information. The scheme is not the same as the NIS2 Directive and provides no general exemption from legal obligations.

SC10, SC20 and SC30: which level fits?

The choice follows from the risks of the service and the arrangements with the client. The explanation below is a starting point for discussion, not a complete account of the scheme requirements. Have the assessing body confirm the current requirements and assessment method in advance.

NIS2-SC10 Basic

Discuss this basic level for a service with a lower risk profile. Make clear which services you provide, which security arrangements apply and what supporting evidence is available.

NIS2-SC10 Basic: scope, evidence and preparation

NIS2-SC20 Substantial

Consider this level when the service entails greater risk, for example through access to systems or sensitive information. Make dependencies and responsibilities with the client explicit.

NIS2-SC20 Substantial: scope, evidence and preparation

NIS2-SC30 High

Discuss this level for critical dependencies where disruption could have major consequences for the client. Build a coherent picture of continuity, recovery and supply chain arrangements.

NIS2-SC30 High: scope, evidence and preparation

Record the chosen scope in writing. A level is not a general classification of the entire organisation and says little about a particular service without a scope.

From customer requirements to demonstrable controls

  1. Gather the customer’s request, contractual requirements and intended scope.
  2. Confirm the scheme, level and assessment method with the parties involved.
  3. Conduct a gap analysis and assign an owner to each missing control.
  4. Implement the controls and gather supporting evidence.
  5. Prepare for independent assessment and follow up findings.
  6. Update the evidence file when services, suppliers or risks change.

Use existing risk analyses and evidence from ISO 27001 where appropriate. Check each requirement to establish whether that evidence is also sufficient for the chosen scheme. Read more about NIS2 and supply chains.

What does DCA do and what does your team do?

With the Compliance Tool you bring requirements, risks, tasks, documents and evidence together. Through implementation support DCA helps with the gap analysis, plan, adaptation of documents and preparation for assessment. The agreed division of responsibilities determines how much implementation we take on.

  • Your management: defines the scope, allocates time and decides on risks and priorities.
  • Your team: provides process knowledge, implements agreed controls and gathers evidence from day-to-day practice.
  • DCA: helps structure, develop and follow up the work. An internal audit is assigned an independent assessor who does not approve their own work.
  • Certification body: conducts the external assessment independently as part of a certification process and makes the certification decision.

The support results in agreed controls, owners and a verifiable evidence file for the chosen scope. Certification depends on independent assessment; software or support alone is not a certificate.

What costs and resources should you agree?

Have software, support, internal implementation and external assessment listed separately in the proposal. Use the DCA service pricing as a starting point; an assessing body determines its own scope and costs. The client, available controls and chosen assessment also influence what is needed.

For a useful initial discussion, bring the customer’s request, a description of the service, existing certificates and known areas for improvement. We help make the next steps and allocation of responsibilities concrete.

Frequently asked questions about NIS2 Supply Chain

Is NIS2 Supply Chain the same as NIS2?+

No. It is a separate certification scheme. The NIS2 Directive and applicable national legislation must be assessed separately.

Which level should I choose?+

Match it to the risks of the service, the customer’s requirements and the current scheme requirements. Have the scope and assessment method confirmed before starting a project.

Can I use existing ISO 27001 documentation?+

Existing controls and evidence can help. Check each scheme requirement to establish what can be reused, what is missing and whether the scope matches.

Official sources

Sources consulted on 19 September 2026. Use the current standard or scheme requirements for implementation.