New: ISO 42001 and NIS2 Supply Chain are available in the Compliance Tool.Explore standards and requirements →Careers
NIS2-SC10 Basic

NIS2-SC10 Basic: establish the foundations for your customer’s requirements.

From a client’s initial security question to concrete arrangements, implementation and a verifiable evidence file.

When should you discuss SC10 Basic?

Have you received your first request to demonstrate cybersecurity? First record which services you provide, what information you process and what access you have to the customer’s environment. The number of employees alone does not determine whether SC10 is appropriate.

Ask the client to clarify which certificate, scope and level they accept. For broader access or dependencies, also compare SC20 Substantial. Assessing statutory NIS2 obligations is separate from choosing this scheme.

Which foundations should you assess first?

Use the questions below to gather information for an initial assessment. They are practical considerations; the current scheme requirements determine the full assessment.

  • Which devices, accounts and software are used for the agreed service?
  • Who grants and terminates access, and who carries out updates?
  • Who can employees call if they suspect an incident?
  • What has been agreed about backups and information recovery?
  • Which security arrangements are employees and contractors aware of?

Also ask the IT supplier what is demonstrably carried out. A subscription or contract alone does not show that a particular check has taken place.

What evidence file should you prepare for the assessment?

Start with a description of the service, the systems involved and the division of responsibilities. Add the agreed controls, each with an owner, status and evidence location. Keep missing information visible as an open action.

  • A recorded account review with a date, reviewer and follow-up.
  • An overview of agreed update activities and the corresponding records.
  • A record of a recovery test, if this forms part of the agreed controls.
  • The incident reporting route and how employees have been informed about it.

These examples help demonstrate implementation. Agree with the assessor which evidence is needed for your scope and current scheme version.

How does preparation with DCA work?

  1. Gather the customer’s request and confirm the scope and intended level.
  2. Compare the current arrangements with the latest SC10 requirements.
  3. Allocate open actions between your team, IT supplier and DCA.
  4. Implement controls, check the evidence and update the file.
  5. Coordinate registration, audit preparation and assessment with the audit provider involved.

DCA can support the initial assessment, planning, development of arrangements and audit preparation. You provide organisational knowledge, make decisions and carry out your own agreed actions. The Compliance Tool helps keep tasks and evidence together. The independent assessment and certification decision are separate from our support.

What should you agree about resources and costs?

Agree the time needed for coordination, gathering information, implementation and checks. The extent of the service, existing arrangements and available people determine the schedule; there is no fixed lead time for every organisation.

Budget separately for software, support, your own time, improvements and external assessment. Explore DCA pricing and our implementation support. Ask the audit provider separately about the applicable costs and procedure.

Frequently asked questions about NIS2-SC10 Basic

Is SC10 automatically sufficient because we are a small business?+

No. Match the level to the risks of your service, the scope, current scheme requirements and the client’s acceptance criteria.

Can we prepare ourselves?+

You can gather information, implement controls and maintain the evidence file yourselves. Determine which knowledge and resources are available internally and which activities you may want support with.

Is a completed task list enough to obtain the certificate?+

No. Implementation must be demonstrable and is independently assessed against the applicable scheme. Software or support alone does not provide a certificate.

Official sources and scheme requirements

Use the scheme owner’s current publications for the full requirements and have the assessing party confirm the applicable version and assessment procedure.

Compare the NIS2 Supply Chain levels

NIS2 Supply ChainNIS2-SC20 SubstantialView level →NIS2 Supply ChainNIS2-SC30 HighView level →OverviewSelection, approach and supportView the overview →