New: ISO 42001 and NIS2 Supply Chain are available in the Compliance Tool.Explore standards and requirements →Careers
NIS2-SC20 Substantial

NIS2-SC20 Substantial: make access and supply chain risks verifiable.

Examine what your role, system access and dependencies mean for the security of the service.

When is SC20 Substantial worth discussing?

Do you manage customer systems or work with sensitive information? Clarify which activities you carry out, what permissions are needed and what consequences an error or incident could have. This assessment supports the discussion about an appropriate level.

Confirm the choice with the client and assessor. Consider SC10 Basic for a lower risk profile and also discuss SC30 High if the customer’s requirements or supply chain dependencies warrant it. A job title or sector does not automatically determine the level.

Which scope questions should you answer?

  • Which customer systems and data can you access, and with what permissions?
  • Which activities are carried out remotely or by subcontractors?
  • What arrangements apply to changes, incidents and termination of the service?
  • Which of your own suppliers are needed to deliver the service?
  • Which checks does the customer carry out and which are your responsibility?

Record the service boundaries and interfaces. Assign responsibility for arrangements on both sides, so uncertainty about implementation does not only become apparent during an incident.

How do you make risk management verifiable?

Link the risk overview to controls and evidence of implementation. The following evidence file components offer practical preparation for a discussion with the assessor; they are not a complete list of SC20 requirements.

  • An overview of administrative privileges and recorded access reviews.
  • Change arrangements, with examples of approval and implementation.
  • An incident reporting route with roles, contact points and arrangements with the client.
  • Assessments of relevant suppliers and follow-up of concerns.
  • Evidence of agreed checks, with a date, owner and any corrective action.

Align documents, implementation and contractual arrangements. Include changes to the service so the evidence file reflects what is currently delivered.

How should you prepare for the SC20 assessment?

  1. Confirm the customer’s requirements, scope and current SC20 publications.
  2. Carry out an initial assessment and record missing controls and evidence.
  3. Allocate actions between process owners, IT, suppliers and DCA.
  4. Check with the employees involved whether arrangements are workable and followed.
  5. Agree the assessment procedure and availability of interviewees with the audit provider.

Do you already have SC10 or ISO 27001? Compare existing evidence against each SC20 requirement. Reuse what is relevant, but do not assume an existing certificate automatically covers the new scope or every requirement.

What does DCA provide and what remains internal?

DCA can help with gap analysis, planning, developing arrangements and audit preparation. The Compliance Tool supports the connection between requirements, risks, owners and evidence. The agreed work plan determines which implementation activities we take on.

You remain essential for organisational knowledge, approving arrangements, carrying out your own actions and making risk decisions. Budget for that time alongside software, support and external assessment. Use the pricing information as a starting point and request a separate quotation from the assessing body. Neither the lead time nor certification is guaranteed.

Frequently asked questions about NIS2-SC20 Substantial

Is SC20 mandatory for every IT supplier?+

Not simply because you are an IT supplier. Examine the risks of the service, the client’s requirements and the scheme requirements. Also assess separately whether statutory NIS2 obligations apply to your organisation.

Can we build on SC10?+

Existing information, controls and evidence may be useful. Compare them with the current SC20 requirements and intended scope, and record missing elements.

Who assesses whether our preparation is sufficient?+

You can review progress internally and engage support. Ultimately, the recognised assessing party examines whether you meet the applicable scheme requirements.

Official sources and scheme requirements

Use the scheme owner’s current publications for the full requirements and have the assessing party confirm the applicable version and assessment procedure.

Compare the NIS2 Supply Chain levels

NIS2 Supply ChainNIS2-SC10 BasicView level →NIS2 Supply ChainNIS2-SC30 HighView level →OverviewSelection, approach and supportView the overview →