When should you consider SC30 High?
Start with the specific service and the reason why a client requests SC30. What happens if there is an outage, loss of information or misuse of access? Describe the consequences for your own organisation and for customers who rely on the service.
Your own statutory NIS2 role and an SC30 certificate are different matters. Do not assume that the certificate covers every legal obligation or that the law automatically prescribes this level for every supplier. During the initial discussion, also compare SC20 Substantial and have the choice justified.
Which dependencies should you map?
- Which parts of the service would be difficult for the client to replace?
- Which platforms, subcontractors and other suppliers do you depend on yourselves?
- Who detects a disruption and who decides on escalation and recovery?
- What information and permissions are needed to restore the service?
- Which arrangements need to be coordinated between several parties during an incident?
Build a coherent overview of services, dependencies, responsibilities and risk decisions. Discuss assumptions with the parties involved rather than recording them solely in your own policy document.
What evidence demonstrates effectiveness?
Organise the evidence file around the chosen scope. Practical examples to gather and discuss in advance include:
- Approved risk decisions and recorded responsibilities for the service.
- Records of agreed checks on access, changes and security.
- Results of recovery or incident exercises, including open improvement actions.
- Assessments and arrangements for important supply chain dependencies.
- Periodic decisions on progress and evidence that identified shortcomings have been followed up.
These are preparation examples, not a complete account of SC30. Link each piece of evidence to the applicable scheme requirement, date and owner, and have the assessing party confirm the depth required.
How should you organise audit preparation?
- Confirm the level, scope and current scheme version with the client and assessor.
- Compare existing controls and evidence with those requirements.
- Plan implementation and checks with the teams and suppliers involved.
- Make interviewees and evidence available for independent assessment.
- Agree how findings, changes and future assessments will be followed up.
Check in advance whether the audit provider is recognised for this level. Have the procedure, registration, preparation and arrangements for subsequent assessments confirmed in writing. The independent assessor and certification decision are separate from DCA’s support.
An existing ISO 27001 certificate or SC20 evidence file may contain relevant information. Its usefulness depends on the scope, how current it is and the requirements being assessed.
What support and costs should you agree?
DCA can support analysis and planning, help develop arrangements and prepare the evidence file for assessment. With the Compliance Tool you keep tasks, owners and evidence together. Explore implementation support for the possible division of responsibilities.
Management and process owners remain responsible for information, risk decisions and their own actions. Also plan for input from the suppliers involved. List software, support, internal time, improvements and external assessment separately in the proposal; see DCA pricing. The agreed scope determines the resources required, without a guaranteed timeframe or certificate.
Frequently asked questions about NIS2-SC30 High
Does SC30 mean we fully comply with NIS2?+
No. The certificate relates to the chosen scheme and assessed scope. Legal applicability and obligations must be examined separately.
Can we use existing ISO 27001 documentation?+
Yes, if the information matches the SC30 requirement and intended scope. Check that it is current and supported by evidence of implementation, and record any additions needed.
Should our suppliers be involved in preparation?+
Involve suppliers when their services, information or activities are needed to demonstrate your controls. Make clear in advance which arrangements and evidence you need from them.
Official sources and scheme requirements
Use the scheme owner’s current publications for the full requirements and have the assessing party confirm the applicable version and assessment procedure.
