← Back to blog
17 August 20266 min read

NIS2 SC10 and SC30: what do these classifications mean for suppliers?

SC10, SC20, SC30: a private quality mark, not a legal classification

Search for "NIS2 SC10" or "NIS2 SC30" and you'll find a specific three-tier scheme that emerged in the Netherlands under the name "NIS2 Supply Chain": SC10 (Basic), SC20 (Substantial) and SC30 (High). One thing to be clear on upfront: this is not a classification from the NIS2 directive itself, and not a legal category recognised by the EU or any national supervisory authority. It is a private quality mark, offered by several accredited audit providers, developed to give concrete shape to an obligation the directive states but does not specify further.

That underlying obligation sits in Art. 21(2)(d) of NIS2 (Directive (EU) 2022/2555): essential and important entities must assess and contractually secure the cybersecurity of their supply chain. The directive does not prescribe how — no fixed certificate, no fixed questionnaire. That gap is exactly where the SC10/SC20/SC30 mark fits in: it gives a supplier a concrete, auditable tier to demonstrate, and a buyer a fixed reference point to ask for.

Don't confuse the quality mark with a legal requirement. You are not obliged to obtain SC10, SC20 or SC30 to comply with NIS2 — a well-documented cybersecurity assessment of your own (see below) is equally valid evidence for most supplier relationships.

The three tiers in detail

SC10 (Basic) is the entry tier, for smaller suppliers with a limited risk profile who supply directly to a NIS2-obligated client — for example, a supplier without access to critical systems or sensitive data. The package covers roughly 17 concrete controls across organisation, people, physical security and technology, largely drawn from Annex A of ISO/IEC 27001.

SC20 (Substantial) is the mid tier, for suppliers with an elevated risk profile: more access to the client's systems or data, or a larger impact if disrupted. Requirements go further than SC10, with more emphasis on demonstrable implementation rather than policy on paper alone.

SC30 (High) is the heaviest tier, for critical links in the chain — suppliers whose disruption could cause significant impact at the client. This tier closely mirrors a full ISO/IEC 27001 certification, with explicit attention to governance, technical controls, monitoring and independent testing.

Which tier a client expects from you depends on three factors: your role in the chain (direct supplier or sub-subcontractor), the access you have to the client's systems or data, and the potential impact of a disruption on your side on the client's own service delivery.

A practical guide: which tier applies to you?

Step 1 — Ask your client. The fastest and most reliable route: a NIS2-obligated client has usually already determined which tier it expects from suppliers, often set out in the supplier contract or tender conditions.

Step 2 — Make your own estimate if your client doesn't specify a tier. Ask yourself: do you have direct access to the client's IT systems or sensitive data? Could a cyber incident on your side disrupt the client's service delivery? Do you supply critical components or services with no quick alternative? The more of these you answer "yes" to, the higher the tier (SC20 or SC30) likely expected.

Step 3 — Start with a gap analysis against the ten CY areas of a standard NIS2 assessment (see our NIS2 supply chain assessment step-by-step guide): risk policy, incident management, business continuity, supply chain security, secure development, vulnerability management, cyber hygiene, cryptography, access management and certifications. This is the same foundation both SC10/SC20/SC30 and a client's own questionnaire rely on.

Step 4 — Only then decide whether formal SC certification is worth pursuing. For a supplier serving one or two NIS2-obligated clients, a well-documented assessment of your own is often enough. If you supply dozens of NIS2-obligated clients, a single independent certificate saves you answering a different questionnaire over and over.

How the certification process works

Certification at any tier follows a fixed pattern: a gap analysis against the chosen tier's requirements, closing the gaps (drafting policy, setting up technical controls, documenting procedures), and finally an independent audit by an accredited provider. Self-declaration is not sufficient at any of the three tiers — that is exactly what sets the quality mark apart from a questionnaire you fill in yourself.

For SC10 and SC20, some audit providers conduct the audit directly themselves; SC30 certification typically runs through an external, independent certification body, similar to an ISO 27001 process.

Expect a structured process of several weeks to a few months, depending on how many of the underlying measures you already have in place — which is exactly why the gap analysis in step 3 above should be the starting point, not the audit itself.

How verified.supply helps

verified.supply does not itself certify an SC10, SC20 or SC30 mark — that remains the domain of accredited audit providers. What verified.supply does do: structure your NIS2 cybersecurity assessment across the same ten CY areas, so you have the documented foundation both a client questionnaire and a formal SC audit will ask for — a risk policy, an incident procedure, access management, and the rest, in one place instead of scattered across separate documents.

Once you've obtained an SC10, SC20 or SC30 certificate, register it as a certificate on your verified.supply profile (under Certificates & insurance), including its expiry date — visible to the clients who request it, with the same automatic expiry monitoring as your other certifications.

That way, one profile covers both the route of a client's own questionnaire and preparation for an independent SC certification — without building the same evidence twice.

Frequently asked questions

What is the difference between NIS2 SC10 and SC30?
SC10 (Basic) is the lightest tier, for smaller suppliers with limited risk. SC30 (High) is the heaviest tier, for critical links in the chain, closely mirroring a full ISO/IEC 27001 certification. SC20 (Substantial) sits in between.
Is an SC10 or SC30 certificate legally required under NIS2?
No. NIS2 itself (Art. 21(2)(d)) prescribes no fixed certification format. SC10/SC20/SC30 is a private quality mark — one way to demonstrate compliance, not the only way.
How do I know which SC tier fits my company?
Ask your client first — they have usually already determined which tier they expect. If they haven't, look at your access to their systems/data and the impact a disruption on your side would have on their service: the higher both, the higher the tier typically expected.
Can I replace an SC certificate with my own NIS2 cybersecurity assessment?
For many client relationships, yes — a well-documented assessment across the same ten CY areas is often sufficient evidence. Formal SC certification becomes valuable mainly once you supply multiple NIS2-obligated clients and don't want to answer a different questionnaire each time.

Read also

Build your VS profile (formerly VSME) once

Create an account and get started today.

No password needed — we email you a login link.