What the three levels broadly represent
SC10 generally represents a basic set of security expectations, SC20 a more substantial level for relevant dependencies and SC30 a demanding level for highly critical or deeply interconnected suppliers. The exact requirements follow from the applicable standard or customer framework.
The level is a structured requirement set, not a substitute for understanding the service and its risk.
Why this matters for boards and procurement
Graded levels can make supplier requirements consistent and prevent every vendor from receiving the same heavy questionnaire. They also support governance by linking risk class, contractual requirements, evidence and review intensity.
Boards should understand how the highest-risk suppliers were identified and which exceptions remain.
The value and limits of the levels
They can support proportionality, contracting and evidence requests. They do not by themselves prove that controls operate, that the legal scope is correct or that continuity and incident cooperation work in practice.
Use service-specific evidence, reviews and exercises where the dependency warrants it.
Questions for the boardroom and audit committee
- Which supplier risk criteria lead to SC10, SC20 or SC30?
- Which critical suppliers have an exception or incomplete evidence?
- Does the required level cover the actual service and subcontractors?
- How are incident, continuity and exit arrangements tested?
- Which residual risks require acceptance or remediation?
Keep supplier requirements proportionate
Document the relationship between the supplier risk class and selected requirements. Provide a route for evidence, exceptions and remediation and review the classification when the service, access or dependency changes.
Frequently asked questions
Are SC10, SC20 and SC30 legal NIS2 entity categories?
No. They are graded supply-chain requirement levels and are distinct from essential and important entity categories.
Does SC30 proof replace supplier due diligence?
No. Review the service, evidence, exceptions, continuity and incident arrangements in context.
Who selects the level?
The customer should select and document the level based on supplier risk, dependency, access, impact and proportionality.
Choose proportionate requirements for each supplier
A focused discussion helps procurement, security and the board use SC10, SC20 and SC30 as risk-based tools with clear limitations.
Discuss the appropriate training route