NIS2 Quality Mark
If, as a supplier, you want to be able to demonstrate that you work securely digitally then it is NIS2 Quality Mark available.
DigiTrust is available as a selected specialist to audit and certify your organisation.
Assessing your information security management system is our core business. We have our own team of auditors, who look closely at the context of your organisation.
- Specialist for all NIS2 Quality Mark audits and certificates
- QM10, QM20 and QM30
- In-house auditors who understand the context of your organisation
- Sharp prices
More than 500 organisations have already gone before you.
![Certification process - DigiTrust - ISO 27001 Certification - NEN 7510 Certification - ISO 9001 certification - ISO 14001 Certification](https://www.digitrust.nl/wp-content/uploads/2022/05/IMG_4921-scaled-1-2048x1536.jpeg)
NIS2 Quality Mark certification
On 10 October 2024, the Quality Innovation Foundation, the holder of the NIS2 Quality Mark launched the NIS2 Quality Mark European. The NIS2 legislation describes that essential and important companies, also known as NIS2 companies, are responsible for the cyber security of their supply chain. This means that they have to start requiring their direct suppliers, mostly SMEs, to be able to demonstrate that they work securely digitally. An NIS2 Quality Mark certificate provides this proof.
In the Netherlands, the European NIS2 has been translated into the Cyber Beveiligingswet (CBW) as a replacement for the Wbni. Each country has thus made its own translation into its own local legislation. So each country has its own specific websites and information .
NIS2 organisations and their suppliers
NIS2 Quality Mark has 3 levels, tailored to the risk of the service provided.
- NIS2-QM10 (Basic)
- NIS2-QM20 (Substantial)
- NIS2-QM30 (High)
![NIS2 guideline - Quality Marks](https://www.digitrust.nl/wp-content/uploads/2024/10/NIS2-QM-grafiek-scaled.jpg)
The different levels
Within the NIS2 Quality Mark, there are 3 levels.
NIS2-QM10 Basic Level
- Organisational control measures
- People-centred management measures
- Physical management measures
- Technological management measures
Download the full QM10 requirements here <link>
NIS2-QM20 Substance Level
- Organisational control measures
- People-centred management measures
- Physical management measures
- Technological management measures
- OT management measures
- IT management measures
Download the full QM20 requirements here <link>
NIS2-QM30 High Level
Which NIS2 Quality Mark is applicable to your organisation?
What type of organisation are you?
Suppliers
Quality Mark 10 (QM10)
Quality Mark 20 (QM20)
- Availability (is the system there or not),
- Integrity (is the data in the systems correct) and the
- Confidentiality (is it well regulated who may or may not see what)
Quality Mark 30 (QM30)
How long does a certification audit take?
A table is available, detailing how much audit time is required per standard for each type of organisation. Depending on your context, the audit time within the range may be lower or higher.
Source: website NIS2 Quality Mark
note; if you already have an ISO27001/NEN7510 certification, you will be granted a waiver on specific requirements already covered within this certification. This therefore reduces the number of audit hours in the table above.
How do you apply for NIS2 Quality Mark certification?
If you believe you meet all the requirements of the NIS2 Quality Mark, DigiTrust is authorised to conduct an audit at your premises. Contact us to start this certification.
If the audit is completed positively by DigiTrust, the Quality Innovation Foundation will prepare and publish the certificate for you. There will be a central register of this.
The certificate is valid for 3 years.
Contact us for a no-obligation quote.