
RDI Sets the Tone: Supply Chain Security is No Longer an Option
With the advent of the Cybersecurity Act, supply chain security explicitly becomes part of the statutory duty of care. The Netherlands Authority for Digital Infrastructure (RDI), designated as the future supervisor, leaves no doubt about this: organizations must demonstrably gain control over their digital supply chain. Read more
With the advent of the Cybersecurity Act, supply chain security explicitly becomes part of the statutory duty of care. The Netherlands Authority for Digital Infrastructure (RDI), designated as the future supervisor, leaves no doubt about this: organizations must demonstrably gain control over their digital supply chain.
Cybersecurity does not stop at an organization's own IT environment. Those who depend on suppliers, service providers, and technology partners are also dependent on hún security level. This exact point is explicitly highlighted by the RDI — and forms a core component of future supervision.
What does the RDI explicitly say about supply chain security?
The RDI makes it clear that organizations falling under the Cybersecurity Act remain responsible for risks entering through their supply chain. This specifically means that organizations must:
- have insight into their suppliers and service providers
- identify and assess risks in the supply chain
- take appropriate measures to manage those risks
- be able to demonstrably prove all of this to the supervisor
The message is clear: no insight means no control, and no control means not complying with the duty of care.
Supply Chain Security is a Management Responsibility
An important point explicitly emphasized by the RDI is that supply chain security is not purely an IT issue. The responsibility explicitly lies with the board and management. They must make choices about which risks are acceptable, determine which suppliers are critical to the organization, and ensure that responsibilities are clearly assigned. After all, the supply chain directly impacts the organization's continuity, the societal impact of disruptions, and compliance with laws and regulations. Thus, supply chain security is an integral part of governance and integrated risk management.
From Paper Policy to Demonstrable Implementation
The RDI makes it clear that policy alone is not enough. Organizations must be able to demonstrate in practice how they manage their supply chain. This means having insight into which suppliers are involved, what role they play in critical processes, what risks are associated with them, and how these risks are actively monitored. A one-time inventory is not sufficient. Threats, vulnerabilities, and dependencies are constantly changing, and the RDI's supervision adapts to this dynamic.
This is where RiskStudio directly connects. The platform helps organizations to systematically identify, organize, and continuously monitor suppliers for digital risks. This is not done through questionnaires or snapshots, but based on objective and current cyber information.
Monitoring Becomes Indispensable Under Supervision
The RDI explicitly states that organizations must not only assess their supply chain but also continuously monitor it. New vulnerabilities at suppliers, major cyber incidents in the supply chain, and changes in digital exposure can quickly increase risks. Without continuous monitoring, it is impossible to make timely adjustments and to demonstrate to the supervisor that the duty of care is being taken seriously.
This is precisely where RiskStudio provides support. With 24/7 monitoring, incident detection, and up-to-date cyber ratings, organizations gain continuous insight into the risks in their supply chain, including the ability to benchmark suppliers against each other.
Suppliers Will Also Notice This
The RDI makes it clear that the obligations do not stop with the primary organization. Suppliers will also feel the effects of the Cybersecurity Act. They will receive more frequent questions about their digital resilience, must account for stricter requirements from customers, and are expected to be more transparent about incidents. As a result, structural monitoring is increasingly becoming part of collaborations. Cyber resilience is thus developing into a strict prerequisite for continuing to do business.
Conclusion: RDI Makes Supply Chain Security Enforceable
The RDI's message is clear and directive: organizations are responsible for their digital supply chain and must demonstrably have it under control.
Supply chain security is no longer a future ambition but a concrete component of supervision under the Cybersecurity Act. Organizations that start now with insight, structure, and monitoring will not fall behind but will be ahead of the supervision.
Source: https://www.rdi.nl/onderwerpen/cyberveiligheid/cyberbeveiligingswet/toeleveringsketen