Twee mensen met koffiekopjes in een kantoor met een bruine leren bank en planten.

How Rotom Group achieved NIS2 Supply Chain SC30 across nine countries

Can you prove your cybersecurity is up to standard? That question will soon be on the table for more and more companies. Rotom Group already had the answer ready: the NIS2 SC30 certification.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Highlights of this success story

NIS 2 SC 30
Highest of the three levels
1 year
From GAP analysis to certification
9 EU countries
25 locations, 750 employees
Client
Rotom Group
Standards
Involved consultants

The reason

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

NIS2 requires more than just technical measures. It impacts governance, HR, procurement, and daily operations at every location. Discover how Rotom Group, with the help of Fendix and Tidal Control, gained control over a program spanning 25 locations and achieved the highest level of the NIS2 Supply Chain certification.

About Rotom Group

Rotom Group provides load carriers and logistics solutions from 25 locations across nine European countries, with approximately 750 employees. As CISO, Ronald van Beers is responsible for the group's digital infrastructure, cybersecurity strategy, and business continuity.

His mandate extends beyond monitoring the IT environment. Cybersecurity must permeate the entire organization, from the shop floor to the boardroom. From day one, this project was therefore much more than just an IT initiative.

"Cybersecurity is no longer just a technical topic. It is a necessary part of how we protect our operations, our customers, and the continuity of our organization."

- Ronald van Beers, CISO Rotom Group

Nine countries, one standard

The logistics sector is digitizing rapidly. Customers, suppliers, and internal teams are increasingly dependent on systems that must be available around the clock. For an organization with 25 locations, this is not an abstract risk, but a daily reality.

Rotom Group falls under NIS2 as an important entity. On top of that, there is a second driver: customers in the supply chain are also setting their own requirements, as every organization subject to NIS2 must assess its suppliers' cybersecurity. Rotom occupies both roles simultaneously: as an organization with its own duty of care, and as a link in the supply chains of others.

That made the choice of standard logical. The NIS2 Supply Chain certification translates the directive's requirements into concrete, verifiable measures. Rotom opted for SC30 High, the level for organizations where a cyber incident would cause major disruption in the supply chain. They didn't set the bar lower than necessary; they chose the level that fits their role.

Bringing structure to complexity

25 locations, nine jurisdictions, nine languages, and just as many ways of working. Disparate documents and action lists per location seem manageable until you aggregate them at the group level. Then, you are left with a patchwork that no one can manage centrally. "The challenge wasn't just understanding the NIS2 requirements, but primarily organizing the work in a way that could be managed consistently across the entire group," says Ronald van Beers, CISO at Rotom Group.

Rotom needed two things: subject-matter expertise to translate the requirements into concrete actions for each department and country, and a way to track those actions at the group level, with a clear owner for every task and real-time visibility into progress.

Getting started with NIS2?

Our NIS2 checklist outlines the most important requirements, from risk management to incident response. Download it for free and see at a glance what is expected of your organization.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Our approach

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Fendix for the content, Tidal Control for the management

Fendix provided the expert guidance, and Tidal Control provided the platform. This combination was a deliberate choice. In a program spanning nine countries, content without management stalls, and management without content results in a checklist that no one understands.

Fendix translated the SC30 requirements into what they concretely mean for IT, HR, procurement, and operations. From setting up the incident response process to awareness sessions for employees at the various locations. Always with the same approach: if people don't understand a measure, they won't implement it.

As a GRC platform, Tidal Control brought all actions, responsibilities, policies, deadlines, and evidence together in one place. Location managers could see exactly what was expected of them. Management tracked progress without having to constantly follow up. During the audit, the evidence was centrally available instead of scattered across mailboxes in nine countries. "The strength of this approach lay in the combination of expert guidance from Fendix and the structured project management that Tidal Control enabled," says Ronald van Beers, CISO at Rotom Group.

Tidal Control

The European compliance platform that immediately provides structure for your certification. With ready-to-use templates, it forms the central 'source of truth' for all your evidence and policies.

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare
  • 01

  • 02

  • 03

  • 04

  • 05

  • 06

  • 07

  • 08

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Next-Gen Consultant speaking

"With 25 locations, you can't dictate how things should work everywhere from a single office. We started with the people who would actually be doing the work and worked backward from there to meet the standard. That takes more time at the beginning, but you get measures in return that remain effective long after the audit."

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Jelle
van Onna
Information Security Consultant & Project Manager

The results

This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

NIS2 Supply Chain 30 and a foundation that lasts

After one year, Rotom Group completed the process and received the NIS2 Supply Chain SC30 High certificate. This demonstrates to customers, regulators, and supply chain partners that the measures from the standard have been demonstrably implemented.

What remains is more than just a certificate. There is clear ownership per department and per location, and awareness is now just as strong in HR and procurement as it is in IT.

The most significant difference is in how open actions and evidence are tracked. Where this was previously done per location, there is now one comprehensive overview. This made coordination between nine countries manageable and provided the flexibility to make adjustments in the lead-up to the audit.

"Certification is an important milestone, but the real value lies in the stronger foundation we have built for supply chain, cybersecurity, risk management, and business continuity."

- Ronald van Beers, CISO Rotom Group

"The strength of this approach lay in the combination of expert guidance from Fendix and the structured project management enabled by Tidal Control."

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Ronald van Beers
CISO & Group IT Director
"The strength of this approach lay in the combination of expert guidance from Fendix and the structured project management enabled by Tidal Control."

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Ronald van Beers
CISO & Group IT Director
This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

The sector is rapidly digitizing, and legislation is becoming stricter. The duty of care under the Cyber Security Act continues, even now that the certificate has been obtained. The structure now in place evolves along with it. "NIS2 is not a one-off project. It is part of a broader ambition to continuously strengthen our digital resilience," says Ronald.

Fendix remains involved as a knowledge partner for internal audits and the further strengthening of the cybersecurity program within the group. Tidal Control remains the central system for managing compliance, actions, and evidence.

Involved consultants

Jelle
van Onna
Information Security Consultant & Project Manager
This is a body. Lorem ipsum by sit amet, consecteur adipising elite. Suspendisse varius enim in eros elementum tristique. German course, mi quis viverra ornare

Kilian Houthuijzen

Commercial Manager

Kilian

Houthuijzen

Commercial Manager & Partner

Do your customers require demonstrable cybersecurity, or do you fall under the Cyber Security Act yourself?

Contact us for a free introduction.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Other success stories

ICT & Media
TAGGRS

How TAGGRS implemented ISO 27001 in 4 months

Healthcare
GGZ Western Noord-Brabant

How GGZ Westelijk Noord-Brabant structured information security

Enterprise
Heras

Heras achieves ISO 27001 certification within one year with worry-free implementation

Enterprise
Total Energies

How Total Energies Charging Solutions Netherlands obtained more than one certificate with the implementation of ISO 27001

ICT & Media
NO

Internal Audits: A Fresh Perspective on ISO 27001 at NOBEARS

Healthcare
Stap & Care Group

Towards ISO 27001 and NEN 7510 certification with Stap & Care Group

ICT & Media
Now Online

NowOnline's Choice for an Interim Security Officer from Fendix

ICT & Media
Nedscaper

With Nedscaper to an ISO 9001 and ISO 27001 certificate in 12 weeks

ICT & Media
SPL

From start-up to ISO 27001 and NEN 7510 certificate in 6 months

Healthcare
Aivory

How Aivory Achieved ISO 27001 and NEN 7510 in Three Months with Zero Findings

Enterprise
Goose VPN

Interactive cybersecurity week at GOOSE VPN