Article
17 Sept 2026
Workforce Cyber Readiness in the NIS2 Supply Chain
A practical guide to keeping workforce cyber-readiness status current and verifiable across staffing agencies, suppliers and client organisations under NIS2 and the Cyberbeveiligingswet.

A practical framework for current, verifiable workforce status across flexible labour and supplier relationships
EdXactly White Paper
September 2026
The workforce moves across organisational boundaries faster than most evidence systems do.
Executive summary
The Cyberbeveiligingswet has been in force in the Netherlands since 15 August 2026.[1] It brings the European NIS2 framework into Dutch law and strengthens expectations around cybersecurity risk management, governance, supply-chain security, cyber hygiene and the effectiveness of controls.[2][3]
For many organisations, the technical and governance layers are already familiar.
Security operations teams manage systems, telemetry and incidents. GRC and third-party risk platforms manage frameworks, controls, policies, risks and suppliers.
A different problem appears when the organisation depends on people who sit outside its permanent workforce.
Agency workers, contractors, supplier personnel and other flexible workers can move between clients, sites and assignments without belonging permanently to any one client's HR, identity or learning environment. Their organisational relationship can change faster than a monthly spreadsheet, certificate bundle or manually maintained LMS record.
That creates a specific evidence question:
Which relevant people currently hold the workforce cyber-readiness status required for the work they are doing?
This is not the same as asking whether a supplier has a policy, whether a security control exists, or whether a person completed an activity in the past.
The workforce layer needs to connect seven things:
Population — who is relevant?
Connection — which organisation-worker relationship is active?
Requirement — what readiness status applies?
Status — has the worker earned it?
Currency — is it still valid now?
Verification — can an authorised party check it?
Lifecycle — what happens when the worker leaves, returns, expires or is revoked?
This paper sets out a practical framework for that layer.
It also makes an important boundary clear: workforce-readiness evidence can support NIS2/Cbw risk management and supplier demonstrability, but it does not by itself determine legal scope, certify compliance, replace technical cybersecurity measures or transfer responsibility between organisations.
Scope of this paper
This paper focuses on workforce cyber-readiness evidence in environments where people cross organisational boundaries.
It is particularly relevant to:
staffing agencies;
workforce suppliers;
contractors;
operators using multiple suppliers;
sites with high worker turnover;
organisations that rely on external personnel with access to systems, information or operational environments.
It is not a general guide to every NIS2/Cbw obligation.
It does not claim that:
every supplier is automatically subject to the Cyberbeveiligingswet;
every external worker needs the same programme;
every staffing relationship creates the same cyber risk;
one worker credential establishes legal compliance;
a workforce register replaces a GRC, ISMS, SOC, IAM or third-party risk platform.
The legal and risk analysis remains organisation-specific.
The purpose here is narrower:
to define the evidence problem that appears when workforce status has to remain current across suppliers, clients and changing assignments.
1. The supply chain has a human edge
Cyber supply-chain risk is usually discussed in terms of technology.
The familiar objects are:
software;
cloud providers;
managed services;
network dependencies;
ICT suppliers;
vulnerabilities;
third-party systems.
Those are essential parts of the risk picture.
But many services are delivered through people.
A supplier may provide personnel who:
enter a client site;
use client systems;
handle client information;
use scanners, terminals or shared workstations;
receive access credentials;
operate around production or logistics technology;
change frequently.
The supplier relationship may be stable while the individual workforce inside that relationship changes every day.
That creates a distinction that traditional supplier governance does not always capture:
the organisation boundary and the workforce boundary are not the same.
A client may know that Supplier A is approved.
It may still need to know:
Which people from Supplier A are relevant today, and what is their current status?
That is a worker-level evidence problem inside an organisation-level supplier relationship.
Figure 1 — The missing workforce layer
The three layers solve different problems.
The workforce layer should integrate with the others where useful. It should not pretend to replace them.
2. What the Cyberbeveiligingswet changes
The Cyberbeveiligingswet entered into force on 15 August 2026.[1]
The NCSC describes ten duty-of-care measures and makes clear that organisations remain responsible for determining which measures are appropriate, with risk management as the basis.[2]
Three areas are particularly relevant to this paper.
2.1 Supply-chain security
The NCSC identifies supply-chain security as one of the duty-of-care measures and advises organisations to include chain risks in risk management, map direct suppliers and strengthen supplier resilience through dialogue and appropriate measures.[2]
The NCSC also states that a Cbw organisation can require cybersecurity measures from direct suppliers and service providers where the relationship is relevant to its network and information-system risks.[4]
That point requires precision.
It does not mean every supplier automatically inherits the client's Cbw obligations.
NCSC guidance explicitly treats supplier impact as risk-dependent. A supplier whose products, services or access can affect a Cbw organisation's network and information systems is more likely to become part of that chain-risk analysis.[4]
For workforce suppliers, the relevant question is therefore not:
“Are staffing agencies automatically subject to the client's obligations?”
It is:
“Does the supplied workforce create a relevant cybersecurity relationship, and if so, what evidence will the client reasonably require?”
That answer depends on the actual work, access, systems, information and risk.
2.2 Cyber hygiene and safe behaviour
The NCSC's Cbw guidance identifies cyber hygiene and cybersecurity training as a separate duty-of-care measure.[2]
Its broader guidance on safe digital behaviour also emphasises that knowledge alone is not enough and that organisations should understand the actual behavioural problem they are trying to solve, measure interventions and combine human and technical measures.[5]
The practical implication for workforce evidence is straightforward:
a record that an activity occurred is useful, but it is not the entire risk-management story.
2.3 Personnel and access security
The NCSC also identifies personnel, access policy and asset management as a Cbw duty-of-care area.[2]
That is relevant because external and flexible workers often sit exactly where these topics meet:
personnel relationship;
access;
system use;
changing assignments;
onboarding and offboarding.
A workforce-readiness layer should therefore complement, rather than blur, the distinction between:
who the person is;
what access the person has;
what readiness status the person currently holds.
3. The workforce boundary changes faster than the evidence
Permanent employees usually fit inside a relatively coherent organisational identity model.
They tend to have:
an HR record;
corporate identity;
email;
LMS profile;
access-management lifecycle;
stable organisational ownership.
Flexible workforces behave differently.
A worker may:
spend two weeks at one client;
move to another site;
disappear for several months;
return through the same staffing agency;
work under a different assignment;
use a different client system;
never receive a permanent client identity.
That creates two common evidence patterns.
Pattern A — duplicate the worker into every client environment
The client creates:
another directory identity;
another LMS profile;
another credential;
another offboarding obligation.
This can be appropriate where the worker genuinely needs system access.
But it creates unnecessary identity sprawl when the account exists mainly to carry evidence.
Pattern B — keep the evidence outside the client environment
The supplier sends:
spreadsheets;
certificates;
screenshots;
LMS exports;
email attachments.
This reduces account creation, but creates evidence sprawl.
The data is often correct only at the moment it was generated.
Neither pattern fully solves the current-status problem.
A third model is possible:
maintain the workforce status in a live register, connect it to the relevant organisational relationship, and let authorised parties verify the current state when needed.
Figure 2 — From duplicated identities to one current workforce layer
The point is not that client identities disappear.
The point is that readiness evidence should not be the reason another unnecessary identity is created.
4. Seven questions a workforce evidence system should answer
A workforce cyber-readiness model does not need to begin with technology.
It can begin with seven questions.
1. Population
Who is actually relevant?
The population may include:
permanent employees;
agency workers;
contractors;
supplier personnel;
temporary site workers;
seasonal workers.
Not every person will have the same cyber relevance.
The organisation's risk analysis determines which workforce populations matter.
But unless the population is known, coverage cannot be demonstrated.
A percentage such as “90% ready” is meaningless if the denominator is unclear.
2. Connection
Which organisation-worker relationship is active?
The same person may be associated with:
one staffing agency;
several client organisations over time;
a physical site;
a supplier contract;
a returning assignment.
The relationship matters because a readiness requirement exists in context.
The person alone is not the whole record.
The useful unit is:
person + active organisational connection.
3. Requirement
What does this connection require?
The requirement should reflect:
role;
system exposure;
information access;
organisational policy;
identified risk.
The existence of a register does not remove the need for risk-based judgement.
A generic requirement may be appropriate in one environment and inadequate in another.
4. Status
Has the person earned the required status?
The method can include:
training;
assessment;
acknowledgement;
practical checks;
other defined evidence.
The operational output should be understandable.
Where a client only needs to know whether the requirement is met, the external result can be a status rather than a detailed worker score.
5. Currency
Is the status still valid now?
Status needs a time dimension.
Relevant events can include:
expiry;
changed requirements;
revocation;
connection closure;
revalidation.
A historical record can remain true while no longer being operationally current.
6. Verification
Can an authorised party check the current answer?
If every question triggers a new manual evidence request, the organisation still has an evidence-collection process.
A live evidence model should make the relevant current state directly verifiable where appropriate.
7. Lifecycle
What happens when the person leaves, returns or changes context?
Flexible labour is defined by movement.
A readiness system should expect that.
It should not treat return as an edge case.
Figure 3 — The EdXactly workforce-evidence framework
This framework is an EdXactly analytical model, not a statutory NIS2/Cbw maturity model.
5. Current status and historical evidence answer different questions
A historical record answers:
What happened?
A current status answers:
What is true now?
Both are valuable.
They should not be confused.
Consider a simple timeline.
A PDF created on Monday may still accurately prove Monday.
It does not automatically answer Friday.
That distinction becomes more important as workforce turnover increases.
Point-in-time evidence still matters
Live status does not eliminate the need for historical evidence.
Auditors, clients and incident reviews may need to know:
What did the register show at a particular moment?
A mature evidence model should therefore support both:
Live view
What is current now?
Point-in-time extract
What was the state of the register when this evidence was generated?
The second should be described exactly that way.
It should not be presented as a timeless compliance certificate.
6. A portable credential should point to a live source
A portable credential can make workforce status easier to present across operational environments.
But portability only works if the credential remains connected to current state.
The useful model is:
the worker carries a credential reference;
the credential is presented;
verification resolves against current source status;
expiry or revocation changes the verification result;
physical identity is still confirmed by the relevant party where required.
This keeps three concepts separate:
identity confirmation;
credential presentation;
readiness status.
A workforce credential can support the second and third.
It does not replace the first.
7. Verification without surveillance
The existence of a readiness requirement does not mean every client needs every piece of worker data.
The operational question is often narrow:
Does this person currently hold the required status?
That question can frequently be answered without exposing:
detailed assessment scores;
question-level responses;
worker rankings;
full personnel records;
unnecessary identifiers.
This creates a practical design principle:
verification without surveillance
The authorised view should contain what is needed for the verification purpose.
Programme-management detail can remain inside the appropriate administrative environment.
Status, not scores
Scores can be useful internally when they help programme owners understand assessment quality or learning needs.
But a client-side register does not need to become a ranking system.
The operational state can remain neutral:
verified;
not yet verified;
expired;
revoked.
This avoids turning readiness evidence into worker profiling.
Low-PII by design
A live register still processes personal data.
The goal should not be “zero PII”.
The stronger principle is:
use the minimum personal data needed for the credential and authorised verification purpose.
This reduces unnecessary data duplication and helps prevent the readiness layer from becoming another personnel database.
8. Identity minimisation is also a security decision
Privacy and identity architecture meet in flexible workforces.
If every client creates a new identity for every external worker, the environment gains:
more accounts;
more credentials;
more lifecycle events;
more offboarding steps;
more opportunities for stale identities.
That expands the administrative and technical attack surface.
A workforce register can reduce that pressure by separating:
proof of readiness
from:
client-system identity
where the two do not need to be the same thing.
The worker may still need a client account to perform the job.
The design principle is narrower:
do not create an extra client identity solely because evidence needs somewhere to live.
9. Language is part of evidence integrity
Multilingual delivery is often treated as a usability feature.
In readiness evidence, it can be more fundamental.
If the claim is that the worker understood a required baseline, then the organisation should care whether:
the language was appropriate;
translated content preserved meaning;
assessment routes remained sufficiently equivalent;
the resulting status means the same thing across language versions.
The important question is not:
How many languages can the interface display?
It is:
Does the resulting status have a consistent meaning across the language routes used to earn it?
That is an evidence-integrity question.
A responsible programme should also distinguish between languages that are:
live;
under review;
planned.
Language claims should reflect actual release status.10. High turnover should be treated as normal
Many enterprise systems are optimised for permanent employment.
Flexible labour is different.
People leave and return.
A useful lifecycle looks like this:
The person is not recreated from zero.
The relationship is.
That distinction matters because it lets the system preserve the appropriate worker identity while still treating organisational context as current and explicit.
For staffing agencies and suppliers, this is not an edge case.
It is normal operations.
11. Supplier demonstrability without liability transfer
The Cyberbeveiligingswet's supply-chain focus increases the importance of clear supplier relationships, but it should not be interpreted as automatic liability transfer.
The client remains responsible for its own:
legal scope;
risk decisions;
controls;
contracting;
governance.
The supplier's contribution is operational:
maintain accurate, current evidence for the workforce the supplier administers.
A strong supplier evidence model can help answer:
which workers are relevant;
which connections are active;
what status each worker currently holds;
whether a status is expired or revoked;
which language route was used where relevant;
what the register showed at a specific point in time.
That can reduce the client's recurring evidence-collection burden.
It does not make the supplier legally responsible for the client's entire compliance position.
The commercial difference
Compare two client conversations.
Evidence project
Send us an updated spreadsheet and the latest certificates.
Maintained capability
We maintain current workforce status and can make the relevant state demonstrable when you need it.
The second is operationally stronger because it is reusable across client relationships.
12. How this complements GRC, TPRM and security operations
The NIS2 market already has strong systems for governance and technical security.
That is not a problem for a workforce-readiness model.
It clarifies the category.
GRC / ISMS
Useful for:
requirements;
controls;
policies;
risks;
evidence ownership;
corrective actions.
Third-party risk management
Useful for:
supplier inventories;
supplier assessments;
risk classification;
contract controls;
recurring review.
SOC / MDR
Useful for:
telemetry;
detection;
incidents;
technical monitoring;
response.
Workforce readiness
Useful for:
people;
current organisational connections;
current workforce status;
verification;
lifecycle across assignments.
The architecture should be composable.
Where useful, workforce evidence can flow into the wider governance environment.
The specialist layer does not need to become the system for everything.
13. A practical checklist for operators
Organisations using multiple suppliers can start with a small set of questions.
Workforce boundary
Have we identified the external worker populations relevant to cyber risk?
Do we know which supplier administers each population?
Do we know when those relationships start and end?
Requirement
Is the expected readiness status defined?
Does it reflect role and risk?
Is the requirement different for different populations where necessary?
Status
Can we distinguish current status from historical activity?
Can status expire?
Can it be revoked?
Can it be revalidated?
Verification
Can an authorised party verify the current state?
Are we still dependent on manually reconstructed spreadsheets?
Data
Are we collecting only what the verification purpose needs?
Are we duplicating worker identities unnecessarily?
Language
Can relevant workers use an appropriate language route?
Is language equivalence treated as part of evidence quality?
Supplier relationship
Is the supplier expected to maintain the evidence?
Are responsibilities clear?
Can evidence be reused across the relationship rather than rebuilt repeatedly?
14. A practical checklist for staffing agencies and workforce suppliers
Client demand
Which clients already ask workforce-security questions?
Which clients are strengthening cybersecurity clauses?
Are the same questions appearing repeatedly?
Population
Which workers are currently connected?
Which are active at which client or site?
Who has left?
Who has returned?
Status
Which workers currently hold the required status?
Which are not yet verified?
Which have expired?
Which have been revoked?
Evidence
Are we relying on static files?
Can an authorised client verify status directly where appropriate?
Can we generate point-in-time evidence when needed?
Identity
Are clients creating extra accounts solely to carry evidence?
Can readiness be demonstrated without another full personnel record?
Language
Are the relevant language routes actually live?
Does the status mean the same thing across those routes?
Commercial reuse
Can the same readiness capability support more than one client relationship?
Does sharing create unnecessary duplicate cost?
Does the worker remain free?
A reusable register capability is more durable than a one-client evidence project.
15. The EdXactly model
EdXactly is designed as a live register of workforce cyber readiness.
The product model separates the layers deliberately.
Connection
A worker is connected to the relevant organisational relationship.
The connection is the context in which readiness matters.
Readiness pathway
Training and assessment can be included in the connection and are how the worker earns the required status.
They support the register.
They are not the category EdXactly is trying to create.
Current status
The operational result is a current status:
verified;
not yet verified;
expired;
revoked.
The register does not need to expose a worker score to answer the client-side status question.
EdXactly Pass
The worker can carry a portable credential linked to the live register status.
The credential is useful because verification resolves against current state rather than relying on a static image alone.
EdXactly Switch
A client can consolidate connected supplier workforce status in one register view.
This supports supplier demonstrability without turning the client into the owner of every supplier's internal worker record.
EdXactly Flex
Where the physical site is the relevant commercial unit, EdXactly Flex provides direct site-level workforce coverage.
16. The commercial principle
EdXactly's commercial model is designed to reinforce the infrastructure model.
You pay for register capacity and connections, never per training. Training and assessment are included in every connection; they are how a name earns its place in the register.
Workers remain free.
Verification is never charged twice.
The aim is to make readiness evidence reusable across the labour relationship rather than repeatedly monetising the same worker activity.
17. What EdXactly does not claim
EdXactly does not:
determine whether a particular organisation is in scope of the Cyberbeveiligingswet;
determine which workforce populations an organisation must include;
certify legal compliance;
replace a risk assessment;
replace technical cybersecurity controls;
replace an ISMS, GRC platform or SOC;
transfer legal liability between client and supplier;
treat a not-yet-verified worker as inherently unsafe;
replace physical identity confirmation where that is required;
turn a historical record into a timeless certificate.
The register is an evidence and verification layer.
It supports demonstrability.
That boundary is part of the product's credibility.
18. Conclusion
NIS2 and the Cyberbeveiligingswet make supply-chain cybersecurity more operational.
For many organisations, the next gap will not be another policy or framework.
It will be maintaining a current answer about the people moving through those frameworks.
The workforce evidence problem can be reduced to seven questions:
Who is relevant?
Which connection is active?
What is required?
What is the current status?
Is it still valid?
Can it be verified?
What happens when the person leaves and returns?
When those answers live in separate spreadsheets, client systems and historical certificates, the evidence becomes expensive to maintain and easy to age.
A live workforce register creates a different operating model.
It keeps readiness attached to the active relationship.
It lets current status change when reality changes.
It supports point-in-time evidence without pretending that old evidence is forever current.
And it gives suppliers and clients a clearer way to share demonstrability without duplicating every worker into every system.
That is the role of the workforce-readiness layer.
The live register of workforce cyber readiness.
Sources and further reading
All regulatory references were reviewed on 14 September 2026.
[1] Rijksoverheid — Cyberbeveiligingswet and Wwke in force
15 August 2026
Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf vandaag van kracht
https://www.rijksoverheid.nl/actueel/nieuws/2026/08/15/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-vandaag-van-kracht
[2] Nationaal Cyber Security Centrum — Cbw duty of care
NCSC's current guidance sets out the ten duty-of-care measures, including supply-chain security, cyber hygiene/security training, personnel/access/asset security and effectiveness assessment.
https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht
[3] Directive (EU) 2022/2555 — NIS2
EUR-Lex
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555
[4] Nationaal Cyber Security Centrum — Suppliers of Cbw organisations
Current NCSC guidance on how Cbw organisations may impose cybersecurity requirements on direct suppliers/service providers where the supply relationship creates relevant network and information-system risk.
https://www.ncsc.nl/cyberbeveiligingswet-nis2/toeleveranciers-van-cbw-organisaties
[5] Nationaal Cyber Security Centrum — Safe digital behaviour
NCSC guidance emphasising that knowledge alone is insufficient and that organisations should diagnose, measure and support safe digital behaviour rather than treating a mandatory e-learning as the complete solution.
https://www.ncsc.nl/mensgerichte-beveiliging/hoe-bevorder-je-veilig-digitaal-gedrag-van-medewerkers
[6] Nationaal Cyber Security Centrum — Five basic principles
Basisprincipe 2: Bevorder veilig gedrag
https://www.ncsc.nl/basisprincipes/basisprincipe-2-bevorder-veilig-gedrag
[7] ENISA — NIS2 Technical Implementation Guidance
Published 26 June 2025. The guidance supports the NIS2 Implementing Regulation for specified digital infrastructure, ICT service-management and digital-provider categories and should not be treated as a universal implementation guide for every NIS2 entity.
https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance
Editorial metadata
Published: 14 September 2026
Last reviewed: 14 September 2026
Jurisdiction: Netherlands / EU NIS2
Primary official sources: Rijksoverheid, NCSC, EUR-Lex, ENISA
Document status: General information, not legal advice.
About EdXactly
EdXactly is setting the standard for workforce cyber security.
EdXactly provides a live register of workforce cyber readiness across workers, suppliers and client organisations.
EdXactly V.O.F.
KVK 99557487
Netherlands