Executive summary
The score and the 3 things to know. Readable by your CEO.
You type a domain. We email the report: a verified 0 to 10 risk score and an audit-ready NIS2 document, checked by an analyst, within 24 hours. €49, no account.
Not an automated scan: verified by an analyst No account Money-back guarantee
More vendors? Add up to 20 at checkout.
See a sample report2 HIGH findings · SSL: B · 2 known breaches · SPF missing
NIS2 Art. 21(2)(d): gap detected
NIS2 Art. 21
Evidence you can hand to your auditor
ACN Det. 127437
Your supplier map, one report at a time
🇪🇺 EU-hosted
Data stays in Europe, GDPR by design
| Vendor | Owner | Security info | |
|---|---|---|---|
| 1 | erp-supplier.com | IT dept | ? |
| 2 | cloudhost.io | Marco | n/a |
| 3 | logistica-spa.it | Sara | questionnaire sent |
| 4 | pay-gateway.net | ? | no reply |
Does one of these moments sound familiar?
Today 14:02
+ paste up to 19 more
One vendor or up to 20. No account, no questionnaire. 30 seconds.
Today 14:03
Card or Apple Pay via Stripe. Automatic invoice.
Tomorrow 09:58
Vendor Risk Report · erp-supplier.com
Audit-ready PDFs in your inbox within 24 hours, analyst-verified before sending.
Report by email within 24 hours No account
The score and the 3 things to know. Readable by your CEO.
Every finding: evidence, meaning, and the action to request from your vendor.
Every gap mapped to NIS2 Art. 21 and Reg. (EU) 2024/2690 Annex 5, in the words your auditor uses.
The request list, ready to forward to your vendor.
Severity scale, data sources, and the limitations an auditor will check.
The same format you will forward to auditors, clients and insurers. Prints clean in black and white.
Art. 21(2)(d)
The report documents the vendor assessment the directive requires.
Art. 21(2)(f)
A score and a repeatable methodology, not opinions.
ACN Det. 127437
Each report is one tile of the map the Italian authority expects.
NIS2 full compliance: October 2026
Vendor risk is already part of the obligation. The evidence takes time to build: start with one vendor now.
An equivalent assessment from a consulting firm: from €1,500. Enterprise tools: from €20,000/year.
Pack 5 Most popular
€49 one-time
Up to 5 vendors
For the request already sitting in your inbox.
Email delivery 24h
Get the report for €49Pack 10
€99 one-time
Up to 10 vendors
Comparable scores across your whole vendor list.
Email delivery 48h
Document up to 10Pack 20
€199 one-time
Up to 20 vendors
The full supplier map the regulator expects.
Email delivery 48h
Document your supply chain14-day money-back guarantee. Invoice included.
October is not the finish line. Scores change: keep your supplier map current automatically.
Starter
€99 /month
Up to 5 vendors
Business
€199 /month
Up to 20 vendors
Professional
€499 /month
Consultants & MSPs
Yes. We only analyse information publicly exposed on the internet (visible ports, certificates, DNS, known breaches). No system access, no intrusive testing.
No. It is a non-intrusive external analysis: the same visibility an attacker would have, without touching anything.
Every report is verified by an analyst before sending: no false positives to explain to your auditor.
That is the best outcome: the report documents the assessment, exactly what NIS2 asks you to demonstrate.
No. Enter the domains, pay, receive the reports by email.
We use it only to send your reports and invoice. No newsletters, no marketing lists. Write to us and we delete it.
Yes, it is built for that: a PDF formatted for auditors, clients and insurers.
Full refund within 14 days, no questions asked.
The evidence the ACN expects takes time to build. The first piece can be in your inbox tomorrow morning.
Report within 24 hours No account Money-back guarantee