Vendor Risk Report
fornitore-erp.it
NIS2 · Art. 21
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 1/7
This is the report you receive for every vendor. Real data, anonymised.
fornitore-erp.it
NIS2 · Art. 21
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 1/7
This summary highlights the highest-impact findings observable from outside. The full set of 4 findings is in section 2; scope and limitations in section 5.
A database port (3306) responds from the public internet. It is the main driver of the HIGH score.
The company appears in 2 known data breaches (2021, 2023). Some credentials may be circulating.
Email anti-spoofing protection (SPF) is not configured. Phishing in this vendor’s name is easier than it should be.
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 2/7
Ask the vendor to restrict database access to a private network.
Ask for confirmation that the affected credentials were rotated.
Request support for TLS 1.2 or higher only.
Request SPF, DKIM and DMARC configuration.
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 3/7
Supply-chain security
Supplier-specific vulnerabilities and practice quality
Effectiveness assessment
Coordinated critical supply-chain assessments
Supplier selection criteria
Documented evidence of monitoring
Relevant-supplier declaration
ACN Det. 127437/2026 is a supplier-declaration obligation, not a security standard. Baseline measures are set by ACN Det. 379907/2025; technical supply-chain controls by Implementing Regulation (EU) 2024/2690, Annex 5.
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 4/7
The requests to forward to the vendor, in priority order:
Restrict database access (port 3306) to a private network.
Confirm rotation of the credentials involved in the 2021 and 2023 breaches.
Disable TLS 1.0 and support only TLS 1.2 or higher.
Configure SPF, DKIM and DMARC records.
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 5/7
VendoReport produces an external, passive assessment of the vendor public attack surface. It does not log into vendor systems, does not run intrusive tests, and does not replace an internal audit.
Assessment performed by the VendoReport security analysis team using the VR-EXT v1.2 methodology.
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 6/7
Directive (EU) 2022/2555 (NIS2)
Art. 21, cybersecurity risk-management measures.
D.lgs. 138/2024
Italian transposition of NIS2.
Implementing Regulation (EU) 2024/2690
Annex 5, technical supply-chain controls.
ACN Det. 379907/2025
Baseline security measures, from 15 January 2026.
ACN Det. 127437/2026
Relevant-supplier declaration to ACN, window 15 April to 31 May.
VendoReport · VR-EXT v1.2 · report VR-2026-0606-ERP · 2026-06-06 p. 7/7
This is what you receive for every vendor.
Get yours for €49Not an automated scan: verified by an analyst · No account · Money-back guarantee