For Suppliers & Vendors

Your customers are already asking. Be ready.

NIS2-obligated companies must verify their suppliers' security. norppa.io monitors your domain daily and generates audit-supporting compliance evidence — automatically.

What NIS2 Art. 21(2)(d) means for you

Every NIS2-obligated company must assess and document the security practices of their entire supply chain. If you supply finance, energy, healthcare, transport or digital infrastructure companies in the EU — you will receive an audit request. norppa.io generates the evidence before they ask.

See yourself as your customers see you

Your NIS2 customers assess you from the public internet — and may quietly score you down or drop you without telling you why. norppa.io shows you the exact same signals an external assessment reveals, so you can fix exposures before a customer ever flags them.

Daily monitoring of your own domain

100+ automated checks every day — ransomware victim lists, dark web credential leaks, DNS/TLS health, post-quantum TLS readiness, AI vendor inventory, certificate status, breach exposure and known vulnerabilities. Everything documented automatically.

Monthly NIS2 report to share with customers

A monthly PDF report — all findings mapped to NIS2 articles, risk score and remediation steps included. Forward it directly to customers as compliance evidence.

Self-assessment questionnaire (SAQ)

Fill in your own 28-question NIS2 self-assessment covering governance, access control, incident response and cryptography — and share it with any customer who asks.

Monitoring from day one — shareable evidence in 30 days.

1

Add your own domain

Enter your company domain. Monitoring starts immediately — no agents, no integrations, no IT project.

2

Daily checks run automatically

Ransomware, dark web, DNS/TLS, breach data and known vulnerabilities — checked every day. Email alert if something critical is found.

3

Monthly PDF, ready to share

Your NIS2 compliance report is generated automatically each month. Forward it to customers as documented proof of your security posture.

Monitoring starts from €249/month — no agents, no IT project, cancel anytime.

See all plans →

See your first NIS2 findings today.

Enter your work email — we scan your company domain automatically and send you a sign-in link. No password, no credit card, no configuration.

Work email

Your company domain is detected from your email. Results typically appear within minutes.

7-day free trial · no credit card · cancel anytime

We use only publicly available data — no access to your systems, nothing installed.