Know the day a supplier, or your own domain, becomes a risk.
Under NIS2, an attacker reaches you two ways: through a weaker supplier, or straight at your own external surface. You are responsible for both, and you must show it continuously, not once a year.
norppa.io runs 100+ external checks on every supplier and on your own domain, every day. Each finding names the concrete gap behind it, not just a score, mapped to NIS2 Article 21, with an audit-ready report on demand. No agents and no integration: built for organisations that must meet NIS2 without a dedicated security team.
Check your domain now
See what's publicly visible about your organisation's security, no sign-up.
This instant preview checks:
- HTTPS reachable
- HSTS enabled
- HTTP → HTTPS redirect
- SPF configured
- DMARC enforced
- Mail (MX) configured
The full report adds ransomware, dark web, certificates, company intel and 100+ more controls.
What you get as a subscriber
Add a supplier or your own domain and norppa.io takes it from there, no manual effort on your side.
Daily automated monitoring
Every supplier is checked automatically, every day. Adding one takes about 30 seconds, and after that there's nothing to schedule, no manual review, no chasing.
Same-day alerts for what matters
A ransomware victim listing, a live credential leak, a certificate about to expire: you get an email the day it's detected, not weeks later.
An on-demand compliance report, ready to use
A NIS2 report in your dashboard, on demand: a plain-language executive summary, a NIS2 score by article with the concrete gap behind each finding named, not just a number, and a prioritised remediation list you can save or print as PDF. Plus one-click exports for a NIS2 audit (CSV) or your DORA register of information. Every monitoring cycle is logged, so you hold a continuous, dated record of your oversight.
Verified, not just collected
Supplier questionnaire answers are checked against what we actually observe: confirmed, contradicted, or clearly marked as attestation only. Uncertain findings are flagged as potential false positives, so your team works on what's real instead of noise.
Built for the EU: 8 languages
Dashboard, reports and supplier questionnaires in eight EU languages, so you can assess and serve suppliers across Europe in their own.
Pre-contract supplier assessment
Assess a candidate supplier's external risk before you sign, without using a monitoring slot. An instant go/no-go verdict plus an auditable decision log for NIS2 Art. 21(2)(d) supplier due diligence.
See your first NIS2 findings today.
Enter your work email — we scan your company domain automatically and send you a sign-in link. No password, no credit card, no configuration.
The full external risk surface of your supply chain.
Daily, across every supplier you monitor, from DNS and TLS to dark-web and code exposure.
Threat & exposure intelligence
Active threats and leaked data, monitored continuously.
Ransomware Victim Tracking
Several ransomware-intelligence sources checked daily against every supplier, with active threat groups followed as they move. The moment a supplier appears on a victim list, you get an email. Mapped to NIS2 Art. 21(2)(b).
Dark Web Intelligence
Dark-web monitoring, daily. If a supplier's employee credentials surface in dark-web markets, you get an email the day we detect it. Mapped to NIS2 Art. 21(2)(b).
Breach & Exposure Monitoring
Breach databases, paste sites and credential exposure, checked daily — so you know if a supplier's accounts or data have surfaced in a public leak before it becomes your problem.
Certificate & Infrastructure
TLS certificates, DNS health, DNSSEC, email security (SPF/DKIM/DMARC), exposed services and subdomain discovery, monitored daily. You get an email when a certificate is within 14 days of expiry.
Identity Provider & BEC Risk Detection
Identifies which identity provider (Entra ID, ADFS, Okta) a supplier uses, detects federated identity configurations that raise BEC risk, and flags publicly exposed SSO endpoints. It correlates with infostealer data to produce a BEC composite risk score. Mapped to NIS2 Art. 21(2)(i)(j).
Domain Spoofing & Email Authentication
We ingest the DMARC aggregate reports that mail receivers already generate, so you see exactly who sends email using your domains. It separates legitimate but misconfigured senders from spoofing and brand impersonation, tracks authentication pass rates over time, and turns failures into prioritised findings. EU-hosted, aggregate data only, never message content. TLS reporting additionally shows whether mail to your domain arrives over encrypted connections. Every sender is labelled (authorized, forwarded, alignment gap or unauthenticated), and we tell you when it is safe to move DMARC to p=reject and MTA-STS to enforce, and what to fix first. Mapped to NIS2 Art. 21(2)(b) and (h).
Supply chain & company intelligence
Who your suppliers are, who owns them, and where risk concentrates.
Technical Security Checks
TLS certificates, DNS integrity (SPF/DKIM/DMARC/DNSSEC), HTTP security headers, HTTPS enforcement, email spoofing risk (MTA-STS, BIMI, BEC composite), subdomain discovery, exposed services and open ports, website change detection, security.txt, AiTM phishing infrastructure detection, RPKI/BGP route origin validation, public code repository analysis (GitHub/GitLab, npm, Docker Hub), and fourth-party supply chain risk. Mapped to NIS2 Art. 21(2)(e)(h)(i).
Company Intelligence
Business registry status including bankruptcy and liquidation detection, LEI/GLEIF registration and lapse detection, sanctions screening (EU, OFAC, UN), VAT validation, and domain registrar and nameserver changes — all cross-checked daily. Mapped directly to the NIS2 Art. 21(2)(d) supply-chain security requirements.
IP Address Monitoring
Tracks supplier IPs and CIDR ranges that aren't behind a main domain — VPN gateways, mail relays, dedicated hosts. CVE exposure detection (CISA KEV), high-risk country alerts, shared-hosting classification. Included per supplier in every plan. Mapped to the NIS2 Art. 21(2)(d) supply-chain asset inventory.
Portfolio Concentration & Systemic Risk
We connect findings across your whole supplier portfolio, not one supplier at a time: shared hosting, networks, SaaS and DNS providers, common corporate parents, and composite risks where stolen credentials or an exploited vulnerability line up into a single attack path. Surfaces the single points of failure where one provider or parent concentrates your supply-chain risk. Mapped to NIS2 Art. 21(2)(d).
Emerging risk for 2026
The exposures most tools don't check for yet.
AI Tool & LLM API Exposure
Discovers exposed AI development tools (Jupyter, Streamlit, Gradio, Ollama), public OpenAI-compatible API endpoints, and HuggingFace Spaces dependencies — including potential secret leaks. These exposures are invisible to traditional EASM tools. Mapped to NIS2 Art. 21(2)(a)(e).
MCP / AI Agent Endpoint Exposure
Public Model Context Protocol servers are the 2026 attack surface: BlueRock found 36.7% of 7,000 surveyed MCP servers vulnerable to SSRF, and CVE-2025-6514 turned 437,000 mcp-remote installations into supply-chain backdoors. We detect /.well-known/mcp, /mcp, /sse and AI-vendor inventory — the only TPRM tool that does. Mapped to NIS2 Art. 21(2)(e) and EU AI Act Art. 26.
Post-Quantum TLS Readiness
NIST FIPS 203 (ML-KEM) became the cryptography standard in August 2024. We fingerprint each supplier's CDN / edge provider and flag those not yet using hybrid post-quantum TLS — Cloudflare, Fastly and AWS CloudFront ship it by default; Akamai, BunnyCDN and direct origins typically don't yet. "Harvest now, decrypt later" is a real threat for long-lived sensitive data. Mapped to NIS2 Art. 21(2)(h).
Reporting, evidence & compliance
Findings turned into audit-ready proof.
External Security Grade
Every supplier's external posture is distilled into a single A–F grade over a 0–100 score, so management can compare and track suppliers at a glance. It reflects only externally observable signals: exposed services, credential leaks, email authentication, certificate and DNS hygiene. It is never a security audit or certification. The grade shows in the dashboard, the supplier report and the portfolio view.
Management Accountability
The management body's Article 20 duty of care, made operational: approve the risk-management approach, oversee critical supplier findings, keep leadership training current, and export a tamper-evident duty-of-care dossier for the board, a regulator or a cyber-insurer. It documents your duty of care; it is never a certification of compliance.
NIS2 Compliance Evidence
Every finding is mapped automatically to its NIS2 article — Art. 21(2)(d) supply chain, Art. 21(2)(h) cryptography, Art. 21(2)(j) access control, Art. 23 incident reporting. The on-demand report is ready for management review and audit.
Supplier Self-Assessment (SAQ)
Send each supplier a tokenised questionnaire link — they answer 39 NIS2-mapped questions on governance, access control, incident response, cryptography, continuity and supply-chain practices. Responses are scored automatically and sit in your dashboard next to the technical findings.
NIS2 + DORA Export-Ready Evidence
One-click CSV exports for a NIS2 audit (12-month findings mapped per article, risk decisions, supplier notifications, certifications) and the EU DORA Register of Information (Implementing Regulation 2024/1773 Annex III B_02.03 + B_05.01). norppa.io columns plus DORA RTS-aligned fields, ready for your compliance team's workbook — for financial entities subject to DORA.
Monthly Full Scan Add-on
Once a month, norppa.io runs a comprehensive external security assessment of your own domain — exposed ports and services, known CVE vulnerabilities (EPSS-ranked), TLS configuration weaknesses, HTTP security headers and subdomain exposure. It's assessed entirely from the public internet, with no access to your infrastructure. It also actively confirms the vulnerabilities flagged passively during daily monitoring, upgrading them from 'potential' to verified. Every finding lands in your on-demand NIS2 report.
Portfolio Intelligence
The risk that hides between your suppliers.
Most tools score each supplier on its own. norppa.io maps what they share: the same hosting, common ownership, a single critical dependency. Concentrated risk can no longer take down half your supply chain unseen.
Shared infrastructure
Suppliers concentrated on the same host or CDN
Common ownership
Vendors that roll up to one parent group
Single point of failure
One dependency with an outsized blast radius
Illustrative. Your live map is built from passive signals across your suppliers.
Two layers of NIS2 evidence, each checked against the other
Automated monitoring catches what suppliers don't disclose; the questionnaire captures what tools can't see. norppa.io checks one against the other, so each attestation is backed by evidence rather than taken on trust.
Automated monitoring: 100+ daily checks
100+ checks run daily on every monitored domain: ransomware victim lists, dark-web credential leaks, DNS/TLS health, post-quantum TLS readiness, AI-vendor inventory (EU AI Act), MCP endpoint exposure, IP geolocation, breach exposure, HTTP security headers, website change detection, company intelligence (business registry, LEI status, bankruptcy detection) and public code repository analysis. No supplier involvement needed.
Supplier self-assessment (SAQ)
Send each supplier a one-click questionnaire link with 39 questions across 9 NIS2 sections: governance, access control, incident response, cryptography, business continuity and more. Scored automatically, visible in your dashboard. Send it in the supplier's own language (eight EU languages) for higher response rates.
Evidence-Backed Attestation
NIS2 Art. 21(2)(d) — Where a control is observable from outside, we check the supplier's answer against what we actually see: a clean TLS scan backs a 'TLS 1.2+' attestation; an exposed vulnerability contradicts a 'we patch promptly' one. Controls we can't observe externally are marked clearly as attestation. We never imply a verification we can't stand behind.
Every answer carries its status: verified, contradicted, questioned, or attestation-only.
Built for lean security teams
100+
automated checks per domain
Ransomware · Dark web · DNS/TLS · Post-quantum TLS · AI vendors · MCP · Company intel · Code repos · Breach data
daily
scan frequency
Continuous monitoring, not a one-off snapshot
100%
EU data residency
EU · Frankfurt region · GDPR by architecture
NIS2
articles mapped automatically
Every NIS2 Art. 21(2) subparagraph covered, each finding's concrete gap named, not just a score
Built on the standards your auditor recognises.
Findings mapped to the frameworks that matter
Built on recognised public security sources
Referenced for identification. norppa.io is independent and not endorsed by these organisations.
2026 threat guide
How a breach happens in 2026, and where norppa.io breaks the chain
Edge devices exploited before a patch exists, credentials harvested at scale, AI-accelerated. The chain reaches you two ways: your own external surface and your supply chain. See it step by step.
Up and running in five minutes. Your NIS2 report on demand after the first scans.
Add your suppliers and your own domain
Enter a company name and domain, and add your own domain the same way. Your whole list takes about five minutes, no integrations, no API keys, no IT project.
Monitoring starts immediately
Ransomware victim tracking, dark-web credential leaks, certificate health, company-registry status and CVE exposure — checked daily across your suppliers and your own domain, with nothing to configure.
Critical findings trigger instant alerts
An email within 24 hours of detecting a ransomware listing, a dark-web credential exposure, or a certificate expiring in under 14 days — so you act as risks emerge.
NIS2 compliance report on demand
A NIS2 report in your dashboard, on demand: every finding mapped to its NIS2 article with the concrete gap named, not just a score, plus supplier rankings and a plain-language executive summary. Save or print as PDF, audit-supporting from your first scans.
Your own external surface and your whole supply chain, without the manual work.
Supply chain monitoring
Dark web & infostealer monitoring
Ransomware victim tracking
NIS2 article-mapped report
Certificate & subdomain monitoring
EU data residency
Full scan add-on
Supplier self-assessment questionnaire (SAQ)
Company intelligence (business registry, bankruptcy detection)
Public code repository analysis (GitHub/GitLab, npm, Docker Hub)
Identity provider risk detection (Entra ID, ADFS, Okta) + BEC composite risk scoring
AI/ML tool exposure and LLM API secret scanning
Art. 23 — Incident reporting readiness (24h)
Cross-validate supplier attestations against scan evidence
| Feature | norppa.io | Traditional EASM tools | Manual process |
|---|---|---|---|
| Supply chain monitoring | Included | Not included | Manual spreadsheet |
| Dark web & infostealer monitoring | Daily | Not included | Not feasible |
| Ransomware victim tracking | Daily | Not included | Manual |
| NIS2 article-mapped report | On-demand report | Not included | Manual |
| Certificate & subdomain monitoring | Continuous | Continuous | Manual |
| EU data residency | Yes | Partial | Depends |
| Full scan add-on | OSINT + HTTP checks included · Full scan: add-on | Higher tiers only | N/A |
| Supplier self-assessment questionnaire (SAQ) | Included | Not included | Manual |
| Company intelligence (business registry, bankruptcy detection) | Included | Partial | Manual |
| Public code repository analysis (GitHub/GitLab, npm, Docker Hub) | Included | Not included | Not feasible |
| Identity provider risk detection (Entra ID, ADFS, Okta) + BEC composite risk scoring | Included | Not included | Not feasible |
| AI/ML tool exposure and LLM API secret scanning | Included | Not included | Not feasible |
| Art. 23 — Incident reporting readiness (24h) | Daily — know immediately | Doesn't cover supplier incidents | Impossible with annual review |
| Cross-validate supplier attestations against scan evidence | Automatic | Not included | Not feasible |
Why a spreadsheet may not satisfy NIS2 Art. 21
An annual questionnaire tells you what a supplier intended to do, not whether their systems are secure today. NIS2's 'appropriate measures' standard is unlikely to be met by yearly snapshots alone.
Based on publicly available feature comparisons. Subject to change.
We don't use customer names in our marketing. We don't ask for references or case studies. What you share with norppa.io stays with you.
Switching from a rating or questionnaire platform? Here is what changes.
Third-party risk platforms tend to reduce a supplier to a yearly questionnaire and a single score. norppa.io is built the other way around: continuous, evidence-first and EU-native.
Per-supplier pricing from €249/month, in eight EU languages. We don't ask you for references or case studies.
NIS2 is being enforced. Can you show your supply chain is under control, every day, not once a year?
The EU's NIS2 Directive (in force since October 2024) requires medium and large companies in critical sectors to actively manage the cybersecurity risk in their supply chains. Article 21(2)(d) names supply-chain security measures specifically, and failing to comply can mean fines of up to €10M or 2% of global turnover.
160,000–200,000 companies across the EU are directly obligated
Finance, energy, healthcare, transport, digital infrastructure: NIS2 applies EU-wide, with the same requirements in every member state.
An annual assessment alone is unlikely to be enough
NIS2 expects you to show how a supplier looks today, not how it looked at the last review. norppa.io cross-checks each supplier's answers against live scan evidence, so an attestation is backed by what we actually observe.
Under audit, you have to show ongoing monitoring
Supervisory authorities can ask for concrete evidence of supply-chain risk management, and management is personally accountable. An annual questionnaire is a weak defence; norppa.io generates dated, finding-level evidence automatically, every day, for every supplier.
A fraction of the cost
Continuous monitoring of up to 10 suppliers from €249/month (under €25 per supplier), set against fines of up to €10M or 2% of global turnover.
One EU-native view across NIS2, CRA, DORA and the AI Act
Most platforms retrofit a US framework. norppa.io maps every supplier signal to the EU regime it actually informs, so the same monitoring answers four regulations at once.
NIS2
Every finding mapped to its Article 21(2) duty. In force across the EU today.
CRA
Readiness against the Cyber Resilience Act's essential requirements. Reporting from September 2026.
DORA
A pre-filled ICT third-party Register of Information export for financial entities.
AI Act
AI-in-use and exposed-AI-surface inventory for Article 26 deployer duties.
CRA and AI Act references are indicative readiness signals from external monitoring, not a conformity assessment. Read the CRA guide · AI Act guide
Your supply-chain risk map never leaves the EU
norppa.io is a European company. Your suppliers, findings and NIS2 evidence are stored and processed in the EU, under EU jurisdiction, with no third-country transfer of your supplier data.
- EU company, Norteris Oy in Helsinki
- EU data residency, Frankfurt region
- EU jurisdiction, no extraterritorial access
- EU support, based in Finland
A NIS2 risk register is sensitive in itself: it is a map of where your supply chain breaks. Before you choose a supply-chain platform, ask one question. Where does it send yours?