NIS2 Article 21(2)(d) requires organisations to manage cybersecurity risk in their supply chain.What does this mean for you? →

Automated NIS2 monitoring: your suppliers and your own domain

Know the day a supplier, or your own domain, becomes a risk.

Under NIS2, an attacker reaches you two ways: through a weaker supplier, or straight at your own external surface. You are responsible for both, and you must show it continuously, not once a year.

norppa.io runs 100+ external checks on every supplier and on your own domain, every day. Each finding names the concrete gap behind it, not just a score, mapped to NIS2 Article 21, with an audit-ready report on demand. No agents and no integration: built for organisations that must meet NIS2 without a dedicated security team.

New for 2026Post-Quantum TLS · MCP / AI-agent exposure · EU AI Act

Check your domain now

See what's publicly visible about your organisation's security, no sign-up.

This instant preview checks:

  • HTTPS reachable
  • HSTS enabled
  • HTTP → HTTPS redirect
  • SPF configured
  • DMARC enforced
  • Mail (MX) configured

The full report adds ransomware, dark web, certificates, company intel and 100+ more controls.

100+ automated checks daily, including dark web · ransomware re-checked every 6 hours
Ransomware · Dark web · DNS/TLS · HTTP security · Breach data · Company intel · Code repos · Identity and business-email fraud · AI exposure
Every finding mapped to its NIS2 article
EU company · EU support from Finland · EU data residency (Frankfurt region) · GDPR by design
Dashboard, reports and supplier questionnaires in 8 EU languages

What you get as a subscriber

Add a supplier or your own domain and norppa.io takes it from there, no manual effort on your side.

01

Daily automated monitoring

Every supplier is checked automatically, every day. Adding one takes about 30 seconds, and after that there's nothing to schedule, no manual review, no chasing.

02

Same-day alerts for what matters

A ransomware victim listing, a live credential leak, a certificate about to expire: you get an email the day it's detected, not weeks later.

03

An on-demand compliance report, ready to use

A NIS2 report in your dashboard, on demand: a plain-language executive summary, a NIS2 score by article with the concrete gap behind each finding named, not just a number, and a prioritised remediation list you can save or print as PDF. Plus one-click exports for a NIS2 audit (CSV) or your DORA register of information. Every monitoring cycle is logged, so you hold a continuous, dated record of your oversight.

04

Verified, not just collected

Supplier questionnaire answers are checked against what we actually observe: confirmed, contradicted, or clearly marked as attestation only. Uncertain findings are flagged as potential false positives, so your team works on what's real instead of noise.

05

Built for the EU: 8 languages

Dashboard, reports and supplier questionnaires in eight EU languages, so you can assess and serve suppliers across Europe in their own.

06

Pre-contract supplier assessment

Assess a candidate supplier's external risk before you sign, without using a monitoring slot. An instant go/no-go verdict plus an auditable decision log for NIS2 Art. 21(2)(d) supplier due diligence.

See your first NIS2 findings today.

Enter your work email — we scan your company domain automatically and send you a sign-in link. No password, no credit card, no configuration.

Your company domain is detected from your email. Results typically appear within a few hours.

7-day free trial · no credit card · cancel anytime

We use only publicly available data — no access to your systems, nothing installed.

The full external risk surface of your supply chain.

Daily, across every supplier you monitor, from DNS and TLS to dark-web and code exposure.

Threat & exposure intelligence

Active threats and leaked data, monitored continuously.

Ransomware Victim Tracking

Several ransomware-intelligence sources checked daily against every supplier, with active threat groups followed as they move. The moment a supplier appears on a victim list, you get an email. Mapped to NIS2 Art. 21(2)(b).

Dark Web Intelligence

Dark-web monitoring, daily. If a supplier's employee credentials surface in dark-web markets, you get an email the day we detect it. Mapped to NIS2 Art. 21(2)(b).

Breach & Exposure Monitoring

Breach databases, paste sites and credential exposure, checked daily — so you know if a supplier's accounts or data have surfaced in a public leak before it becomes your problem.

Certificate & Infrastructure

TLS certificates, DNS health, DNSSEC, email security (SPF/DKIM/DMARC), exposed services and subdomain discovery, monitored daily. You get an email when a certificate is within 14 days of expiry.

Identity Provider & BEC Risk Detection

Identifies which identity provider (Entra ID, ADFS, Okta) a supplier uses, detects federated identity configurations that raise BEC risk, and flags publicly exposed SSO endpoints. It correlates with infostealer data to produce a BEC composite risk score. Mapped to NIS2 Art. 21(2)(i)(j).

New for 2026

Domain Spoofing & Email Authentication

We ingest the DMARC aggregate reports that mail receivers already generate, so you see exactly who sends email using your domains. It separates legitimate but misconfigured senders from spoofing and brand impersonation, tracks authentication pass rates over time, and turns failures into prioritised findings. EU-hosted, aggregate data only, never message content. TLS reporting additionally shows whether mail to your domain arrives over encrypted connections. Every sender is labelled (authorized, forwarded, alignment gap or unauthenticated), and we tell you when it is safe to move DMARC to p=reject and MTA-STS to enforce, and what to fix first. Mapped to NIS2 Art. 21(2)(b) and (h).

Portfolio Intelligence

The risk that hides between your suppliers.

Most tools score each supplier on its own. norppa.io maps what they share: the same hosting, common ownership, a single critical dependency. Concentrated risk can no longer take down half your supply chain unseen.

Your suppliersShared hostSame parent

Shared infrastructure

Suppliers concentrated on the same host or CDN

Common ownership

Vendors that roll up to one parent group

Single point of failure

One dependency with an outsized blast radius

Illustrative. Your live map is built from passive signals across your suppliers.

Included in all plans

Two layers of NIS2 evidence, each checked against the other

Automated monitoring catches what suppliers don't disclose; the questionnaire captures what tools can't see. norppa.io checks one against the other, so each attestation is backed by evidence rather than taken on trust.

Layer 1

Automated monitoring: 100+ daily checks

100+ checks run daily on every monitored domain: ransomware victim lists, dark-web credential leaks, DNS/TLS health, post-quantum TLS readiness, AI-vendor inventory (EU AI Act), MCP endpoint exposure, IP geolocation, breach exposure, HTTP security headers, website change detection, company intelligence (business registry, LEI status, bankruptcy detection) and public code repository analysis. No supplier involvement needed.

Layer 2

Supplier self-assessment (SAQ)

Send each supplier a one-click questionnaire link with 39 questions across 9 NIS2 sections: governance, access control, incident response, cryptography, business continuity and more. Scored automatically, visible in your dashboard. Send it in the supplier's own language (eight EU languages) for higher response rates.

Evidence-Backed Attestation

NIS2 Art. 21(2)(d)Where a control is observable from outside, we check the supplier's answer against what we actually see: a clean TLS scan backs a 'TLS 1.2+' attestation; an exposed vulnerability contradicts a 'we patch promptly' one. Controls we can't observe externally are marked clearly as attestation. We never imply a verification we can't stand behind.

Every answer carries its status: verified, contradicted, questioned, or attestation-only.

Built for lean security teams

100+

automated checks per domain

Ransomware · Dark web · DNS/TLS · Post-quantum TLS · AI vendors · MCP · Company intel · Code repos · Breach data

daily

scan frequency

Continuous monitoring, not a one-off snapshot

100%

EU data residency

EU · Frankfurt region · GDPR by architecture

NIS2

articles mapped automatically

Every NIS2 Art. 21(2) subparagraph covered, each finding's concrete gap named, not just a score

Built on the standards your auditor recognises.

Findings mapped to the frameworks that matter

NIS2DORACRAEU AI Act

Built on recognised public security sources

NIST FIPS 203CISA KEVEUVDEPSS

Referenced for identification. norppa.io is independent and not endorsed by these organisations.

See our live EU-sector security hygiene index →

2026 threat guide

How a breach happens in 2026, and where norppa.io breaks the chain

Edge devices exploited before a patch exists, credentials harvested at scale, AI-accelerated. The chain reaches you two ways: your own external surface and your supply chain. See it step by step.

Read the guide

Up and running in five minutes. Your NIS2 report on demand after the first scans.

1

Add your suppliers and your own domain

Enter a company name and domain, and add your own domain the same way. Your whole list takes about five minutes, no integrations, no API keys, no IT project.

2

Monitoring starts immediately

Ransomware victim tracking, dark-web credential leaks, certificate health, company-registry status and CVE exposure — checked daily across your suppliers and your own domain, with nothing to configure.

3

Critical findings trigger instant alerts

An email within 24 hours of detecting a ransomware listing, a dark-web credential exposure, or a certificate expiring in under 14 days — so you act as risks emerge.

4

NIS2 compliance report on demand

A NIS2 report in your dashboard, on demand: every finding mapped to its NIS2 article with the concrete gap named, not just a score, plus supplier rankings and a plain-language executive summary. Save or print as PDF, audit-supporting from your first scans.

Your own external surface and your whole supply chain, without the manual work.

Supply chain monitoring

norppa.ioIncluded
Traditional EASM toolsNot included
Manual processManual spreadsheet

Dark web & infostealer monitoring

norppa.ioDaily
Traditional EASM toolsNot included
Manual processNot feasible

Ransomware victim tracking

norppa.ioDaily
Traditional EASM toolsNot included
Manual processManual

NIS2 article-mapped report

norppa.ioOn-demand report
Traditional EASM toolsNot included
Manual processManual

Certificate & subdomain monitoring

norppa.ioContinuous
Traditional EASM toolsContinuous
Manual processManual

EU data residency

norppa.ioYes
Traditional EASM toolsPartial
Manual processDepends

Full scan add-on

norppa.ioOSINT + HTTP checks included · Full scan: add-on
Traditional EASM toolsHigher tiers only
Manual processN/A

Supplier self-assessment questionnaire (SAQ)

norppa.ioIncluded
Traditional EASM toolsNot included
Manual processManual

Company intelligence (business registry, bankruptcy detection)

norppa.ioIncluded
Traditional EASM toolsPartial
Manual processManual

Public code repository analysis (GitHub/GitLab, npm, Docker Hub)

norppa.ioIncluded
Traditional EASM toolsNot included
Manual processNot feasible

Identity provider risk detection (Entra ID, ADFS, Okta) + BEC composite risk scoring

norppa.ioIncluded
Traditional EASM toolsNot included
Manual processNot feasible

AI/ML tool exposure and LLM API secret scanning

norppa.ioIncluded
Traditional EASM toolsNot included
Manual processNot feasible

Art. 23 — Incident reporting readiness (24h)

norppa.ioDaily — know immediately
Traditional EASM toolsDoesn't cover supplier incidents
Manual processImpossible with annual review

Cross-validate supplier attestations against scan evidence

norppa.ioAutomatic
Traditional EASM toolsNot included
Manual processNot feasible

Why a spreadsheet may not satisfy NIS2 Art. 21

An annual questionnaire tells you what a supplier intended to do, not whether their systems are secure today. NIS2's 'appropriate measures' standard is unlikely to be met by yearly snapshots alone.

Based on publicly available feature comparisons. Subject to change.

We don't use customer names in our marketing. We don't ask for references or case studies. What you share with norppa.io stays with you.

Already using a third-party risk platform?

Switching from a rating or questionnaire platform? Here is what changes.

Third-party risk platforms tend to reduce a supplier to a yearly questionnaire and a single score. norppa.io is built the other way around: continuous, evidence-first and EU-native.

Rating / questionnaire platformsA single letter grade you cannot interrogate
norppa.ioThe evidence behind every finding, so your team can verify it
Rating / questionnaire platformsAn annual questionnaire snapshot
norppa.io100+ checks daily including dark web, with ransomware re-checked every six hours
Rating / questionnaire platformsSelf-reported answers taken at face value
norppa.ioAttestations cross-checked against what we observe: confirmed, contradicted or attestation-only
Rating / questionnaire platformsA framework retrofitted from outside the EU
norppa.ioNIS2-native mapping, your data and support in the EU

Per-supplier pricing from €249/month, in eight EU languages. We don't ask you for references or case studies.

NIS2 is being enforced. Can you show your supply chain is under control, every day, not once a year?

The EU's NIS2 Directive (in force since October 2024) requires medium and large companies in critical sectors to actively manage the cybersecurity risk in their supply chains. Article 21(2)(d) names supply-chain security measures specifically, and failing to comply can mean fines of up to €10M or 2% of global turnover.

160,000–200,000 companies across the EU are directly obligated

Finance, energy, healthcare, transport, digital infrastructure: NIS2 applies EU-wide, with the same requirements in every member state.

An annual assessment alone is unlikely to be enough

NIS2 expects you to show how a supplier looks today, not how it looked at the last review. norppa.io cross-checks each supplier's answers against live scan evidence, so an attestation is backed by what we actually observe.

Under audit, you have to show ongoing monitoring

Supervisory authorities can ask for concrete evidence of supply-chain risk management, and management is personally accountable. An annual questionnaire is a weak defence; norppa.io generates dated, finding-level evidence automatically, every day, for every supplier.

A fraction of the cost

Continuous monitoring of up to 10 suppliers from €249/month (under €25 per supplier), set against fines of up to €10M or 2% of global turnover.

EU regulation, natively

One EU-native view across NIS2, CRA, DORA and the AI Act

Most platforms retrofit a US framework. norppa.io maps every supplier signal to the EU regime it actually informs, so the same monitoring answers four regulations at once.

NIS2

Every finding mapped to its Article 21(2) duty. In force across the EU today.

CRA

Readiness against the Cyber Resilience Act's essential requirements. Reporting from September 2026.

DORA

A pre-filled ICT third-party Register of Information export for financial entities.

AI Act

AI-in-use and exposed-AI-surface inventory for Article 26 deployer duties.

CRA and AI Act references are indicative readiness signals from external monitoring, not a conformity assessment. Read the CRA guide · AI Act guide

Built in the EU, stays in the EU

Your supply-chain risk map never leaves the EU

norppa.io is a European company. Your suppliers, findings and NIS2 evidence are stored and processed in the EU, under EU jurisdiction, with no third-country transfer of your supplier data.

  • EU company, Norteris Oy in Helsinki
  • EU data residency, Frankfurt region
  • EU jurisdiction, no extraterritorial access
  • EU support, based in Finland

A NIS2 risk register is sensitive in itself: it is a map of where your supply chain breaks. Before you choose a supply-chain platform, ask one question. Where does it send yours?

Frequently asked questions