NIS2 supply-chain tools compared: norppa.io vs rating platforms, EASM and spreadsheets
How continuous, evidence-first EU-native monitoring compares with rating and questionnaire platforms, traditional attack-surface tools, and the manual spreadsheet approach, for NIS2 Article 21(2)(d) supply-chain due diligence.
NIS2 supply-chain security from €249/month, without the enterprise complexity.
Supply chain monitoring
Dark web & infostealer monitoring
Ransomware victim tracking
NIS2 article-mapped report
Certificate & subdomain monitoring
EU data residency
Full scan add-on
Supplier self-assessment questionnaire (SAQ)
Company intelligence (business registry, bankruptcy detection)
Public code repository analysis (GitHub/GitLab, npm, Docker Hub)
Identity provider risk detection (Entra ID, ADFS, Okta) + BEC composite risk scoring
AI/ML tool exposure and LLM API secret scanning
Art. 23 — Incident reporting readiness (24h)
Cross-validate supplier attestations against scan evidence
| Feature | norppa.io | Traditional EASM tools | Manual process |
|---|---|---|---|
| Supply chain monitoring | Included | Not included | Manual spreadsheet |
| Dark web & infostealer monitoring | Daily | Not included | Not feasible |
| Ransomware victim tracking | Daily | Not included | Manual |
| NIS2 article-mapped report | On-demand report | Not included | Manual |
| Certificate & subdomain monitoring | Continuous | Continuous | Manual |
| EU data residency | Yes | Partial | Depends |
| Full scan add-on | OSINT + HTTP checks included · Full scan: add-on | Higher tiers only | N/A |
| Supplier self-assessment questionnaire (SAQ) | Included | Not included | Manual |
| Company intelligence (business registry, bankruptcy detection) | Included | Partial | Manual |
| Public code repository analysis (GitHub/GitLab, npm, Docker Hub) | Included | Not included | Not feasible |
| Identity provider risk detection (Entra ID, ADFS, Okta) + BEC composite risk scoring | Included | Not included | Not feasible |
| AI/ML tool exposure and LLM API secret scanning | Included | Not included | Not feasible |
| Art. 23 — Incident reporting readiness (24h) | Daily — know immediately | Doesn't cover supplier incidents | Impossible with annual review |
| Cross-validate supplier attestations against scan evidence | Automatic | Not included | Not feasible |
Why a spreadsheet may not satisfy NIS2 Art. 21
An annual questionnaire tells you what a supplier intended to do, not whether their systems are secure today. NIS2's 'appropriate measures' standard is unlikely to be met by yearly snapshots alone.
Based on publicly available feature comparisons. Subject to change.
We don't use customer names in our marketing. We don't ask for references or case studies. What you share with norppa stays with you.
Switching from a rating or questionnaire platform? Here is what changes.
Third-party risk platforms tend to reduce a supplier to a yearly questionnaire and a single score. norppa.io is built the other way around: continuous, evidence-first and EU-native.
Per-supplier pricing from €249/month, in eight EU languages. We don't ask you for references or case studies.
See it on your own suppliers
Start a free trial and add a supplier in about 30 seconds. No credit card, no integration.
Start free trial