Sample report (fictional company data. Every norppa.io plan includes 100+ automated checks on all monitored domains) passive OSINT and HTTP security checks, running daily automatically.

NIS2 Supply Chain Intelligence Report

Acme Manufacturing Oy

Reporting period: March 2026 · Generated 1 April 2026

61/100
40/36
NIS2 Risk Score
Needs attention
-13 (vs 74 last month)

Summary

2
Critical
5
High
4
Medium
2
Info
5 suppliers monitored across 100+ automated checks daily. 2 critical findings require immediate action: one supplier appeared on an active threat actor victim list and another has employee credentials circulating in dark web markets. 5 high-severity issues (including shadow IT: internal tooling exposed) and 4 medium findings require remediation within 7 days. The report also inventories fourth-party SaaS dependencies. Active findings map to NIS2 articles 21(2)(a), (b), (d), (e) and (h).

Company profile — Acme Logistics Oy

Country
Finland (FI)
Legal form
Oy
Industry
52.29
NIS2 status
Essential entity · Transport (indicative)
Employees
118
Trading names
Acme Logistics, Acme Freight
Parent
Acme Holding Oy
AI Executive Summary

Acme Manufacturing's NIS2 supply chain risk posture has deteriorated this period, with a score decline from 74 to 62 driven by two critical-severity findings requiring immediate executive attention.

The most significant threat is the active ransomware victim listing for Acme Logistics Oy. The threat actor group behind this campaign is known for maintaining persistent access and selling network entry to secondary actors when primary ransom negotiations fail. All integration points (APIs, file transfers, shared authentication systems) between your organisation and Acme Logistics should be treated as potentially compromised until the supplier provides a verified containment report. Simultaneously, 14 employee credentials from Nordic Cloud Services are circulating in dark web infostealer markets, creating a multi-vector exposure risk for any shared cloud environments or VPN endpoints.

From a NIS2 compliance perspective, several articles carry active findings this period. The two critical findings both fall under Art. 21(2)(b) (incident handling): a supplier on an active ransomware victim list and 14 leaked employee credentials must each be treated as a security incident (contained, responded to and documented. Art. 21(2)(d) (supply chain risk management) is triggered by high-risk-country infrastructure; Art. 21(2)(e) (security in development and maintenance, including vulnerability handling and disclosure) by the detected CVEs, the expiring TLS certificate, the missing DMARC policy and the absent security.txt; and Art. 21(2)(h) (cryptography) by missing DNSSEC. The TLS certificate expiry on databridge.fi in 6 days is a hard deadline) failure to renew will cause service disruption.

Grounded in the raw findings below: every claim is auditable.

Priority actions

1

Acme Logistics Oy, ransomware victim listing: contact supplier immediately and review data flows. Engage incident response.

Critical
2

Nordic Cloud Services, 14 employee credentials on dark web: notify supplier, require password rotation and MFA enforcement.

Critical
3

DataBridge Finland, TLS certificate expires in 6 days: ask the supplier to renew immediately to avoid service disruption.

High
4

Acme Logistics Oy, high-risk country infrastructure: request supplier's infrastructure documentation and review NIS2 Art. 21(2)(d) obligations.

High
5

Nordic Cloud Services, DMARC missing: ask the supplier to publish a DMARC record to prevent domain spoofing.

High

EU regulatory readiness

NIS2
Art. 21(2)(b)Art. 21(2)(d)Art. 21(2)(e)
CRA
Secure by designVulnerability handlingCoordinated disclosureSBOM
AI Act
AI in use (Art. 26)Exposed AI surface
DORA
ICT third party — DORA Register of Information export available.

Indicative mapping of open findings to EU frameworks from external signals — not a conformity assessment.

NIS2 article compliance status

Art. 21(2)(a)
Risk management

1 finding
Art. 21(2)(b)
Incident handling

Incident handling: detection, response and recovery

2 findings
Art. 21(2)(d)
Supply chain

Supply chain security & third-party measures

1 finding
Art. 21(2)(e)
Development & maintenance

Security in systems acquisition, development & maintenance (incl. vulnerability handling and disclosure)

4 findings
Art. 21(2)(h)
Cryptography

Cryptography (DNSSEC, TLS and certificate hygiene)

1 finding

Active findings (11)

CriticalActive ransomware victim listing detectedArt. 21(2)(b)
Acme Logistics Oy · acme-logistics.fi · Detected 15 Mar 2026
Your action: Contact the supplier immediately. Engage an incident response team. Assume services may be partially compromised and review data flows between your organisation and this supplier.
CriticalDark web: employee credentials leakedArt. 21(2)(b)
Nordic Cloud Services · nordiccloud.fi · Detected 18 Mar 2026
Your action: Notify the supplier. Request immediate password rotation and MFA enforcement for all accounts. Verify no shared credentials are used in integrations with your systems.
HighInfrastructure in high-risk countryArt. 21(2)(d)
Acme Logistics Oy · acme-logistics.fi · Detected 1 Mar 2026
Evidence
IP / Host:203.0.113.45ASN:AS64500: ExampleNet
Your action: Request the supplier's infrastructure documentation. Review contractual obligations and data processing agreements in light of NIS2 Art. 21(2)(d) supply chain security requirements.
HighTLS certificate expires in 6 daysArt. 21(2)(e)
DataBridge Finland · databridge.fi · Detected 24 Mar 2026
Evidence
Host:databridge.fiExpires in:6 d
Ask your supplier to: renew the TLS certificate immediately. Automated renewal via ACME/Let's Encrypt is recommended to prevent future expiry.
HighDMARC policy missingArt. 21(2)(e)
Nordic Cloud Services · nordiccloud.fi · Detected 1 Mar 2026
Evidence
DMARC policy:none
Ask your supplier to: publish a DMARC record. Start with p=none to collect aggregate reports, then tighten to p=quarantine or p=reject.
HighShadow IT: internal tooling publicly exposedArt. 21(2)(a)
Nordic Cloud Services · nordiccloud.fi · Detected 5 Mar 2026
Your action: Confirm the asset is intentional and within scope of access control and patching, or decommission it and remove its DNS record.
InfoSaaS service in use: Zendesk (supply chain)Art. 21(2)(d)
DataBridge Finland · databridge.fi · Detected 5 Mar 2026
Your action: Inventory this SaaS dependency for NIS2 supplier risk management: confirm a data processing agreement and access governance.
HighKnown vulnerabilities detected (CVE)Art. 21(2)(e)
Acme Logistics Oy · acme-logistics.fi · Detected 2 Mar 2026
Evidence
IP / Host:203.0.113.45Host:acme-logistics.fiCVE:CVE-2023-44487CVSS:7.5EPSS:94%KEV:Actively exploitedAffected products:nginx 1.24.0
Ask your supplier to: apply available security patches for the identified CVEs immediately, prioritising vulnerabilities with known public exploits.
MediumDNSSEC not enabledArt. 21(2)(h)
SupplyLink Partners · supplylink.eu · Detected 1 Mar 2026
Evidence
DNSSEC:Unsigned
Ask your supplier to: enable DNSSEC at their domain registrar to authenticate DNS responses against tampering.
Mediumsecurity.txt missing (NIS2 Art. 21(2)(e))Art. 21(2)(e)
DataBridge Finland · databridge.fi · Detected 1 Mar 2026
Evidence
Path:/.well-known/security.txtsecurity.txt:Missing
Ask your supplier to: create a security.txt file at /.well-known/security.txt with a security contact address and policy URL.
InfoHTTP security header missing
SupplyLink Partners · supplylink.eu · Detected 1 Mar 2026
Evidence
Missing:Content-Security-Policy
Ask your supplier to: configure HTTP security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security.

Want this report for your own supplier network?

Start free trial: no credit card

Supplier risk overview

SupplierSecurity scoreCritical
Acme Logistics Oy
22
1
Nordic Cloud Services
48
1
DataBridge Finland
64
SupplyLink Partners
81
Vantage IT Oy
97

Your own environment

acme-manufacturing.fi

Last scanned: 31 Mar 2026

78/100

Security score

Mediumsecurity.txt missing (NIS2 Art. 21(2)(e))Art. 21(2)(e)

No security.txt file found at /.well-known/security.txt. NIS2 Art. 21(2)(e) requires a reachable vulnerability disclosure channel.

Impact: No published disclosure channel slows how fast a reported vulnerability reaches the right contact.

Evidence
Path:/.well-known/security.txtsecurity.txt:Missing
Your action: Create a security.txt at /.well-known/security.txt with a security contact address and policy URL.
MediumDNSSEC not enabledArt. 21(2)(h)

DNSSEC is not configured for your domain. DNS responses cannot be cryptographically authenticated.

Impact: Without DNSSEC, DNS answers can be forged, enabling traffic redirection and interception.

Evidence
DNSSEC:Unsigned
Your action: Enable DNSSEC at your domain registrar to authenticate DNS responses against tampering.

Your own domain receives the same 100+ automated checks as your suppliers: passive OSINT and HTTP security checks daily. Full Scan add-on (if enabled) adds a monthly external security assessment on this domain.

Supplier Self-Assessments (SAQ)

Suppliers complete a 37-question NIS2 self-assessment. Responses are scored automatically and visible here alongside automated findings: two layers of compliance evidence in one report.

SupplierSAQ score
Acme Logistics Oy
Nordic Cloud Services61/100
DataBridge Finland74/100
SupplyLink Partners
Vantage IT Oy91/100

Nordic Cloud Services

[email protected] · 20 Mar 2026

61/100

SAQ score

Section breakdown

Governance & Security Policies

Art. 21(2)(a)

75

Access Control & Authentication

Art. 21(2)(i)(j)

40

Incident Response & Disclosure

Art. 21(2)(b), Art. 23

50

Data Protection & Cryptography

Art. 21(2)(h)

75

Business Continuity

Art. 21(2)(c)

67

Supply Chain & Third Parties

Art. 21(2)(d)

50

Vulnerability Management

Art. 21(2)(e)(g)

67
Analyst note: SAQ reveals MFA not enforced on all accounts and no tested incident response plan: consistent with the dark web credential leak detected in automated monitoring.

Monitoring methodology

Over 100 automated checks run daily on all monitored domains, with ransomware and dark-web monitoring every 6 hours. Checks cover: ransomware victim lists (multiple threat intelligence feeds), dark web infostealer credential leaks, TLS/certificate health and expiry, DNS integrity (SPF, DMARC, DKIM, DNSSEC), DNSSEC validation chain, MX server DNS blacklist status, email security posture and spoofability scoring (TLS-RPT, MTA-STS, BIMI, composite BEC risk), cookie security flags (Secure, HttpOnly, SameSite), robots.txt and sitemap sensitive path exposure, IP geolocation and high-risk country detection, known vulnerability exposure (CVE/EPSS), AiTM phishing infrastructure detection via Certificate Transparency logs, RPKI/BGP route origin validation, business registry and LEI status (PRH, GLEIF), dangling CNAME and MX record detection, SBOM/CSAF reference detection, security.txt presence, security headers, HTTPS redirect verification, and website change detection. New for 2026, post-quantum TLS readiness fingerprinting (NIST FIPS 203 ML-KEM hybrid suites), Model Context Protocol (MCP) endpoint exposure detection, JavaScript bundle secret scanning (API keys, tokens), AI vendor inventory for EU AI Act Art. 26 deployer obligations, GraphQL introspection and OpenAPI exposure checks, and DORA Register of Information export (Annex III B_02.03 + B_05.01). DMARC and TLS-RPT report analytics additionally reveal who actually sends email using your domains, flag active spoofing sources, and confirm whether inbound mail arrives over encrypted connections. All findings mapped to NIS2 articles automatically.

Scans run daily. Last scan: 31 March 2026 23:00 UTC.

Get this report for your supplier network

New suppliers are queued for scanning immediately. On-demand NIS2 compliance reports, ready after each scan cycle: with AI executive summary. No agents to install.

See pricing →