NIS2 Article 21(2)(d) requires organisations to manage cybersecurity risk in their supply chain.What does this mean for you? →

Automated NIS2 monitoring: your suppliers and your own domain

Know the day a supplier, or your own domain, becomes a risk.

Under NIS2, an attacker reaches you in two ways: through a weaker supplier, or straight at your own external surface. You are responsible for both, and you must show it continuously, not once a year.

norppa.io runs 100+ external checks on every supplier and on your own domain, every day. Each finding names the concrete gap behind it, not just a score, mapped to NIS2 Article 21, with an audit-ready report on demand. For your own domains, every gap comes with the exact change, a due date and a check that confirms the fix. No agents, no credentials and no access to your systems: built for organisations that must meet NIS2 without a dedicated security team.

New for 2026Post-Quantum TLS · MCP / AI-agent exposure · EU AI Act

Check your domain now

See what's publicly visible about your organisation's security, no sign-up.

This instant preview checks:

  • HTTPS reachable
  • HSTS enabled
  • HTTP → HTTPS redirect
  • SPF configured
  • DMARC enforced
  • Mail (MX) configured

The full report adds ransomware, dark web, certificates, company intel and 100+ more controls.

  • 100+ automated checks daily, including dark web · ransomware re-checked every 6 hours
  • EU company · EU support from Finland · EU data residency (Frankfurt region) · GDPR by design
  • Every finding mapped to its NIS2 article
  • Dashboard, reports and supplier questionnaires in 8 EU languages
  • Ransomware · Dark web · DNS/TLS · HTTP security · Breach data · Company intel · Code repos · Identity and business-email fraud · AI exposure

What you get as a subscriber

Add a supplier or your own domain and norppa.io takes it from there, no manual effort on your side.

Daily automated monitoring

Every supplier is checked automatically, every day. Adding one takes about 30 seconds, and after that there's nothing to schedule, no manual review, no chasing. Services your own email and website already use are suggested when they are missing from your list.

Same-day alerts for what matters

A ransomware victim listing, a live credential leak, a certificate about to expire: you get an email the day it's detected, not weeks later.

Your own domains: from finding to verified fix

Every gap on your own domains comes with the exact change to make, a due date and an owner. When the change is made, we check again and close the task only if the problem is gone. Certificates, domain registrations and DKIM keys appear in a renewal calendar before they lapse. We never touch your systems: you make the change, we verify it from outside.

The full external risk surface of your supply chain.

Daily, across every supplier you monitor, from DNS and TLS to dark-web and code exposure.

Threat & exposure intelligence

Active threats and leaked data, monitored continuously.

Ransomware Victim Tracking

Several ransomware-intelligence sources re-checked every six hours against every supplier, with active threat groups followed as they move. The moment a supplier appears on a victim list, you get an email. Mapped to NIS2 Art. 21(2)(b).

Dark Web Intelligence

Dark-web monitoring, daily. If a supplier's employee credentials surface in dark-web markets, you get an email the day we detect it. Mapped to NIS2 Art. 21(2)(b).

Breach & Exposure Monitoring

Breach databases, paste sites and credential exposure, checked daily — so you know if a supplier's accounts or data have surfaced in a public leak before it becomes your problem.

Certificate & Infrastructure

TLS certificates, DNS health, DNSSEC, email security (SPF/DKIM/DMARC), exposed services and subdomain discovery, monitored daily. You get an email when a certificate is within 14 days of expiry.

Identity Provider & BEC Risk Detection

Identifies which identity provider (Entra ID, ADFS, Okta) a supplier uses, detects federated identity configurations that raise BEC risk, and flags publicly exposed SSO endpoints. It correlates with infostealer data to produce a BEC composite risk score. Mapped to NIS2 Art. 21(2)(i)(j).

New for 2026

Domain Spoofing & Email Authentication

We read the DMARC aggregate reports that receiving mail servers already send, so you see which services send email as your domains, notice when a new one appears, and can tell misconfigured legitimate senders from spoofing. TLS reports show whether mail reaches you encrypted. We tell you when p=reject and MTA-STS enforce are safe, and what to fix first. EU-hosted, aggregate data only. Mapped to NIS2 Art. 21(2)(b) and (h).

Portfolio Intelligence

The risk that hides between your suppliers.

Most tools score each supplier on its own. norppa.io maps what they share: the same hosting, common ownership, a single critical dependency. Concentrated risk can no longer take down half your supply chain unseen.

Your suppliersShared hostSame parent

Shared infrastructure

Suppliers concentrated on the same host or CDN

Common ownership

Vendors that roll up to one parent group

Single point of failure

One dependency with an outsized blast radius

Illustrative. Your live map is built from passive signals across your suppliers.

Included in all plans

Two layers of NIS2 evidence, each checked against the other

Automated monitoring catches what suppliers don't disclose; the questionnaire captures what tools can't see. norppa.io checks one against the other, so each attestation is backed by evidence rather than taken on trust.

Layer 1

Automated monitoring: 100+ daily checks

100+ checks run daily on every monitored domain: ransomware victim lists, dark-web credential leaks, DNS/TLS health, post-quantum TLS readiness, AI-vendor inventory (EU AI Act), MCP endpoint exposure, IP geolocation, breach exposure, HTTP security headers, website change detection, company intelligence (business registry, LEI status, bankruptcy detection) and public code repository analysis. No supplier involvement needed.

Layer 2

Supplier self-assessment (SAQ)

Send each supplier a one-click questionnaire link with 41 questions across 9 NIS2 sections: governance, access control, incident response, cryptography, business continuity and more. Scored automatically, visible in your dashboard. Send it in the supplier's own language (eight EU languages) for higher response rates.

Evidence-Backed Attestation

NIS2 Art. 21(2)(d) — Where a control is observable from outside, we check the supplier's answer against what we actually see: a clean TLS scan backs a “TLS 1.2+” attestation; an exposed vulnerability contradicts a “we patch promptly” one. Controls we can't observe externally are marked clearly as attestation. We never imply a verification we can't stand behind.

Every answer carries its status: verified, contradicted, questioned, or attestation-only.

Built on the standards your auditor recognises.

Findings mapped to the frameworks that matter

NIS2DORACRAEU AI Act

Built on recognised public security sources

NIST FIPS 203CISA KEVEUVDEPSS

Referenced for identification. norppa.io is independent and not endorsed by these organisations.

See our live EU-sector security hygiene index →

Built in the EU, stays in the EU

Your supply-chain risk map never leaves the EU

norppa.io is a European company. Your suppliers, findings and NIS2 evidence are stored and processed in the EU, under EU jurisdiction, with no third-country transfer of your supplier data.

  • EU company, Norteris Oy in Helsinki
  • Fully Finnish-owned: every shareholder is Finnish and based in Finland
  • EU data residency, Frankfurt region
  • EU jurisdiction: your contract is under EU law only
  • EU support, based in Finland

A NIS2 risk register is sensitive in itself: it is a map of where your supply chain breaks. Before you choose a supply-chain platform, ask one question. Where does it send yours?

Check your own domain and send your first supplier questionnaire today.

Enter your work email and we send you a sign-in link. The free account checks your company domain's public configuration, sends the NIS2 questionnaire to up to 10 suppliers and reads DMARC reports for one domain. No password, no credit card. Nobody will call you.

Your company domain is detected from your email.

Free, no time limit · no credit card · no sales call

We use only publicly available data — no access to your systems, nothing installed.

Frequently asked questions