Know the day a supplier, or your own domain, becomes a risk.
Under NIS2, an attacker reaches you in two ways: through a weaker supplier, or straight at your own external surface. You are responsible for both, and you must show it continuously, not once a year.
norppa.io runs 100+ external checks on every supplier and on your own domain, every day. Each finding names the concrete gap behind it, not just a score, mapped to NIS2 Article 21, with an audit-ready report on demand. For your own domains, every gap comes with the exact change, a due date and a check that confirms the fix. No agents, no credentials and no access to your systems: built for organisations that must meet NIS2 without a dedicated security team.
Check your domain now
See what's publicly visible about your organisation's security, no sign-up.
This instant preview checks:
- HTTPS reachable
- HSTS enabled
- HTTP → HTTPS redirect
- SPF configured
- DMARC enforced
- Mail (MX) configured
The full report adds ransomware, dark web, certificates, company intel and 100+ more controls.

- 100+ automated checks daily, including dark web · ransomware re-checked every 6 hours
- EU company · EU support from Finland · EU data residency (Frankfurt region) · GDPR by design
- Every finding mapped to its NIS2 article
- Dashboard, reports and supplier questionnaires in 8 EU languages
- Ransomware · Dark web · DNS/TLS · HTTP security · Breach data · Company intel · Code repos · Identity and business-email fraud · AI exposure
What you get as a subscriber
Add a supplier or your own domain and norppa.io takes it from there, no manual effort on your side.
Daily automated monitoring
Every supplier is checked automatically, every day. Adding one takes about 30 seconds, and after that there's nothing to schedule, no manual review, no chasing. Services your own email and website already use are suggested when they are missing from your list.
Same-day alerts for what matters
A ransomware victim listing, a live credential leak, a certificate about to expire: you get an email the day it's detected, not weeks later.
Your own domains: from finding to verified fix
Every gap on your own domains comes with the exact change to make, a due date and an owner. When the change is made, we check again and close the task only if the problem is gone. Certificates, domain registrations and DKIM keys appear in a renewal calendar before they lapse. We never touch your systems: you make the change, we verify it from outside.
The full external risk surface of your supply chain.
Daily, across every supplier you monitor, from DNS and TLS to dark-web and code exposure.
Threat & exposure intelligence
Active threats and leaked data, monitored continuously.
Ransomware Victim Tracking
Several ransomware-intelligence sources re-checked every six hours against every supplier, with active threat groups followed as they move. The moment a supplier appears on a victim list, you get an email. Mapped to NIS2 Art. 21(2)(b).
Dark Web Intelligence
Dark-web monitoring, daily. If a supplier's employee credentials surface in dark-web markets, you get an email the day we detect it. Mapped to NIS2 Art. 21(2)(b).
Breach & Exposure Monitoring
Breach databases, paste sites and credential exposure, checked daily — so you know if a supplier's accounts or data have surfaced in a public leak before it becomes your problem.
Certificate & Infrastructure
TLS certificates, DNS health, DNSSEC, email security (SPF/DKIM/DMARC), exposed services and subdomain discovery, monitored daily. You get an email when a certificate is within 14 days of expiry.
Identity Provider & BEC Risk Detection
Identifies which identity provider (Entra ID, ADFS, Okta) a supplier uses, detects federated identity configurations that raise BEC risk, and flags publicly exposed SSO endpoints. It correlates with infostealer data to produce a BEC composite risk score. Mapped to NIS2 Art. 21(2)(i)(j).
Domain Spoofing & Email Authentication
We read the DMARC aggregate reports that receiving mail servers already send, so you see which services send email as your domains, notice when a new one appears, and can tell misconfigured legitimate senders from spoofing. TLS reports show whether mail reaches you encrypted. We tell you when p=reject and MTA-STS enforce are safe, and what to fix first. EU-hosted, aggregate data only. Mapped to NIS2 Art. 21(2)(b) and (h).
Supply chain & company intelligence
Who your suppliers are, who owns them, and where risk concentrates.
Technical Security Checks
TLS certificates, DNS integrity (SPF/DKIM/DMARC/DNSSEC), HTTP security headers, HTTPS enforcement, email spoofing risk (MTA-STS, BIMI, BEC composite), subdomain discovery, exposed services and open ports, website change detection, security.txt, AiTM phishing infrastructure detection, RPKI/BGP route origin validation, public code repository analysis (GitHub/GitLab, npm, Docker Hub), and fourth-party supply chain risk. Mapped to NIS2 Art. 21(2)(e)(h)(i).
Company Intelligence
Business registry status including bankruptcy and liquidation detection, LEI/GLEIF registration and lapse detection, sanctions screening (EU, OFAC, UN), VAT validation, and domain registrar and nameserver changes — all cross-checked daily. Mapped directly to the NIS2 Art. 21(2)(d) supply-chain security requirements.
IP Address Monitoring
Tracks supplier IPs and CIDR ranges that aren't behind a main domain — VPN gateways, mail relays, dedicated hosts. CVE exposure detection (CISA KEV / ENISA EUVD), high-risk country alerts, shared-hosting classification. Included per supplier in every plan. Mapped to the NIS2 Art. 21(2)(d) supply-chain asset inventory.
Portfolio Concentration & Systemic Risk
We connect findings across your whole supplier portfolio, not one supplier at a time: shared hosting, networks, SaaS and DNS providers, common corporate parents, and composite risks where stolen credentials or an exploited vulnerability line up into a single attack path. Surfaces the single points of failure where one provider or parent concentrates your supply-chain risk. Mapped to NIS2 Art. 21(2)(d).
Emerging risk for 2026
The exposures most tools don't check for yet.
AI Tool & LLM API Exposure
Discovers exposed AI development tools (Jupyter, Streamlit, Gradio, Ollama), public OpenAI-compatible API endpoints, and HuggingFace Spaces dependencies — including potential secret leaks. These exposures are invisible to traditional EASM tools. Mapped to NIS2 Art. 21(2)(a)(e).
MCP / AI Agent Endpoint Exposure
Public Model Context Protocol servers are the 2026 attack surface: BlueRock found 36.7% of 7,000 surveyed MCP servers vulnerable to SSRF, and CVE-2025-6514 turned 437,000 mcp-remote installations into supply-chain backdoors. We detect /.well-known/mcp, /mcp, /sse and AI-vendor inventory. Mapped to NIS2 Art. 21(2)(e) and EU AI Act Art. 26.
Post-Quantum TLS Readiness
NIST FIPS 203 (ML-KEM) became the cryptography standard in August 2024. We fingerprint each supplier's CDN / edge provider and flag those not yet using hybrid post-quantum TLS — Cloudflare, Fastly and AWS CloudFront ship it by default; Akamai, BunnyCDN and direct origins typically don't yet. “Harvest now, decrypt later” is a real threat for long-lived sensitive data. Mapped to NIS2 Art. 21(2)(h).
Reporting, evidence & compliance
Findings turned into audit-ready proof.
External Security Grade
Every supplier's external posture is distilled into a single A–F grade over a 0–100 score, so management can compare and track suppliers at a glance. It reflects only externally observable signals: exposed services, credential leaks, email authentication, certificate and DNS hygiene. It is never a security audit or certification. The grade shows in the dashboard, the supplier report and the portfolio view.
Management Accountability
The management body's Article 20 duty of care, made operational: approve the risk-management approach, oversee critical supplier findings, keep leadership training current, and export a tamper-evident duty-of-care dossier for the board, a regulator or a cyber-insurer. It documents your duty of care; it is never a certification of compliance.
NIS2 Compliance Evidence
Every finding is mapped automatically to its NIS2 article — Art. 21(2)(d) supply chain, Art. 21(2)(h) cryptography, Art. 21(2)(i) access control, Art. 21(2)(e) vulnerability handling. The on-demand report is ready for management review and audit.
Supplier Self-Assessment (SAQ)
Send each supplier a tokenised questionnaire link — they answer 41 NIS2-mapped questions on governance, access control, incident response, cryptography, continuity and supply-chain practices. Responses are scored automatically and sit in your dashboard next to the technical findings.
NIS2 + DORA Export-Ready Evidence
One-click CSV exports for a NIS2 audit (12-month findings mapped per article, risk decisions, supplier notifications, certifications) and the EU DORA Register of Information (Implementing Regulation 2024/2956 Annex I, template B_05.01). norppa.io columns plus DORA ITS-aligned fields, ready for your compliance team's workbook — for financial entities subject to DORA.
Into Your Tools, Not Another Dashboard
Material supplier changes reach your own systems as a signed webhook, and a read-only API serves your events, suppliers and findings with CISA KEV and EPSS already attached. The webhook says that something changed and how serious it is, never what was found. And when a vulnerability we already reported enters KEV or becomes likelier to be exploited, you hear about that too.
Monthly Full Scan Add-on
Once a month, norppa.io runs a comprehensive external security assessment of your own domain — exposed ports and services, known CVE vulnerabilities (EPSS-ranked), TLS configuration weaknesses, HTTP security headers and subdomain exposure. It's assessed entirely from the public internet, with no access to your infrastructure. It also actively confirms the vulnerabilities flagged passively during daily monitoring, upgrading them from “potential” to verified. Every finding lands in your on-demand NIS2 report.
Portfolio Intelligence
The risk that hides between your suppliers.
Most tools score each supplier on its own. norppa.io maps what they share: the same hosting, common ownership, a single critical dependency. Concentrated risk can no longer take down half your supply chain unseen.
Shared infrastructure
Suppliers concentrated on the same host or CDN
Common ownership
Vendors that roll up to one parent group
Single point of failure
One dependency with an outsized blast radius
Illustrative. Your live map is built from passive signals across your suppliers.
Included in all plans
Two layers of NIS2 evidence, each checked against the other
Automated monitoring catches what suppliers don't disclose; the questionnaire captures what tools can't see. norppa.io checks one against the other, so each attestation is backed by evidence rather than taken on trust.
Automated monitoring: 100+ daily checks
100+ checks run daily on every monitored domain: ransomware victim lists, dark-web credential leaks, DNS/TLS health, post-quantum TLS readiness, AI-vendor inventory (EU AI Act), MCP endpoint exposure, IP geolocation, breach exposure, HTTP security headers, website change detection, company intelligence (business registry, LEI status, bankruptcy detection) and public code repository analysis. No supplier involvement needed.
Supplier self-assessment (SAQ)
Send each supplier a one-click questionnaire link with 41 questions across 9 NIS2 sections: governance, access control, incident response, cryptography, business continuity and more. Scored automatically, visible in your dashboard. Send it in the supplier's own language (eight EU languages) for higher response rates.
Evidence-Backed Attestation
NIS2 Art. 21(2)(d) — Where a control is observable from outside, we check the supplier's answer against what we actually see: a clean TLS scan backs a “TLS 1.2+” attestation; an exposed vulnerability contradicts a “we patch promptly” one. Controls we can't observe externally are marked clearly as attestation. We never imply a verification we can't stand behind.
Every answer carries its status: verified, contradicted, questioned, or attestation-only.
Built on the standards your auditor recognises.
Findings mapped to the frameworks that matter
Built on recognised public security sources
Referenced for identification. norppa.io is independent and not endorsed by these organisations.
Built in the EU, stays in the EU
Your supply-chain risk map never leaves the EU
norppa.io is a European company. Your suppliers, findings and NIS2 evidence are stored and processed in the EU, under EU jurisdiction, with no third-country transfer of your supplier data.
- EU company, Norteris Oy in Helsinki
- Fully Finnish-owned: every shareholder is Finnish and based in Finland
- EU data residency, Frankfurt region
- EU jurisdiction: your contract is under EU law only
- EU support, based in Finland
A NIS2 risk register is sensitive in itself: it is a map of where your supply chain breaks. Before you choose a supply-chain platform, ask one question. Where does it send yours?
Check your own domain and send your first supplier questionnaire today.
Enter your work email and we send you a sign-in link. The free account checks your company domain's public configuration, sends the NIS2 questionnaire to up to 10 suppliers and reads DMARC reports for one domain. No password, no credit card. Nobody will call you.