For suppliers and vendors

Your customers are already asking. Be ready.

NIS2-obligated companies have to verify their suppliers' security. norppa.io monitors your domain daily and generates audit-supporting compliance evidence — automatically.

What NIS2 Art. 21(2)(d) means for you

Every NIS2-obligated company has to assess and document the security of its whole supply chain. If you supply finance, energy, healthcare, transport or digital-infrastructure companies in the EU, an audit request is coming. norppa.io has the evidence ready before they ask.

See yourself as your customers see you

Your NIS2 customers assess you from the public internet — and may quietly mark you down, or drop you, without saying why. norppa.io shows you the same signals an external assessment reveals, so you can fix exposures before a customer ever flags them.

Daily monitoring of your own domain

100+ automated checks every day — ransomware victim lists, dark-web credential leaks, DNS/TLS health, post-quantum TLS readiness, AI-vendor inventory, certificate status, breach exposure and known vulnerabilities. All documented automatically. Every gap comes with the exact change and a due date, and a new check confirms the fix.

An on-demand NIS2 report to share with customers

An on-demand NIS2 report with every finding mapped to its NIS2 article, plus a security score and remediation steps — save or print it as PDF and forward it straight to a customer as compliance evidence.

Self-assessment questionnaire (SAQ)

Complete your own 41-question NIS2 self-assessment — governance, access control, incident response, cryptography — and share it with any customer who asks.

Monitoring from day one — shareable evidence on demand.

1

Add your own domain

Enter your company domain. With a subscription the first scan runs within minutes — no agents, no integrations, no IT project.

2

Daily checks run automatically

Ransomware, dark web, DNS/TLS, breach data and known vulnerabilities — checked every day, with an email alert if something critical turns up.

3

An on-demand report, ready to share

Your NIS2 compliance report is available on demand in your dashboard. Forward it to customers as documented proof of your security posture.

Monitoring starts from €249/month — no agents, no IT project, cancel anytime.

See all plans

Check your own domain and send your first supplier questionnaire today.

Enter your work email and we send you a sign-in link. The free account checks your company domain's public configuration, sends the NIS2 questionnaire to up to 10 suppliers and reads DMARC reports for one domain. No password, no credit card. Nobody will call you.

Your company domain is detected from your email.

Free, no time limit · no credit card · no sales call

We use only publicly available data — no access to your systems, nothing installed.