From €249/month, a fraction of what enterprise EASM tools cost
No setup fees. No hidden costs. Prices excl. VAT.
Continuous monitoring plans
All plans include 100+ automated checks on your own domain (included, no slot used) and every monitored supplier domain, automatic subdomain discovery and monitoring, continuous threat intelligence, and an on-demand NIS2 report in your dashboard (save or print as PDF). No agents. No integration. Up and running in minutes.
Annual plans are billed by invoice (bank transfer). Confirmation arrives within 1 business day.
| Plan | Basic €249 /month ≈ €25 per supplier/month | Pro €449 /month ≈ €18 per supplier/month | Advanced €799 /month ≈ €16 per supplier/month | Enterprise By agreement custom contract |
|---|---|---|---|---|
| Monitored supplier domains | 10 | 25 | 50 | 50+ |
| Subdomains actively scanned (per root domain) | 50 | 50 | 50 | ∞ |
| IP addresses & CIDR ranges (per supplier) | 1 | 5 | 10 | ∞ |
| Own domains, checked and maintained | 3 | 5 | 10 | 25 |
| Maintenance: the exact fix for each gap, due dates, verification after the change, renewal calendar and DMARC project | ||||
| Ransomware every 6 h, infostealer monitoring daily | ||||
| 100+ checks per monitored domain & subdomains | ||||
| On-demand NIS2 report (save as PDF) | ||||
| Email alerts for critical findings | ||||
| Email security monitoring: named sending services, lookalike domains, DMARC & MTA-STS enforcement guidance, TLS encryption (TLS-RPT), blocklist reputation | ||||
| Supplier SAQ (self-assessment questionnaire) | ||||
| NIS2 audit evidence export (CSV) | ||||
| Full Scan add-on (monthly external assessment) | +€299/month | +€299/month | +€299/month | Available |
| Start free | Start free | Start free | Contact us |
Free
€0For collecting supplier self-assessments
- Up to 10 suppliers on your list, with suggestions from your own email and website
- Send the 41-question NIS2 questionnaire in 8 languages
- Answers, scores and section breakdown
- Each supplier gets their own scored result
- Public checks on your own domain, with the exact fix for each gap
- Email-security monitoring (DMARC, TLS-RPT) for one domain, with an email when a new service starts sending as it
- One colleague with read access
Visible, but part of a subscription
- Continuous scanning of your suppliers
- Checking those answers against what we observe
- Alerts, NIS2 reports, portfolio view and audit pack
- Additional domains, with email findings attached to the supplier they concern
What free means here
The free plan is not a trial: it does not expire and asks for no card. It works with information that already exists: your suppliers' own answers, and the authentication reports your domain already receives. Free puts that in one place, scored and comparable. We use no analytics, advertising or tracking cookies, and data is stored in the EU.
A subscription is the other half of an assessment: going out and checking, continuously, instead of taking an answer at face value. Nine of the 41 questions can be verified against what a supplier's infrastructure publicly shows, and a supplier's security keeps changing long after the questionnaire is filed.
Need deep infrastructure monitoring without supplier tracking?
Active Monitor
per month
Continuous monitoring for your own domain: ransomware victim lists, dark web credential leaks, DNS health, certificate status, breach exposure, and HTTP security checks, plus one monthly external security assessment covering port exposure, vulnerability risks and TLS configuration. For companies that need comprehensive external security monitoring without supplier tracking.
Being assessed by your NIS2 customers? See how norppa.io helps suppliers →Add monthly Full Scan to any monitoring plan
A comprehensive monthly external security assessment of your own domain, added to your existing monitoring plan. Goes beyond the daily automated checks — exposed port and service discovery, TLS/SSL configuration assessment, known vulnerability exposure (CVE/EPSS), subdomain analysis, WAF detection. Performed entirely from the public internet — no integration with your infrastructure required. All findings included in your on-demand NIS2 report.
Example pricing:
• Basic + add-on = €548/mo
• Pro + add-on = €748/mo
• Advanced + add-on = €1,098/mo
Up and running in five minutes. Your NIS2 report on demand after the first scans.
Add your suppliers and your own domain
Enter a company name and domain, and add your own domain the same way. We also suggest services that your own email and website show are already in use. Your whole list takes about five minutes, no integrations, no API keys, no IT project.
Monitoring starts with your subscription
Ransomware victim tracking, dark-web credential leaks, certificate health, company-registry status and CVE exposure — checked daily across your suppliers and your own domain, with nothing to configure.
Critical findings trigger instant alerts
An email the same day we detect a ransomware listing, a dark-web credential exposure, or a certificate expiring in under 14 days — so you act as risks emerge.
NIS2 compliance report on demand
A NIS2 report in your dashboard, on demand: every finding mapped to its NIS2 article with the concrete gap named, not just a score, plus supplier rankings and a plain-language executive summary. Save or print as PDF, audit-supporting from your first scans.