Use Case Use Cases / Supply Chain

Supply Chain Monitoring

Know which supplier puts you at risk — and be able to prove it.

Why this matters

A supplier goes down — do you know what depends on them at your organization?

“If my IT provider goes down, I don’t know what’s at stake for us — and I can’t prove that I have my suppliers under control either.” That is how managing directors and CISOs at mid-sized companies describe their situation the moment a customer questionnaire or a supervisor asks specifically about the supply chain. NIS2 Art. 21(2)(d) (§ 30(2) no. 4 BSIG), DORA Art. 28–29, and ISO 27001 A.5.19 all demand the same answer: suppliers and service providers must be assessed, managed, and demonstrably under control — and enterprise customers ask the very same thing through their own security questionnaires.

Most companies do have a list — but not one that holds up under this pressure. A spreadsheet of suppliers is quick to set up, but it goes stale the moment no one actively maintains it: no traceable justification for the criticality rating, no version history, no proof of who last reviewed it and when. At the next audit, that is exactly what counts.

What counts is a register that does both at once: assess and prove. Every criticality rating traceably justified, every state cryptographically sealed, independently verifiable — for NIS2, DORA, and ISO 27001 from the same data foundation, instead of maintained three times separately.

What you get

Five building blocks that turn a list into a register of proof.

Supplier register with AI-assisted criticality

Every supplier is assigned a criticality tier with AI assistance — with a rationale you can review and correct if needed, never a black-box result. An approval workflow ensures a rating only becomes binding after sign-off.

Supplier register with AI criticality, LEI and contract data in ReportAct

Concentration risk analysis

Concentrations by provider and country are calculated under DORA Art. 29, exposing single points of failure — the result is sealed, instead of disappearing as a one-off snapshot in a slide deck.

Interactive supply chain graph with a detected risk at a sub-supplier in ReportAct

Supplier questionnaires

Questionnaires go out directly to suppliers, and answers come together in the portal. Customer questionnaires that arrive at your own organization are answered from the same pool of data — one data foundation for both directions.

Security questionnaires with supplier responses in ReportAct

Sealed evidence

Every state of the register is cryptographically sealed (RSA signature plus RFC 3161 timestamp) and independently verifiable — a single piece of evidence that counts for NIS2, DORA, and ISO 27001 at once, instead of being created three times separately.

Sealed evidence with signature and timestamp in ReportAct

AI contract review against mandatory controls

Upload supplier contracts — the AI reviews clause by clause whether the required controls are covered, with source location, quote, and confidence score. No finding is adopted without your confirmation, and the result is sealed as evidence. Today for the 47 DORA contractual requirements (Art. 30); catalogs for NIS2 and further regimes are on the way.

AI-assisted contract clause review under DORA Art. 30 in ReportAct
Learn more

More on supply chain security and the engine behind it.

NIS2 & the supply chain — what Art. 21 requires

What Art. 21(2)(d) requires for assessing suppliers and service providers.

NIS2 & supply chain — what Art. 21 requires →
Vendor Intelligence — the engine behind it

How supplier register, criticality, and concentration risk work together technically.

Feature details →
Next step

Your first sealed supplier register — today.

No-obligation intro call · 30 minutes