Supply Chain Monitoring
Know which supplier puts you at risk — and be able to prove it.
A supplier goes down — do you know what depends on them at your organization?
“If my IT provider goes down, I don’t know what’s at stake for us — and I can’t prove that I have my suppliers under control either.” That is how managing directors and CISOs at mid-sized companies describe their situation the moment a customer questionnaire or a supervisor asks specifically about the supply chain. NIS2 Art. 21(2)(d) (§ 30(2) no. 4 BSIG), DORA Art. 28–29, and ISO 27001 A.5.19 all demand the same answer: suppliers and service providers must be assessed, managed, and demonstrably under control — and enterprise customers ask the very same thing through their own security questionnaires.
Most companies do have a list — but not one that holds up under this pressure. A spreadsheet of suppliers is quick to set up, but it goes stale the moment no one actively maintains it: no traceable justification for the criticality rating, no version history, no proof of who last reviewed it and when. At the next audit, that is exactly what counts.
What counts is a register that does both at once: assess and prove. Every criticality rating traceably justified, every state cryptographically sealed, independently verifiable — for NIS2, DORA, and ISO 27001 from the same data foundation, instead of maintained three times separately.
Five building blocks that turn a list into a register of proof.
Supplier register with AI-assisted criticality
Every supplier is assigned a criticality tier with AI assistance — with a rationale you can review and correct if needed, never a black-box result. An approval workflow ensures a rating only becomes binding after sign-off.

Concentration risk analysis
Concentrations by provider and country are calculated under DORA Art. 29, exposing single points of failure — the result is sealed, instead of disappearing as a one-off snapshot in a slide deck.

Supplier questionnaires
Questionnaires go out directly to suppliers, and answers come together in the portal. Customer questionnaires that arrive at your own organization are answered from the same pool of data — one data foundation for both directions.

Sealed evidence
Every state of the register is cryptographically sealed (RSA signature plus RFC 3161 timestamp) and independently verifiable — a single piece of evidence that counts for NIS2, DORA, and ISO 27001 at once, instead of being created three times separately.

AI contract review against mandatory controls
Upload supplier contracts — the AI reviews clause by clause whether the required controls are covered, with source location, quote, and confidence score. No finding is adopted without your confirmation, and the result is sealed as evidence. Today for the 47 DORA contractual requirements (Art. 30); catalogs for NIS2 and further regimes are on the way.

More on supply chain security and the engine behind it.
What Art. 21(2)(d) requires for assessing suppliers and service providers.
NIS2 & supply chain — what Art. 21 requires →How supplier register, criticality, and concentration risk work together technically.
Feature details →