Skip to content

NIS2 Supplier Check

Free NIS2 supplier check – evidence for your customers in 10 minutes.

Your customer wants proof of your supply-chain security? Check your domain for free and get a report you can attach right away.

  • Technically verified, not just self-declared
  • Mapped to NIS2 Article 21(2) and Section 30 BSIG
  • Free, with data stored in the EU

Must belong to the domain. No free-mail addresses.

Before verification we only read public DNS records, do one TLS handshake and load your home page.

What your report contains

  1. Section 1

    Cover page with a QR code for authenticity checks

  2. Section 2

    Summary with grade A–F and the top three actions

  3. Section 3

    NIS2 mapping (a)–(j): technically verified or self-declared

  4. Section 4

    Action plan with instructions for nginx, Microsoft 365, Cloudflare and more

Frequently asked questions

What is checked?

23 technical indicators from the outside (TLS, security headers, SPF/DMARC/DKIM, DNSSEC, subdomains, exposed files) plus 15 questions about organisational measures.

Is this a certification?

No. The report documents indicators and self-declared answers as of a date. It is not an audit and not a seal.

Is the scanning legal?

We only check passively and read-only, and the full check runs only after you prove the domain is yours with a DNS record.

Where is my data stored?

In the EU (AWS eu-central-1, Frankfurt).

Who sees my report?

Only you. Your customer's authenticity page shows only the report ID, domain and date.

How do I delete my data?

Click "Delete all data" in your account.