Supplier readiness check.
Two scopes — pick one inside the tool. Supply chain (default · 20 questions, ~5 min) covers documentation foundations, operational practice, supply-chain transparency, and buyer-relationship readiness — what NIS2-driven buyer questionnaires ask first. Full NIS2 (35 questions, ~8-10 min) adds dedicated coverage of vulnerability handling, cryptography depth, and cyber hygiene / access / secure communications — the deeper questions regulated buyers increasingly send. Reference-anchored (NIS2, GDPR, ISO 27001) gap report at the end.
Honest framing: this is a directional steer for how prepared you are to answer the next NIS2-driven assurance questionnaire from a regulated buyer. Sister to the buyer-side NIS2 readiness check.
Two scopes available: Supply chain (default — twenty questions, what buyers ask first) or Full NIS2 (thirty questions, adds vulnerability handling + cryptography depth — the deeper questions NIS2-regulated buyers increasingly send). Three answers per question. Your inputs stay in your browser; each item is anchored to the framework reference (NIS2, GDPR, ISO 27001) it draws on so you can verify the framing.
Documentation foundations
The artefacts a buyer expects to find on day one — security policy, attestation status, named ownership.
Do you have a written information security policy with version control and a documented annual review cycle?
ISO 27001 A.5.1 / NIS2 21(2)(a)Do you hold a current independent attestation (SOC 2 Type II, ISO 27001, or equivalent) — or have a defined plan with a date?
Attestation disciplineIs there a named individual (not a department) accountable for security at executive level — appearing on customer-facing trust documents?
NIS2 20 / governanceDo you maintain a customer-facing trust surface (a /trust page, a security overview PDF, or equivalent) that is current within the last 6 months?
Trust transparencyDo you have a standard Data Processing Agreement (Article 28-compliant) you can share without a legal-review cycle?
GDPR Art. 28