Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Supplier overview
Free · Interactive · 5 minutes

Supplier readiness check.

Two scopes — pick one inside the tool. Supply chain (default · 20 questions, ~5 min) covers documentation foundations, operational practice, supply-chain transparency, and buyer-relationship readiness — what NIS2-driven buyer questionnaires ask first. Full NIS2 (35 questions, ~8-10 min) adds dedicated coverage of vulnerability handling, cryptography depth, and cyber hygiene / access / secure communications — the deeper questions regulated buyers increasingly send. Reference-anchored (NIS2, GDPR, ISO 27001) gap report at the end.

Honest framing: this is a directional steer for how prepared you are to answer the next NIS2-driven assurance questionnaire from a regulated buyer. Sister to the buyer-side NIS2 readiness check.

Two scopes available: Supply chain (default — twenty questions, what buyers ask first) or Full NIS2 (thirty questions, adds vulnerability handling + cryptography depth — the deeper questions NIS2-regulated buyers increasingly send). Three answers per question. Your inputs stay in your browser; each item is anchored to the framework reference (NIS2, GDPR, ISO 27001) it draws on so you can verify the framing.

Scope
Switch between what buyers ask first (supply-chain) and full Article 21(2) coverage. Your answers persist across both.
Progress
0%
0/20
Category breakdown
Documentation foundations0/5
Operational practice0/5
Supply-chain transparency0/5
Buyer-relationship readiness0/5
Score so far
0 / 40
References touched
NIS2 20NIS2 21(2)(a)NIS2 21(2)(b)NIS2 21(2)(c)NIS2 21(2)(d)+5
20 remaining to unlock your readiness band and gap report. Use the sidebar to jump between categories.
01/

Documentation foundations

The artefacts a buyer expects to find on day one — security policy, attestation status, named ownership.

0/5 answered0%
Score · 0/10
01

Do you have a written information security policy with version control and a documented annual review cycle?

ISO 27001 A.5.1 / NIS2 21(2)(a)
02

Do you hold a current independent attestation (SOC 2 Type II, ISO 27001, or equivalent) — or have a defined plan with a date?

Attestation discipline
03

Is there a named individual (not a department) accountable for security at executive level — appearing on customer-facing trust documents?

NIS2 20 / governance
04

Do you maintain a customer-facing trust surface (a /trust page, a security overview PDF, or equivalent) that is current within the last 6 months?

Trust transparency
05

Do you have a standard Data Processing Agreement (Article 28-compliant) you can share without a legal-review cycle?

GDPR Art. 28