Supplier portal
One security questionnaire for all your customers.
Your customers fall under NIS 2 and have to check how securely their suppliers work. So they send you security questionnaires, each one in a different format. Here you answer the questions once and release them to every customer who invites you. Open Source, no lock-in.
Does your own company fall under NIS 2? Check applicability.
NIS 2 Directive (EU) 2022/2555 · CIR 2024/2690 · ENISA TIG v1.0

How it works
1Create the profile
Sign in, enter your company name and domain. The profile belongs to you, not to one of your customers.
2Answer once
59 questions on security management, certification, incident plans, access, and contract clauses. Every question names the paragraph it rests on. Drafts are saved as you go.
3Invite customers
Each customer gets their own private link. They see your profile, the systems you run for them, and your certificates. They do not need an account.
4Report incidents
If a customer's system is affected, you report it from inside the portal. Only that one customer sees the report. It is how they meet their Article 21(2)(d) duty to keep an eye on their suppliers.
What gets asked
The structure follows ENISA's NIS2 Technical Implementation Guidance v1.0 from June 2025. Every question names the paragraph in CIR 2024/2690 or BSI IT-Grundschutz it rests on. An auditor recognises the structure, so you do not have to invent one. The question set is public on GitHub.
nis2-supply-chain-questionnaire-schema- Identity and contact
- Legal name, address, domain, and who a customer reaches when something goes wrong. Plus the window you commit to responding in.
- Security practice
- How your company runs information security: management system, certification, training, vulnerability handling, access, continuity planning.
- Contract terms
- Right to audit, data processing agreement, subprocessors, return of data at the end of the contract, notification of material changes.
- Type of service
- SaaS, software on the customer's premises, professional services, or managed services. You only answer the questions that match your business.
- Certificates
- Upload ISO 27001, BSI Grundschutz, or an equivalent as a PDF. Customers see how long it stays valid.
Bilateral and private
There is no public supplier directory. Only the customers you release it to can see your profile, and each of them can end their own access. No public address, no search engine indexing.
„Wir begrüßen aktuelle Vorstöße der Wirtschaft, einen einheitlichen Fragenkatalog für Lieferanten zu erarbeiten."
We welcome current industry initiatives to develop a unified question set for suppliers.
Why free?
The supplier portal costs nothing and the code is open. We earn from training and hands-on implementation work, not from your data. Platform and question set are on GitHub, so you can check for yourself.
Ready in two minutes.
Sign in, enter your company name and domain, work through the questionnaire at your own pace. When you are ready, invite your customers.
Create supplier profile