EUSEC
Dashboard
Pricing Services Insurance
Supply Chain Security:
A must-do required by NIS2.

Secure Your Future|

Built on 26,000+ supplier assessments.

Cyber Risk Rating

Bad Security Ltd.

OUTLOOK: NEGATIVE
ID: EU-XX-55214
C
Cyber Risk Rating

SAP SE

OUTLOOK: STABLE
ID: EU-DE-11042
AAA
Cyber Risk Rating

Airbus Group

OUTLOOK: STABLE
ID: EU-FR-88120
AAA
Cyber Risk Rating

Vulnerable Vendor

OUTLOOK: NEGATIVE
ID: EU-UK-11042
B
Cyber Risk Rating

Siemens Energy AG

OUTLOOK: STABLE
ID: EU-DE-99120
AAA

Latest Ratings

Latest EUSEC cyber security ratings of European companies, with the option to request your own rating.
Company Name Industry Outside Rating Inside Rating
Siemens Energy AG Energy AAA
SAP SE Software AAA
Airbus Group Aerospace AAA

Built for the realities of modern supply chains

Fragmented security questionnaires unified into one cyber rating standard
The standard

One standard in a fragmented landscape

Security data is scattered across questionnaires, frameworks and regions. EUSEC brings it together — one connected cyber security rating built on a common standard that turns complexity into comparable scores.

Cyber risk methodology aligned to ISO 27001, NIST CSF and BSI IT-Grundschutz
Methodology

Built with AI. Verified by experts.

Every rating combines large-scale signal analysis with a methodology aligned to ISO 27001, NIST CSF and BSI IT-Grundschutz — then reviewed and verified by in-house security analysts.

Analysing millions of cyber threat intelligence signals across Europe
The dataset

Built on one of Europe's largest cyber intelligence datasets

5M
Signals analysed every month
180K
Sources monitored
44
Jurisdictions covered
Prioritised remediation and continuous monitoring of supplier cyber risk
From score to action

Built to drive real change, not just measure it

A rating is only the starting point.

One connected system

A connected system for your entire supply chain

Bring cyber security ratings, signals and insights into one place — making cyber performance and third-party risk across your supply chain visible, comparable and defensible.

26,000+
Assessments completed
27
EU member states
18
NIS2 sectors covered
180K
Sources monitored

Start rating your supply chain today

Map cyber risk across 100% of your supplier and vendor base instantly. Know exactly where third-party risk sits — and where to focus — before an incident makes the headlines.

Supply chain risk mapping
Mapping cyber risk across the entire supplier and vendor base
Automated third-party and vendor risk management workflow

Less admin. More insight.

Standardised cyber security ratings and automated workflows cut manual questionnaires and turn fragmented supplier data into one clear, comparable view of security performance.

The rating platform

Stay ahead of regulation

Map supplier performance to NIS2 Article 21, §30 BSIG and DORA through one connected system — simplifying complex supply chain security requirements into a single, clear overview.

Regulatory compliance
Mapping suppliers to NIS2, §30 BSIG and DORA requirements

Rate once. Unlock everywhere.

Complete a single cyber security rating and get a trusted, comprehensive view of your security posture — ready to share with your entire customer network.

The value of a rating
A single security rating shared across a customer network
Meeting customer and regulatory security requirements with one rating

Stay eligible to do business

Meet customer and regulatory requirements with a single standardised rating — without repeating the same security questionnaire for every request.

Grades & recognition

Turn your rating into growth

Use your EUSEC rating and grade to stand out, strengthen your reputation and win new business with security-conscious customers.

Benchmark against your industry
Benchmarking a company's security rating against its industry

Built for every NIS2 sector

Energy Transport Banking Financial Market Infrastructure Health Drinking Water Waste Water Digital Infrastructure ICT Service Management Public Administration Space Postal & Courier Waste Management Chemicals Food Manufacturing Digital Providers Research
FAQ

Cyber security ratings, NIS2 & §30 BSIG — explained

Straight answers for CISOs, security teams and procurement on supplier ratings, third-party risk and EU supply chain compliance.

What is a cyber security rating?

A cyber security rating is an objective, data-driven score that measures how well an organisation protects its systems and data — similar to a credit rating, but for cyber risk. EUSEC ratings run from AAA (strongest) downward, are derived from millions of external signals, aligned to ISO 27001, NIST CSF and BSI IT-Grundschutz, and verified by security analysts, so buyers can compare suppliers on one common standard.

How does EUSEC help prove NIS2 Article 21 and §30 BSIG supply chain security?

NIS2 Article 21 and §30 Abs. 2 Nr. 4 BSIG require in-scope companies to manage the security of their suppliers and service providers. EUSEC rates every company in your supply chain, documents each supplier's cyber posture, and gives you a defensible, continuously updated record — the evidence auditors and the BSI expect for supply chain risk management.

What does §30 BSIG require for supplier and vendor security?

§30 BSIG lists ten mandatory risk-management measures; measure four is supply chain security, covering the security of direct suppliers and service providers. In-scope organisations must assess supplier-specific vulnerabilities, the overall quality of their vendors' cyber practices, and document the results. Since the BSIG (NIS2 Umsetzungsgesetz) took effect on 6 December 2025 with no transition period, these obligations apply now.

How do I assess the cyber security of my suppliers?

Start by mapping every supplier and third party with system or data access, then score each one's external cyber posture instead of relying on slow questionnaires. With EUSEC you rate up to ten companies for free, receive a grade per supplier, and prioritise the weakest first — turning a fragmented vendor base into one comparable, continuously monitored view of third-party risk.

How is a EUSEC rating calculated?

Each EUSEC rating combines large-scale analysis of external signals — over five million per month across 180,000 sources — with a methodology aligned to ISO 27001, NIST CSF and BSI IT-Grundschutz. In-house security analysts then review and verify every rating, so the resulting AAA-to-lower grade is comparable across 27 EU jurisdictions and defensible in audits and procurement decisions.

What does my company need to do to get rated?

Nothing complex. Suppliers can claim a single EUSEC rating and reuse it across their entire customer network, instead of answering a new security questionnaire for every buyer. A rating gives your customers a trusted view of your security posture, helps you stay eligible for contracts under NIS2 and §30 BSIG, and lets you benchmark against your industry.

How much does EUSEC cost?

EUSEC lets you rate up to ten companies for free — no credit card, no account, and no automatic subscription. Confirmation, status updates and reports are delivered to your inbox, and you upgrade only when you are ready to rate a larger supplier base. This makes it straightforward to start mapping supply chain cyber risk today.

How is EUSEC different from other security ratings providers?

EUSEC is a European cyber rating agency built specifically around EU regulation — NIS2 Article 21, §30 BSIG and DORA — and standards such as ISO 27001, NIST CSF and BSI IT-Grundschutz. Ratings are generated at scale and then verified by in-house analysts, combining broad coverage of 26,000+ companies with expert review, so scores are both comparable and defensible for supply chain compliance.

Does EUSEC support DORA and TISAX requirements?

Yes. Beyond NIS2 and §30 BSIG, EUSEC ratings help financial entities address third-party ICT risk under DORA and support supplier assurance alongside frameworks such as TISAX in the automotive sector. One standardised rating maps supplier cyber performance to several regulations at once, reducing duplicate assessments across your supply chain.

Get started

10 company ratings, free.

No credit card. No account. Cyber security ratings delivered straight to your inbox.

>