EUSEC
Dashboard
Pricing Services Insurance

FAQ.

Exhibit 01 — Scope & liability

Does this apply to us — and who carries the risk?

Q.01

“Are we affected by NIS2?”

Probably more than you'd hope. In Germany the NIS2 Implementation Act has been in force since 6 December 2025 — with no transition period, covering roughly 29,500 entities across 18 sectors (from about 50 staff or €10M turnover). But scope cascades: even if your own company sits below the threshold, any in-scope customer is legally obliged to manage the security of its suppliers — which includes you. You're rarely fully "out" — either directly obligated or pulled in through someone else's chain. Our two-minute NIS2 check settles it quickly.

In short Directly in scope, or in a customer's — either way it reaches you.
Q.02

“We're too small. Nothing will happen.”

Size shields you from direct supervision, not from the supply chain. Larger customers must vet and monitor their suppliers no matter how small — so the security questions arrive whether or not you're personally in scope. And operational risk is indifferent to headcount: a single compromised small vendor is one of the most common ways large organisations get breached. "Nothing will happen" bets against both your customers' procurement rules and your own attackers.

In short Too small to be audited — never too small to be the way in.
Q.03

“What exactly does NIS2 require of us?”

Ten core risk-management measures under § 30(2) BSIG — risk analysis, incident handling, business continuity, supply-chain security (no. 4), secure procurement, effectiveness reviews, cyber hygiene and training, cryptography, access control and MFA — plus registration with the BSI (§ 33), incident reporting on a 24h / 72h / 1-month clock (§ 32), management approval, oversight and training (§ 38), and ongoing evidence and supervision (§§ 39 / 61 / 62). Nine of the ten sit inside your own walls. The structural exception is supply-chain security: you must assess and manage the posture of companies you don't control — and document it.

In short Nine duties you control. The tenth — your supply chain — you must also prove.
Q.04

“Who is liable?”

Management — by design. Under § 38 BSIG the management body must approve and oversee the risk-management measures, and that duty cannot be delegated away to IT or a provider. Breaches can trigger fines up to €10M or 2% of worldwide annual turnover for essential entities (€7M or 1.4% for important ones), on top of personal accountability for leadership. You can size your own exposure with our fine & liability calculator.

In short § 38 BSIG points at the management body — personally, with no delegating it away.
Q.05

“Will the authority (e.g. BSI) audit us?”

It depends on your classification. Essential entities can be asked for evidence and audited at any time, without cause (§§ 61/62 BSIG); important entities are typically examined reactively, after an incident or on specific suspicion; KRITIS operators have a fixed three-year cycle (§ 39). Most NIS2 entities have no fixed audit date — which is why the only safe posture is to keep your supply-chain documentation current and producible on demand, rather than reconstructing it from email chains under pressure.

In short No fixed date — so the only safe posture is audit-ready every day.
Exhibit 02 — “We already have…”

Each of these is real — and each leaves the same gap.

Q.06

“We have already ISO 27001.”

Excellent — for your organisation. But an ISO 27001 certificate attests to your own management system, not to the security of the suppliers NIS2 asks you to oversee. It's also point-in-time, renewed over years, while threats move daily. EUSEC doesn't replace ISO 27001 — it extends that diligence outward across your supply chain and keeps it continuous. (A supplier's own ISO 27001 certificate can even satisfy the deep-audit step for your most critical A-tier vendors.)

In short ISO certifies you. NIS2 asks about everyone you depend on.
Q.07

“We use questionnaires already.”

Then you already know their limits: low response rates, self-reported answers, and a snapshot that's stale the moment it's filed. A questionnaire records what a supplier says — not what an attacker can see. EUSEC rates your whole portfolio from the outside in hours, including suppliers who never reply, and then flags exactly where the questionnaire's claims and the external evidence disagree. It doesn't bin your questionnaires; it verifies them — and cuts the back-and-forth on both sides.

In short Questionnaires capture claims. We capture the gap to reality — continuously.
Q.08

“We have already a GRC tool.”

Keep it. A GRC platform manages process — workflows, policies, evidence collection — but it generally doesn't generate the underlying security signal; it waits to be fed. EUSEC is that data layer: independent, evidence-based supplier ratings, exportable as a CSV audit trail or piped in through our API (a 20% add-on) straight into your GRC or TPRM platform. One orchestrates; the other observes.

In short Your GRC tool manages the data. We produce it.
Q.09

“We have cyber insurance.”

Insurance transfers cost after an incident; it doesn't prevent one, and it doesn't discharge NIS2's preventive duties under § 30. Insurers are tightening the rules, too — increasingly requiring evidence of supply-chain risk management as a condition of cover, and reducing payouts where due diligence was missing. Continuous ratings support both sides: fewer incidents, and the documentation your insurer now expects.

In short A policy pays after. NIS2 — and your insurer — want proof you acted before.
Exhibit 03 — What EUSEC is, and isn't

A rating agency — not a certificate, not a badge.

Q.10

“Is this a NIS2 certification?”

No — and be wary of anyone selling one. NIS2 creates no certificate, and no private party can certify NIS2 conformity; that judgement rests with the authority alone. What EUSEC delivers is an independently verified maturity assessment backed by evidence, plus audit-ready documentation of your supply-chain measures — as a record of due diligence that is often stronger than a narrow seal. But it is not a legal certificate, and we never claim to "certify NIS2 compliance" on your behalf.

In short There's no NIS2 certificate. There's evidence — and that's what we deliver.
Q.11

“What is your methodology based on?”

Two complementary lenses, resolved into one scale. The Outside Rating assembles observable evidence across 10 risk dimensions — domain & email authentication, transport encryption, web surface, breach history and more — entirely non-intrusively, plus a documented sector-and-entity calibration. The Inside Rating is a structured self-disclosure scoped to your NIS2 status (7, 11 or 15 criteria) and scored on the BSI maturity model (RUN). Both produce one grade from AAA to C with a forward-looking outlook, weighted by your ABC criticality tiers. The scoring core comes out of the Cyber Risk Score research project with TH Rosenheim.

In short Two lenses — observed and declared — on one AAA-to-C scale.
Q.12

“Is an outside rating actually defensible as § 30 evidence?”

Yes. § 30 BSIG requires risk-based, proportionate supply-chain measures — not a full audit of every supplier. For your long tail (C-tier), a documented, repeatable, automated outside rating is exactly that kind of proportionate measure — much as Creditreform's scoring is for commercial credit risk — while critical suppliers get deeper inside ratings and audits. EUSEC publishes its methodology, commits to the US Chamber of Commerce Principles for Fair and Accurate Security Ratings, and gives you exportable § 30 documentation built to hold up in front of the BSI, your insurer or the board.

In short § 30 wants proportionate, documented diligence — exactly what an outside rating is.
Q.13

“Are you recognised by, or official with, the BSI?”

NIS2 defines no official accreditation for rating providers, so no "BSI-approved" status exists to hold — for us or anyone else. EUSEC is an independent rating agency, modelled on the credit-rating agencies rather than on a consultancy. Our methodology is mapped to recognised reference points — ENISA Technical Implementation Guidance, CIR (EU) 2024/2690 and ISO/IEC 27001 — so our output speaks the language your obligations are written in. We point to those standards for orientation; we claim no authority's endorsement of us.

In short No badge to claim — a published method you can check, built on the credit-agency model.
Exhibit 04 — Lawful, fair & reliable

The concerns every security and legal team raises.

Q.14

“Is it legal for you to rate our suppliers without their consent?”

Yes — and it's lawful by design. An Outside Rating reads only what is public or voluntarily disclosed by a server, record or document; there is no exploitation and no break-in. EUSEC's legal opinion finds no offence under §§ 202a/202b/303a StGB and no trade-secret breach under the GeschGehG. Most signals are technical data of legal persons, outside the GDPR entirely; for the few personal inputs, the basis is Art. 6(1)(f) GDPR — legitimate interest, the same footing SCHUFA, Creditreform and Dun & Bradstreet have used for decades. Inside ratings, by contrast, are always invitation-based.

In short We read only what's already public — no break-in, on a credit-agency legal basis.
Q.15

“How reliable are the ratings — what about false positives?”

A rating is an informed opinion built on evidence — not a guarantee, and not a penetration test. Every outside finding is traceable: you can drill from the grade down to the specific signal behind it, rather than trusting a black box. False positives are minimised by validation and by the discrepancy check between the outside view and a supplier's inside self-assessment, and the outlook shows whether posture is improving or eroding over time. It's a risk indicator — which is why critical suppliers are escalated to inside ratings and audits for confirmation.

In short An informed opinion you can trace to its evidence — not a guarantee, not a pen test.
Q.16

“Can a supplier dispute or challenge a rating?”

Yes — fairness is built in. Any rated company can open a dispute: we correct inaccurate inputs and re-assess on new evidence, and the rights to object, rectify and access (Art. 21/16/15 GDPR) run through the same channel. Crucially, every adverse grade (B or worse) is held for roughly 14 days before it's shared with other subscribers, giving the supplier a fair chance to respond first. So a poor result never circulates behind a supplier's back — which also keeps your supplier relationships intact.

In short Every adverse grade gets a 14-day right to reply — plus a standing dispute channel.
Exhibit 05 — Data, security & suppliers

Where your data lives, how we protect it, what suppliers must do.

Q.17

“How is our data handled — where is it stored, do we need a DPA/AVV?”

All processing happens within the EU, in line with the GDPR and BDSG, and there is no data transfer to third countries. A data-processing agreement (DPA / AVV) is available — provided directly in your customer account, with the technical and organisational measures (TOMs) in its Annex and reviewed by an external auditor (currently TÜV Rheinland). Outside ratings draw only on publicly observable data; anything you or your suppliers submit for inside ratings is used solely to produce your assessments.

In short EU-processed, GDPR-aligned, DPA/AVV in your account — confirmed before you start.
Q.18

“How do you secure the data we entrust to you — and is EUSEC itself certified?”

We hold ourselves to the standard we measure others against. EUSEC runs an ISMS aligned with ISO/IEC 27001:2022, owned and reviewed by management annually, with data encrypted at rest and in transit, enforced MFA, least-privilege access, a secure development lifecycle and independent penetration testing. Everything runs on EU-hosted, hardened infrastructure (Hetzner) carrying ISO/IEC 27001:2022, BSI C5 Type 2, KRITIS/§ 8a BSIG and PCI DSS v4 attestations — and our staff hold EU citizenship. The current subprocessor list is available to customers on request.

In short We hold ourselves to the standard we measure others against — EU-hosted, ISO 27001-aligned.
Q.19

“Do our suppliers have to pay or do anything — and do we need an NDA?”

For an Outside Rating, your supplier does nothing — no onboarding, no participation, results in hours. An Inside Rating is invitation-based: the supplier completes a short 7–15 question self-disclosure. No bilateral NDA is required — the platform terms create a three-party confidentiality framework (EUSEC keeps supplier data confidential from unauthorised parties; you commit to using inside data solely for your own § 30 compliance), and a standard NDA PDF is available if their counsel asks. Suppliers gain something, too: one verified rating they can reuse across all their customers instead of answering endless questionnaires.

In short Your suppliers do nothing for an outside rating — and no bilateral NDA is needed.
Exhibit 06 — Make, buy & price

The commercial question, answered without the dance.

Q.20

“Make or buy?”

You can build it in-house, but the bill is larger than it looks — scanning infrastructure, threat-intelligence feeds, analysts and their relentless upkeep, multiplied across every supplier — and scanning vendors yourself is resource-intensive and legally fraught. Buying gives you full coverage from day one, consistent and comparable scores, clean lawful data on a credit-agency basis, and something an internal team structurally can't provide: an independent, third-party view your customers and auditors will actually credit.

In short Building is possible. An independent, lawful outside view isn't something you can build.
Q.21

“What does it cost?”

It scales with risk, and you can start free — 10 company ratings, no credit card and no account, results in hours. Beyond that, pricing is linear and transparent: €149 per supplier per year, with automatic volume discounts (€129 from 51, €109 from 251, custom above 500) and a 15-supplier minimum. There are no tier games — your ABC classification sets monitoring intensity, never your invoice — and we rate an organisation, not a domain count (subdomains and up to three TLDs are included). An optional API integration adds 20%.

In short €149 per supplier, linear, start free — your tier sets intensity, never the invoice.
Exhibit 07 — Trust & continuity

Trust earned by verifiability — and protected if we're gone.

Q.22

“Is EUSEC really independent?”

Structurally, yes — independence is the product. EUSEC is modelled on the credit-rating agencies: we run no consulting or remediation business on the side (a firewall, on purpose), and Outside Ratings are unsolicited and subscriber-funded — the rated company is neither our customer nor our paymaster. No one can pay to raise, lower or suppress a grade; the nine inside areas carry equal, disclosed weighting; and the model is automated, with expertise built in rather than case-by-case discretion that could be lobbied. Disagreements go through a transparent 14-day appeal.

In short We rate. We don't sell what we rate, and no one can pay to move a grade.
Q.23

“Why should we trust EUSEC?”

Because trust here rests on verifiability, not authority. The methodology is published, every finding traces back to its evidence, the scoring core is grounded in the Cyber Risk Score research with TH Rosenheim, and the legal basis has been examined by counsel rather than assumed. Your data stays EU-hosted under the GDPR, and we're honest about our limits — we don't certify compliance, and we label an automatic outside rating distinctly from a verified, audited one. Follow any grade down to the signal that produced it: trust the method, then trust the result.

In short Don't trust us — trust the method, the evidence, and the research behind it.
Q.24

“What if EUSEC stops operating?”

Your continuity is protected by design. Your supplier data, ratings and the full audit trail are exportable (CSV), so you keep what you've built. And because the assessment rests on open, recognised standards — not a proprietary secret — the approach is reproducible elsewhere; you're never locked into a method only we understand. Data export and continuity are addressed directly in our contractual terms.

In short Your data is exportable and the method is open — no lock-in, by design.
Didn't find it?

A question we haven't answered here?

Ask it directly. We'll answer in plain language — and if it belongs to your legal or procurement team, we'll tell you that too, rather than pretending otherwise.

Scalable. Trusted.

10 company ratings — free. Start today.

No credit card. No account required. Zero obligation.
Results delivered straight to your inbox.