Probably more than you'd hope. In Germany the NIS2 Implementation Act has been in force since 6 December 2025 — with no transition period, covering roughly 29,500 entities across 18 sectors (from about 50 staff or €10M turnover). But scope cascades: even if your own company sits below the threshold, any in-scope customer is legally obliged to manage the security of its suppliers — which includes you. You're rarely fully "out" — either directly obligated or pulled in through someone else's chain. Our two-minute NIS2 check settles it quickly.
Size shields you from direct supervision, not from the supply chain. Larger customers must vet and monitor their suppliers no matter how small — so the security questions arrive whether or not you're personally in scope. And operational risk is indifferent to headcount: a single compromised small vendor is one of the most common ways large organisations get breached. "Nothing will happen" bets against both your customers' procurement rules and your own attackers.
Ten core risk-management measures under § 30(2) BSIG — risk analysis, incident handling, business continuity, supply-chain security (no. 4), secure procurement, effectiveness reviews, cyber hygiene and training, cryptography, access control and MFA — plus registration with the BSI (§ 33), incident reporting on a 24h / 72h / 1-month clock (§ 32), management approval, oversight and training (§ 38), and ongoing evidence and supervision (§§ 39 / 61 / 62). Nine of the ten sit inside your own walls. The structural exception is supply-chain security: you must assess and manage the posture of companies you don't control — and document it.
Management — by design. Under § 38 BSIG the management body must approve and oversee the risk-management measures, and that duty cannot be delegated away to IT or a provider. Breaches can trigger fines up to €10M or 2% of worldwide annual turnover for essential entities (€7M or 1.4% for important ones), on top of personal accountability for leadership. You can size your own exposure with our fine & liability calculator.
It depends on your classification. Essential entities can be asked for evidence and audited at any time, without cause (§§ 61/62 BSIG); important entities are typically examined reactively, after an incident or on specific suspicion; KRITIS operators have a fixed three-year cycle (§ 39). Most NIS2 entities have no fixed audit date — which is why the only safe posture is to keep your supply-chain documentation current and producible on demand, rather than reconstructing it from email chains under pressure.
Excellent — for your organisation. But an ISO 27001 certificate attests to your own management system, not to the security of the suppliers NIS2 asks you to oversee. It's also point-in-time, renewed over years, while threats move daily. EUSEC doesn't replace ISO 27001 — it extends that diligence outward across your supply chain and keeps it continuous. (A supplier's own ISO 27001 certificate can even satisfy the deep-audit step for your most critical A-tier vendors.)
Then you already know their limits: low response rates, self-reported answers, and a snapshot that's stale the moment it's filed. A questionnaire records what a supplier says — not what an attacker can see. EUSEC rates your whole portfolio from the outside in hours, including suppliers who never reply, and then flags exactly where the questionnaire's claims and the external evidence disagree. It doesn't bin your questionnaires; it verifies them — and cuts the back-and-forth on both sides.
Keep it. A GRC platform manages process — workflows, policies, evidence collection — but it generally doesn't generate the underlying security signal; it waits to be fed. EUSEC is that data layer: independent, evidence-based supplier ratings, exportable as a CSV audit trail or piped in through our API (a 20% add-on) straight into your GRC or TPRM platform. One orchestrates; the other observes.
Insurance transfers cost after an incident; it doesn't prevent one, and it doesn't discharge NIS2's preventive duties under § 30. Insurers are tightening the rules, too — increasingly requiring evidence of supply-chain risk management as a condition of cover, and reducing payouts where due diligence was missing. Continuous ratings support both sides: fewer incidents, and the documentation your insurer now expects.
No — and be wary of anyone selling one. NIS2 creates no certificate, and no private party can certify NIS2 conformity; that judgement rests with the authority alone. What EUSEC delivers is an independently verified maturity assessment backed by evidence, plus audit-ready documentation of your supply-chain measures — as a record of due diligence that is often stronger than a narrow seal. But it is not a legal certificate, and we never claim to "certify NIS2 compliance" on your behalf.
Two complementary lenses, resolved into one scale. The Outside Rating assembles observable evidence across 10 risk dimensions — domain & email authentication, transport encryption, web surface, breach history and more — entirely non-intrusively, plus a documented sector-and-entity calibration. The Inside Rating is a structured self-disclosure scoped to your NIS2 status (7, 11 or 15 criteria) and scored on the BSI maturity model (RUN). Both produce one grade from AAA to C with a forward-looking outlook, weighted by your ABC criticality tiers. The scoring core comes out of the Cyber Risk Score research project with TH Rosenheim.
Yes. § 30 BSIG requires risk-based, proportionate supply-chain measures — not a full audit of every supplier. For your long tail (C-tier), a documented, repeatable, automated outside rating is exactly that kind of proportionate measure — much as Creditreform's scoring is for commercial credit risk — while critical suppliers get deeper inside ratings and audits. EUSEC publishes its methodology, commits to the US Chamber of Commerce Principles for Fair and Accurate Security Ratings, and gives you exportable § 30 documentation built to hold up in front of the BSI, your insurer or the board.
NIS2 defines no official accreditation for rating providers, so no "BSI-approved" status exists to hold — for us or anyone else. EUSEC is an independent rating agency, modelled on the credit-rating agencies rather than on a consultancy. Our methodology is mapped to recognised reference points — ENISA Technical Implementation Guidance, CIR (EU) 2024/2690 and ISO/IEC 27001 — so our output speaks the language your obligations are written in. We point to those standards for orientation; we claim no authority's endorsement of us.
Yes — and it's lawful by design. An Outside Rating reads only what is public or voluntarily disclosed by a server, record or document; there is no exploitation and no break-in. EUSEC's legal opinion finds no offence under §§ 202a/202b/303a StGB and no trade-secret breach under the GeschGehG. Most signals are technical data of legal persons, outside the GDPR entirely; for the few personal inputs, the basis is Art. 6(1)(f) GDPR — legitimate interest, the same footing SCHUFA, Creditreform and Dun & Bradstreet have used for decades. Inside ratings, by contrast, are always invitation-based.
A rating is an informed opinion built on evidence — not a guarantee, and not a penetration test. Every outside finding is traceable: you can drill from the grade down to the specific signal behind it, rather than trusting a black box. False positives are minimised by validation and by the discrepancy check between the outside view and a supplier's inside self-assessment, and the outlook shows whether posture is improving or eroding over time. It's a risk indicator — which is why critical suppliers are escalated to inside ratings and audits for confirmation.
Yes — fairness is built in. Any rated company can open a dispute: we correct inaccurate inputs and re-assess on new evidence, and the rights to object, rectify and access (Art. 21/16/15 GDPR) run through the same channel. Crucially, every adverse grade (B or worse) is held for roughly 14 days before it's shared with other subscribers, giving the supplier a fair chance to respond first. So a poor result never circulates behind a supplier's back — which also keeps your supplier relationships intact.
All processing happens within the EU, in line with the GDPR and BDSG, and there is no data transfer to third countries. A data-processing agreement (DPA / AVV) is available — provided directly in your customer account, with the technical and organisational measures (TOMs) in its Annex and reviewed by an external auditor (currently TÜV Rheinland). Outside ratings draw only on publicly observable data; anything you or your suppliers submit for inside ratings is used solely to produce your assessments.
We hold ourselves to the standard we measure others against. EUSEC runs an ISMS aligned with ISO/IEC 27001:2022, owned and reviewed by management annually, with data encrypted at rest and in transit, enforced MFA, least-privilege access, a secure development lifecycle and independent penetration testing. Everything runs on EU-hosted, hardened infrastructure (Hetzner) carrying ISO/IEC 27001:2022, BSI C5 Type 2, KRITIS/§ 8a BSIG and PCI DSS v4 attestations — and our staff hold EU citizenship. The current subprocessor list is available to customers on request.
For an Outside Rating, your supplier does nothing — no onboarding, no participation, results in hours. An Inside Rating is invitation-based: the supplier completes a short 7–15 question self-disclosure. No bilateral NDA is required — the platform terms create a three-party confidentiality framework (EUSEC keeps supplier data confidential from unauthorised parties; you commit to using inside data solely for your own § 30 compliance), and a standard NDA PDF is available if their counsel asks. Suppliers gain something, too: one verified rating they can reuse across all their customers instead of answering endless questionnaires.
You can build it in-house, but the bill is larger than it looks — scanning infrastructure, threat-intelligence feeds, analysts and their relentless upkeep, multiplied across every supplier — and scanning vendors yourself is resource-intensive and legally fraught. Buying gives you full coverage from day one, consistent and comparable scores, clean lawful data on a credit-agency basis, and something an internal team structurally can't provide: an independent, third-party view your customers and auditors will actually credit.
It scales with risk, and you can start free — 10 company ratings, no credit card and no account, results in hours. Beyond that, pricing is linear and transparent: €149 per supplier per year, with automatic volume discounts (€129 from 51, €109 from 251, custom above 500) and a 15-supplier minimum. There are no tier games — your ABC classification sets monitoring intensity, never your invoice — and we rate an organisation, not a domain count (subdomains and up to three TLDs are included). An optional API integration adds 20%.
Structurally, yes — independence is the product. EUSEC is modelled on the credit-rating agencies: we run no consulting or remediation business on the side (a firewall, on purpose), and Outside Ratings are unsolicited and subscriber-funded — the rated company is neither our customer nor our paymaster. No one can pay to raise, lower or suppress a grade; the nine inside areas carry equal, disclosed weighting; and the model is automated, with expertise built in rather than case-by-case discretion that could be lobbied. Disagreements go through a transparent 14-day appeal.
Because trust here rests on verifiability, not authority. The methodology is published, every finding traces back to its evidence, the scoring core is grounded in the Cyber Risk Score research with TH Rosenheim, and the legal basis has been examined by counsel rather than assumed. Your data stays EU-hosted under the GDPR, and we're honest about our limits — we don't certify compliance, and we label an automatic outside rating distinctly from a verified, audited one. Follow any grade down to the signal that produced it: trust the method, then trust the result.
Your continuity is protected by design. Your supplier data, ratings and the full audit trail are exportable (CSV), so you keep what you've built. And because the assessment rests on open, recognised standards — not a proprietary secret — the approach is reproducible elsewhere; you're never locked into a method only we understand. Data export and continuity are addressed directly in our contractual terms.
Ask it directly. We'll answer in plain language — and if it belongs to your legal or procurement team, we'll tell you that too, rather than pretending otherwise.
No credit card. No account required. Zero obligation.
Results delivered straight to your inbox.