# EUSEC — Cyber Rating Agency > EUSEC is a European cyber rating agency that provides independent cyber security ratings for supply chains. The ratings help companies evidence NIS2 Article 21 and §30 BSIG supply chain security, manage third-party and vendor risk, and address DORA third-party ICT risk. Ratings run from AAA downward, are built from millions of external signals, aligned to ISO 27001, NIST CSF and BSI IT-Grundschutz, and verified by in-house security analysts. Buyers can rate up to 10 companies for free — no credit card, no account. ## Key facts - Service: independent cyber security ratings (cyber risk ratings) for suppliers, vendors and partners. - Rating scale: AAA (strongest) downward, with an outlook (e.g. Stable / Negative). - Method: large-scale external signal analysis (5M+ signals/month across 180,000 sources) + expert verification. - Standards referenced: ISO 27001, NIST CSF, BSI IT-Grundschutz. - Regulations addressed: NIS2 Directive, NIS2 Article 21, §30 BSIG (incl. §30 Abs. 2 Nr. 4 supply chain security), DORA; supports TISAX assurance. - Coverage: 26,000+ companies assessed, 27 EU member states, all 18 NIS2 sectors. - Free tier: rate 10 companies at no cost, no credit card, no account; reports delivered by email. - Audience: CISOs and IT security teams (buyers/assessors) and procurement / third-party risk managers, plus suppliers who want to be rated. ## Pages - [Home / Supply chain cyber security ratings](https://www.eusec.net/): Overview of EUSEC ratings, NIS2 Article 21 and §30 BSIG supply chain security, and the free 10-company offer. - [FAQ](https://www.eusec.net/#faq): Answers on what a cyber security rating is, §30 BSIG supplier requirements, how ratings are calculated, pricing, and DORA/TISAX support. - [For buyers](https://www.eusec.net/#buyers): Supply chain risk mapping, third-party/vendor risk management and regulatory compliance for CISOs and procurement. - [For suppliers](https://www.eusec.net/#suppliers): Rate once and share across your customer network; stay eligible for contracts and benchmark against your industry. - [NIS2 sectors](https://www.eusec.net/#sectors): The 18 NIS2 essential and important sectors EUSEC covers. ## Regulatory context (Germany / EU) - The NIS2 Umsetzungsgesetz (BSIG, new version) took effect in Germany on 6 December 2025 with no transition period. - §30 BSIG defines ten mandatory risk-management measures; measure four is supply chain security, covering direct suppliers and service providers. - In-scope organisations must assess supplier-specific vulnerabilities and their vendors' overall cyber practices, and document the results for the BSI.