Six reasons the rating holds up — and why an independent agency is the right shape for this job.
We're modelled on the credit-rating agencies, not the consultancies. Our methodology is published, our ratings are never moved by what a company pays, and we run no remediation or consulting business on the side — there's a firewall, on purpose. Ratings update continuously, and anyone who disagrees has a transparent 14-day appeal. An audit verifies what's there; it can't buy a better grade.
Our outside rating is passive and non-intrusive — we never touch a supplier's systems. It runs on a credit-agency legal basis (Art. 6(1)(f) GDPR, the footing Creditreform operates on), so you consume clean, lawful data instead of scanning vendors yourself, which is both resource-intensive and legally fraught.
Your data stays within the European Union. No third-country transfer, no detours — one less thing to explain to your own auditors and regulators.
The scoring core comes out of the Cyber Risk Score research project with TH Rosenheim. The method is built to be defensible because it was built to be examined.
Our methodology is mapped to the NIS2 supply-chain requirements (Art. 21 / §30 BSIG), the ENISA Technical Implementation Guidance, CIR (EU) 2024/2690 and ISO/IEC 27001 — as reference points, so our output speaks the language your obligations are written in. We point to these standards; we don't claim any authority's endorsement of us.
Transparent, linear pricing instead of the usual enterprise opacity. You see what coverage costs before you commit, and you can budget for it without a sales cycle.
Honesty is part of what you're buying. A rating is only worth something if the people behind it don't overstate it.
We don't certify NIS2 compliance, because no private provider can. What we deliver is an independently verified maturity assessment, backed by evidence — and as a record of due diligence, that is often stronger than a narrow certificate, not weaker. We say so plainly. The responsibility for your compliance stays with you; our job is to make it defensible.
The hardest part isn't the work — it's the assumption that this can wait. It can't. The transposition deadline has already passed, failing to register is its own finable offence, and after any incident the first question asked is what you did to know your suppliers. That isn't alarmism; it's just the order things happen in.
Our automatic outside rating is a non-intrusive, continuously updated external view, available with no supplier participation. A verified or audited rating is something more — independent confirmation of specific controls for the suppliers that matter most. We keep the two clearly labelled, so you always know which kind of assurance you're looking at.
No credit card. No account required. Zero obligation.
Results delivered straight to your inbox.