Most NIS2 obligations have a playbook. Supply chain security doesn't.
Vittnor — Supply Chain Assurance for the mid-market. It turns supplier proof into structured, audit-ready records — without the spreadsheet sprawl. Built for the buyers that bigger players ignored, in central Europe by a cybersecurity practitioner who's been in your shoes.
- Pilot free for the first cohort
- EU-built, EU-hosted
- Audit-ready evidence records
- No tracking cookies
EnlargeWalk through the NIS2 obligations as a CISO or Head of IT. Awareness training has a playbook. Incident response has a runbook. Patch management is procedural. Supply chain security isn't. The evidence sits with external parties. It arrives in a dozen formats. It expires unevenly. And someone has to defend the decisions later. That's why Vittnor is its own product — because the obligation deserves its own tool.
Structured supplier evidence — without the spreadsheet sprawl.
Vittnor turns supplier proof — certificates, audit reports, contract clauses, policy documents — into Evidence records with expiry context and a full decision trace. When a supplier has an incident, an auditor asks a hard question, or a regulator sends an inquiry, you have the answer in minutes, not hours.
- Process-driven supplier scoping
- Structured assessment with AI-assisted answer extraction — every suggestion cited
- Evidence records with review history
- NIS2-shaped audit exports — structured, hash-anchored, defensible
Microsoft Azure, EU regions only.
Read the long-formFull list, updated on every change. DPA template available before the deal.
Read the long-formHash-anchored, signed, decision-traced. Stands up six months later, unchanged.
Read the long-formWhen a supplier discloses an incident.
One scenario. Two ways it goes. The difference is what you signed up for the day before it happened.
Open the supplier register spreadsheet. Search SharePoint for their last assessment, your inbox for the contract clauses, a different folder for the evidence files, your calendar for the last review date. Half a day per supplier. Longer if the original reviewer has left. By the time you've reconstructed who reviewed what and when, you're not sure you have the latest version of anything.
One record per supplier. Current evidence, review history, contract clauses, in-scope services — linked, dated, exportable. The CEO gets the answer the same morning. The auditor gets the same answer six months later, unchanged.
What you actually get.
Evidence, decisions, exports — the three things an auditor actually asks for. We build supplier-assurance tooling and we're honest about what it's for: no 24/7 SOC, no managed endpoint agents.
How it fits togetherSub-processor lists, certificates, audit reports — linked, dated, hash-anchored, with reviewer attribution. Always the latest version.
Every approval, rejection, and escalation timestamped and signed. Auditor asks "why was that rejected" — you hand over the trace.
Machine-readable export of every approved evidence record, every reviewer decision, every signed dossier — built to match the structure a NIS2 auditor expects.

Pavel Láska.
Built by the practitioner.
Shards Cybersecurity was founded by Pavel Láska — a CISSP- and CISM-certified cybersecurity practitioner with over a decade across banking, pharma, and education.
Eight years in the banking sector progressing from senior engineer to senior risk manager. Time on critical financial infrastructure. Then a global security services team in pharma across three continents. He was the one filling the spreadsheets, defending the supplier decisions, prepping for the audits. Vittnor is the tooling that should have existed back then.
The product was shaped by quiet conversations with practising CISOs and security leads across regulated industries — people who've sat in the audit chair, defended supplier decisions to boards, and lived with the consequences. They're not named on this page, but they're in the product.
Bratislava · CISSP · CISM · Microsoft Partner
Built on Microsoft Azure, with a Microsoft-first architecture and security model. Microsoft Marketplace listing goes live Q4 2026; V1 commercial launch Q1 2027.
Bratislava-headquartered, EU-hosted. In pilot conversations with regulated buyers across the EU and UK.
Designed for NIS2 supply-chain obligations from day one — not retrofitted from a generic GRC suite.
Two ways to start. Both open today.
Run your supplier register in Vittnor — free for the first cohort of design partners. You shape what ships; V1 lists on the Microsoft Marketplace Q4 2026.
Start with the NIS2 Supplier Exposure Assessment — fixed scope, fixed deliverable, €3,900 one-off. A practitioner-written report on where your supplier risk actually sits, in two to three weeks.
A ten-minute form about your company and suppliers. No sales team screens it — you hear back from the founder personally.
Thirty minutes on your supplier register and what the pilot should prove for you.
Your first suppliers in Vittnor within two weeks.
Pilot open today. Free for the first cohort.
We help you, you help us — the first cohort shapes what we build next. After the pilot: published prices, no quote calls. See pricing →
Nothing to install, no credit card, no procurement cycle — the pilot runs on your real supplier register in Vittnor.
