Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Vittnor · Buyer side

The clean answer when the auditor asks.

Vittnor — Supply Chain Assurance for the mid-market. Scope your supplier portfolio. Assess what matters with structured questionnaires. Collect evidence with provenance. When the question comes, hand over a signed decision trace — not a spreadsheet reconstruction. Built in central Europe by a cybersecurity practitioner — for the buyers that enterprise GRC suites priced out and ignored.

NIS2 Article 21(2)(d) by designMicrosoft Azure, EU regionsPilot open now · V1 Q4 2026
Supplier? A buyer sent you a request →
Supplier review lifecycleFive-stage workflow from scope through risk tier, questionnaire, evidence collection, to final decision.Edge ingress · Tier 2 · Cirrus EdgeScopeApr 04Risk tierApr 12QuestionnaireApr 1867%EvidenceIn review5DecisionPending
For your role

Three angles into the same product.

The platform is the same regardless of who's using it. The framing changes depending on what you're trying to defend — to whom, and how fast. Pick the angle that matches; the rest of the product story flows below.

For GRC leads

Audit defensibility, not framework gymnastics.

Decision-trace and signed evidence stand up six months later, unchanged. Article-anchored gap reports map directly to the NIS2 control set your auditor will reference.

  • Article 21(2)(d) gap reports anchored to the directive, not interpreted away from it
  • Reviewer attribution + timestamp on every approval, immutable post-fact
  • Hash-anchored evidence model — same artefact, same answer, six months later
How the decision-trace works
For CISO / IT manager

A supplier graph you can query in minutes.

When a supplier discloses an incident, you need to know which of your services depend on them, which sub-suppliers are downstream, and what evidence you currently hold — fast.

  • Tier 1 + sub-supplier lineage in a single graph, queryable by impact path
  • Reviewer-flagged certificate expiries, with re-review prompts on the calendar
  • NIS2 Article 21(2)(d) control mapping by design
Incident response in the product
For owners and CEOs

Article 20 governance support, not jargon.

NIS2 makes management bodies personally accountable for cybersecurity oversight. The platform produces the board-ready evidence that lets you discharge that accountability.

  • Structured monthly summary — supplier posture, open exposures, decisions taken
  • Named accountability — your name appears on the documents the board signs
  • Audit-readiness sign-off you can hand to the auditor without rebuilding
See the audit-ready evidenceQualified Manager retainer
1.0 / Inside the product

Four screens. Four stories.

Real product, redacted. Supplier names and numbers are placeholders; the workflow is real.

Assess

Risk scored by worst dimension.

Each in-scope subject — a whole supplier type or a single service — carries its own risk assessment, scored across six dimensions: availability, confidentiality, privacy, supply chain, jurisdiction, resilience. Every score is colour-coded, Low to Critical, and the supplier's tier is the worst dimension across active assessments — not an average. One weak dimension never hides behind five good ones.

PreviewRisk assessment with six colour-coded dimension scores per subject and a worst-dimension rollup tierEnlarge
Respond

Every customer request in one inbox.

Suppliers see every inbound customer request in one place — who is asking, what is due, and how far along each answer is. When a buyer requests changes, the request is flagged for attention the moment it comes back — not rediscovered in an email thread weeks later. The questionnaire back-and-forth scattered across inboxes stops here.

PreviewSupplier-side inbox of customer requests with deadlines, progress, and a changes-requested flagEnlarge
Depth

The chain doesn't stop at tier one.

Suppliers disclose the sub-processors behind the service — who runs the cloud, the telemetry, the endpoints — each with criticality, region, and the contract clause that declared it. Removing one requires a reason and leaves an archived entry, so historic dependencies stay discoverable. Captured at each review cycle, not reconstructed after the incident.

PreviewSub-suppliers tab listing disclosed sub-suppliers with criticality, region, declaring contract clause, and audit-grade change historyEnlarge
Export

Every decision, stamped and exportable.

Every approval, rejection and resubmission is logged with the actor, the reason and the timestamp. Auditors get a chronological export that closes regulator questions in minutes, not hours.

PreviewDecision trace timeline with attributed scope verdicts and approvals, exportable as CSV or trace bundleEnlarge
Hidden risk three hops deepTracing a weak link from your direct suppliers down through their sub-suppliers to surface a critical risk three steps below.YouTier 1Tier 2Tier 3 +You!From your direct supplier — three steps deep — into a sub-supplier with no NIS2 controls.
2.0 / The hidden chain

Your supplier list ends at one name. The risk doesn’t.

Most supplier-management tools audit who you’re paying. Vittnor maps the chain behind them — Tier 1, Tier 2, Tier 3 — and surfaces the supplier you didn’t know was a supplier. Because that’s where the risk actually lives, and that’s where it always has.

How: sub-suppliers captured from supplier-disclosed lists at each review cycle and held alongside the L1 record. Reviewers flag what changed since last cycle. Automated drift detection ships in V1.2 (2027). More on supply chain depth →

Supplier evidence becomes questionnaire answersFour supplier-provided evidence artefacts on the left — ISO 27001 certificate, SOC 2 Type II report, sub-processor list, DPA — each mapped to specific items in the buyer's supplier questionnaire on the right, with one item marked manual to show that AI never closes the loop.Supplier evidenceYour supplier questionnaireISO 27001 certificateValid · 2025–2028SOC 2 Type II reportAudit · Mar 2026Sub-processor listv2 · Apr 2026DPASigned · Jan 2026Are sub-processors disclosed?ISO 27001 certified — current?SOC 2 Type II in date?DPA in place with you?Incident notification SLA?BC/DR tests · last 12 mo?MANUALTheir certs.Your answers — with citations and a reviewer sign-off.
3.0 / Their certs, your answers

The supplier's evidence answers most of your questionnaire.

Your suppliers upload their SOC 2 Type II report, their ISO 27001 certificate, their sub-processor list, their DPA. The platform extracts the structured facts and pre-fills the matching items in your supplier questionnaire — every suggested answer cited back to the exact source page or clause. You accept, edit, or reject. The reviewer's decision is signed and hash-anchored.

How: Azure Document Intelligence extracts text and structure from each supplier artefact; AI-suggested answers carry mandatory citations to the source. No automated approval — every suggestion needs a reviewer sign-off, captured as an audit event with model, version, evidence set, and timestamp.

Decision trace ready for the regulatorAuditor question answered by a signed, hash-anchored decision trace with five entries from risk tier through final approval.?Auditor question"How did you assess Cirrus Edge Networks for NIS2 21(2)(d)?"Decision traceEdge ingress · REV-2026-014Risk tier set: Tier 2 / HighApr 12 · You8/8 questionsISO 27001 + SoA approvedApr 18 · Yousha256:f1c…Sub-processor list v2 approvedApr 22 · Yousha256:7d2…Privileged access review approvedApr 22 · Yousha256:b8e…Approved · valid until Oct 26, 2026Apr 26 · YousealedEvery entry timestamped, signed, hash-anchored.Hand it over. Walk away.
4.0 / Audit-ready by default

Hand the regulator the file. Walk away.

When a regulator, an auditor, or your board asks "how did you decide on this supplier eighteen months ago" — most companies reconstruct the answer under pressure. With Vittnor, you hand them the trace. Every decision timestamped, every signature attributable, every evidence reference hash-anchored. Already prepared.

How: append-only decision log with reviewer attribution, evidence linkage, and content-addressable hashing. Exportable as a single signed dossier. What NIS2 expects in your supplier files →

5.0 / Incident response

Vendor breach in the news. Supplier exposure mapped in one search.

An attack on a major vendor becomes your problem if your suppliers depend on them. Vittnor captures those dependencies at every supplier review — direct relationships and the sub-suppliers behind them — so when something happens, the answer is already structured and searchable in the file you maintain.

  • Direct suppliersTier 1 relationships, current as of the last review.
  • Sub-supplier disclosuresTier 2 and Tier 3 dependencies, surfaced from supplier-provided lists.
  • Searchable attributesQuery by vendor name, technology, country, or risk attribute.
  • Refresh cadenceUpdated on every supplier review — not just when something goes wrong.
See it for your role
Searchable supplier graphQuerying which suppliers depend on a specific vendor and surfacing the relevant matches across the supplier graph.Suppliers using OAuth-Bridge as a sub-supplier?3 of 12 suppliers depend on this vendorCirrus Edge Networksvia OAuth-Bridge (Tier 2)USES VENDORHalo CDNvia OAuth-Bridge (Tier 2)USES VENDORNorthwind Managed ITvia OAuth-Bridge (Tier 3)USES VENDORYour supplier graph, searchable in one place.Updated on every supplier review.
6.0 / The supplier-review lifecycle

From scoping to next year's review.

Six stages, one cycle. The capabilities above (decision trace, supplier graph, Article 21(2)(d) mapping) are what makes each stage hold up — this is the flow they sit inside.

01/

Scope your portfolio

Add suppliers — Tier 1 and below where visibility allows. Tag each by the service they provide and the data classification they touch. Sub-suppliers recorded separately as they are disclosed.

Artefact · Supplier register · Sub-supplier map
02/

Risk-tier each supplier

Score by data sensitivity × service criticality × replaceability. Top-tier gets full assessment; lower tiers lighter-touch. Either way the tier choice is signed and timestamped, not implicit.

Artefact · Risk-tier matrix · Tier rationale
03/

Request the evidence that matters

When residual risk warrants it, send a tailored questionnaire. You pick which artefacts — SOC 2 Type II, sub-processor list, breach-disclosure history, BCP test results, contract clauses on file. Supplier receives it via the supplier-side surface; you see what they have already uploaded to their evidence library and what is new.

Artefact · Questionnaire · Supplier evidence library
04/

AI-assisted answer extraction

When the supplier returns evidence, AI extracts structured facts and suggests answers to the items in your supplier questionnaire — every suggestion carries a mandatory citation to the exact source page or clause. You accept, modify, or reject each one. AI never closes the loop.

Artefact · Extracted facts · Mandatory citations
05/

Decide and sign

Approval, rejection, or accepted-with-conditions — the decision is hash-anchored with reviewer attribution and timestamp. Future you, the auditor, and the regulator all see the same answer. Mark compliant, and the file is closed for this cycle.

Artefact · Decision-trace ledger · Signed dossier
06/

Watch for change. Re-review on signal.

Annual cadence sits on top — every supplier file knows when it is due. Reviewers flag out-of-cycle re-reviews when something material changes: vendor breach disclosure, certificate expiry, sub-supplier addition, ownership change. Automated trigger detection — and the half-prepared file that comes with it — ships in V1.2 (2027).

Artefact · Annual review · Reviewer-flagged re-reviews

Stage 06 feeds back into Stage 03 (or 02 if the change is material enough to re-tier). The cycle is the point — supplier assurance is not a one-off audit, it is the continuous practice the audit trail depends on.

6.1 / One review, closed

This is what the lifecycle leaves behind.

One supplier review, rendered as the record it produces — scope, risk, questionnaire, decisions, closure. Scroll it the way an auditor would read it back: every entry carries its reason.

Supplier Review Record · REV-2026-014

Cirrus Edge Networks

BuyerVltavia Energy a.s.ReviewerM. DvořákováOpened04 Apr 2026AuthorityNIS2 Art. 21(2)(d)

The following is the record of a supplier review. Every section below was authored in sequence — scope, risk, questions, decisions, closure — and each entry carries the reason behind it.

Illustrative record — buyer, supplier, and data are fictional.

Article I

Scope of review

Three services were enumerated on the supplier's register. Each was triaged against the five-question scoping policy. Of the three, one carried regulated traffic and was placed in scope; one was a public-only asset and exempted under §3.2; one is awaiting triage.

  1. SVC-001
    Edge ingress and DDoS protection
    Production traffic for regulated services.
    IN SCOPE
  2. SVC-002
    Status page hosting
    Public assets only — exempt under scoping policy.
    OUT OF SCOPE
  3. SVC-003
    Internal monitoring API
    Awaiting triage.
    PENDING
§ Scope Check S1–S5 · Decision IDs D-2026-111 → D-2026-113
Article II

Risk assessment

Twelve scored questions were answered against the in-scope service. The normalised score is reported alongside the four highest-contributing drivers; the tier follows from the score and the category gates.

46/100
Normalised score
Final tier
HIGH · TIER 2
Raised from MEDIUM · TIER 3 last cycle. Tier set by score and category ratings; no gates fired.
Top drivers
  • Q1
    How critical to your operations?Production traffic, regulated services
    +6
  • Q6
    Privileged inbound access?Yes — admin, persistent
    +6
  • Q2
    Acceptable recovery time?< 24 hours
    +4
  • Q4
    Records exposed if breached?1k–100k
    +4
RA-2026-014-1 · ModelVersion 1 · Reviewer notes Q13 on file
Article III

Questionnaire assembled and sent

Nine questions are required by the Tier-2 pack. Of these, four were already satisfied by evidence on file in the buyer's library — those questions were skipped to save the supplier's time. The remaining five were dispatched to the supplier's designated security contact on 26 Apr 2026, 14:08 CET; a receipt was logged the same minute.

On file · skipped
4/9
~16 minutes of the supplier's time reclaimed.
Dispatched
5/9
Questions sent with a due date of May 10, 2026.
From
m.dvorakova@vltavia-energy.example
To
a.novakova@cirrusedge.example
Due
10 May 2026
Pack QP-T2-2026-014 · Dispatch D-2026-114-OUT · hash-anchored at dispatch
Article IV

Decisions and reasons

The supplier returned nine evidence items, each attached to the question it answered and bound to a submission attestation. Every item was reviewed; the reviewer's verdict and the reason behind it are recorded below. The full record is the audit trail — no decision in this register stands without its reason.

  1. T2Information security policy
    APPROVED
    Signed v2.4 — covers in-scope service.
  2. T1ISO 27001 + SoA
    APPROVED
    Current cert; scope covers production.
  3. T1SOC 2 Type II report
    APPROVED
    NDA-bound copy on file; last 12 months.
  4. T3Privileged access review
    APPROVED
    Quarterly cadence; service-scoped.
  5. T2Sub-processor declaration
    APPROVED
    Matches register; no new processors.
  6. T3Incident response runbook
    REJECTED
    Missing notification SLA per contract Annex 3.
  7. T2Data processing addendum
    APPROVED
    SCC mappings present and current.
  8. T3Acceptable use policy
    APPROVED
    Public summary acceptable for service tier.
  9. T4Data protection / privacy policy
    APPROVED
    Self-attested OK for T4 evidence.
8 approved · 1 rejectedReviewer · M. Dvořáková · timestamped each row
Decision IDs D-2026-114 → D-2026-122 · all linked to evidence hashes
Article V

Closure

The review for the in-scope service is closed. On this cycle's score the reviewer raised the supplier's tier from MEDIUM to HIGH; one item carries an outstanding rejection for which a remediation request has been opened. The review cadence tightens accordingly — twelve months becomes six.

Closed
RA-2026-014-1
28 Apr 2026 · 16:42 CET
Tier raised
MED 3 → HIGH 2
Score 46 / 100 · reviewer decision
Cadence tightened
12 → 6 months
Next review 26 Oct 2026
Portfolio risk distributionnarrows
CriticalHighMediumLow ↑
Signed
M. Dvořáková
Reviewer · Vltavia Energy a.s.
Hash-anchored at closure
0x9a4f…c218
End of record · Exportable JSON / CSV via /api/exports
— end of record —
Skip the record
Run a review yourselfTwo minutes, interactive, no signup — you make the calls.
7.0 / Built for the mid-market

Not enterprise procurement. Not a consumer tool. The segment in between.

Most supplier-assurance platforms target the global procurement team running 5,000-vendor audits. We built ours for the businesses inside the supply chain — the 50–500-person manufacturer, the regional MSP, the medical device company — that suddenly need to prove their security posture to three different customers asking three slightly different questions, and answer for their own supplier risk under NIS2.

7.1 / Roadmap visibility

What you can use today, what ships, what comes after.

We claim the present accurately and name the future honestly — no feature marketed before it exists, and no hiding the line between what pilot members test now and what general availability brings.

Pilot · today

What design partners test now

  • Process-driven supplier scoping
  • Structured assessment with AI-assisted ingestion
  • Evidence records with reviewer attribution
  • Decision-trace ledger with hash-anchoring
  • NIS2-shaped audit exports — machine-readable, structured
Production-ready · Q4 2026

What ships at general availability

  • Microsoft Marketplace listing + procurement-friendly billing
  • SLA commitments published at GA
  • Single-tenant deployments on request
V1.2 · 2027

What ships next

  • Review-trigger engine — automated re-review on cert expiry, sub-supplier change, contract amendment
  • Sub-supplier change notifications
  • Source drift detection — trust-center page changes, posture shifts
V2 · 2028+

What the platform grows into

  • Cross-framework crosswalks — NIS2 evidence reused across ISO 27001, DORA, SOC 2
  • Shared assurance pools (buyers + suppliers in the same regulated chain)
  • Sector-specific evidence templates per Annex I/II category
  • Slovak / Czech / German UI translations
8.0 / Who built this
Pavel Láska — founder of Shards Cybersecurity

Built by the practitioner.

Pavel Láska · Founder · Bratislava

Vittnor is built by Pavel Láska — a CISSP/CISM practitioner with a decade-plus across banking, pharma, and education. He filled the spreadsheets, defended the supplier decisions, and prepped the audits this product now organises.

The full story

Bratislava · CISSP · CISM · Microsoft Partner

9.0 / FAQ

Common questions

Is the product available today?+

The pilot is open today — Vittnor is in pre-launch and we are onboarding the first cohort of design partners now. The live production version (V1) is planned for Q4 2026 via the Microsoft Marketplace. Apply via the /pilot page to join the first cohort.

Do I need to be NIS2-regulated to use it?+

No. Many pilot conversations are with suppliers to NIS2-regulated firms who want to demonstrate posture quickly when assurance requests arrive — and with mid-market buyers who are themselves in scope.

How is this different from the NIS2 Supplier Exposure Assessment?+

The Assessment is a fixed-scope advisory engagement: a practitioner walks your supplier portfolio, produces an audit-ready exposure report and a prioritised remediation list, and hands it over. Vittnor is the SaaS — the platform you operate after that initial picture is in your hands. Many buyers do the Assessment first, then onboard the platform.

Does Vittnor replace our audit?+

No. Vittnor produces the structured, attributable evidence an audit draws on — the audit itself still happens with your auditor. What changes is how much of the preparation is already in place when they arrive.

How does the lineage tracing work?+

Where a supplier discloses its sub-processors and downstream providers, we capture the chain from supplier-disclosed lists at each review cycle, so the riskiest path is visible in one place. Most supplier lists only show your direct (Tier 1) relationships; the real risk often hides two or three hops deeper.

How is evidence reused across requests?+

Once a supplier uploads policies, certificates or attestations to their library, future requests from that buyer pull the existing evidence forward. Re-keying the same answers across spreadsheets stops.

What’s your data residency posture?+

EU-hosted by default — Microsoft Azure, EU regions only. Single-tenant deployments available on request for buyers with stricter requirements. No customer data leaves the EU without explicit configuration.

Do you offer a Data Processing Agreement?+

Yes. Standard DPA template available on request, GDPR Article 28-compliant. We’ll sign yours if it’s standard, or work through redlines.

Who are your sub-processors?+

Our sub-processor list is published and updated on every change. Currently: Microsoft (Azure hosting, database, blob storage, AI inference), EU regions only. No customer evidence is sent to third-party AI services.

What happens to my data when the pilot ends?+

Full export available in machine-readable format (JSON + signed PDF dossiers). Thirty-day grace period to export, then complete deletion, confirmed in writing.

How does this differ from OneTrust, Vanta, or Diligent 3rdRisk?+

Those are enterprise procurement-side tools, priced and configured for global teams running thousands of vendor audits. Vittnor is built for the mid-market — companies that need defensible NIS2 supplier assurance without a six-figure platform contract or a six-month implementation. We have 30–40% fewer features than enterprise GRC suites, at a price that reflects that. Honest tradeoff.

What’s a typical onboarding timeline?+

Pilot customers are live in under two weeks: import supplier list, run risk tier on the top 20, send the first questionnaires. Full coverage of a 100-supplier portfolio typically settles within 90 days.

10.0 / Join the pilot

Join the pilot — open today.

The pilot is open now. A small first cohort of mid-market buyers and their key suppliers — members join free or at compute cost and shape the roadmap. Production-ready V1 ships Q4 2026 via the Microsoft Marketplace. Mutual exchange — we help you, you help us.

Nothing to install, no credit card, no procurement cycle — your first suppliers are in Vittnor within two weeks. Published prices, no quote calls →