Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Vittnor · Supplier side

When your customer asks for your security evidence.

If your customer is using Vittnor — Supply Chain Assurance for the mid-market — to assess you, you'll receive questionnaires from them via the platform. This page explains what to expect, how to navigate it, and how to make next year's assessment easier than this year's.

One evidence library — versions and expiry trackedMicrosoft Azure, EU regionsPilot open now · V1 Q4 2026
Supplier evidence becomes questionnaire answersFour supplier-provided evidence artefacts on the left — ISO 27001 certificate, SOC 2 Type II report, sub-processor list, DPA — each mapped to specific items in the buyer's supplier questionnaire on the right, with one item marked manual to show that AI never closes the loop.Supplier evidenceYour supplier questionnaireISO 27001 certificateValid · 2025–2028SOC 2 Type II reportAudit · Mar 2026Sub-processor listv2 · Apr 2026DPASigned · Jan 2026Are sub-processors disclosed?ISO 27001 certified — current?SOC 2 Type II in date?DPA in place with you?Incident notification SLA?BC/DR tests · last 12 mo?MANUALTheir certs.Your answers — with citations and a reviewer sign-off.
1.0 / Why this is happening

Your customer is preparing for NIS2 — and you're in their supply chain.

Most likely your customer is preparing for NIS2 obligations, or another framework like DORA, ISO 27001 supplier provisions, or their own internal risk programme. They need documented evidence of how their suppliers — including you — manage cybersecurity.

Article 21(2)(d) of NIS2 requires essential and important entities to manage the security of their relationships with direct suppliers or service providers. In practice, that means assessing supplier posture and documenting the evidence behind those decisions. This isn't bureaucracy for its own sake — it's a real shift in how supply chain assurance works in the EU, and suppliers of regulated businesses are where the work lands.

2.0 / What you'll see

A clear list of what's being asked — and when it's due.

  • Evidence items your customer has requested (e.g. ISO 27001 certificate, sub-processor list, privileged-access policy)
  • Clear deadlines for each item
  • Upload directly, or link a URL where the evidence already lives
  • A note field for context the reviewer should know
  • Save as draft — your progress is kept if you get interrupted

You see only what's been requested of you. You don't see other suppliers' submissions.

PreviewSupplier view of a customer request showing evidence items and deadlinesEnlarge
PreviewBuyer reviewing supplier-submitted evidence — what your customer seesEnlarge
3.0 / What your customer sees

Your submission. Their review. Both sides in sync.

Your customer's reviewers see only your submission — not anything you've sent to other customers. They work through the evidence you've uploaded, mark items approved or send them back for clarification, and you see every update in your dashboard.

No more chasing email threads. No more wondering if your documents arrived. The review is tracked, both sides see the same status, and you get notified when something needs attention.

4.0 / The value to you

It gets easier every time.

Build it once, keep it organised.

When you upload evidence to a customer request, the platform keeps every artefact you have uploaded in one library — current version, expiry date, and the requests it answered. The next request starts from what you already proved. Cross-customer reuse is planned for later versions.

Predictable review loop.

You see when your customer reviewed each item, what they approved, and what they sent back for clarification — instead of guessing whether your email arrived.

Build a posture portfolio.

Over time, your evidence library becomes a durable asset — useful for repeat requests, audit prep, and your own internal review. The same artefact, organised once — ready the next time your customer asks.

5.0 / Getting started

Your customer invites you. You click through.

You'll receive an email invitation from your customer. Click through, set up your account, and their request will be waiting for you. Suppliers aren't onboarded proactively — your customer initiates the relationship.

If you're expecting requests but haven't received an invitation, ask your customer's compliance contact to invite you, or get in touch directly.

Ask us about an invitation
6.0 / FAQ

Common questions

Do I have to pay to use this?+

No. Suppliers don't pay anything. Your customer is the one running the platform; you receive customer requests, upload evidence, and respond. There's no charge to suppliers.

What if I don't have a SOC 2 or ISO 27001 certificate?+

That's normal. Most mid-market suppliers don't, and the platform is designed for that. Your customer's questionnaire will be tailored to your size and the criticality of what you provide — for many suppliers it's policies, sub-processor lists, and incident-response contacts, not formal certifications.

Does my customer see what I sent to other customers?+

No. Each customer sees only your submission to them. Your evidence library is private to you — your customer reviews what you attach to their request, and nothing you have sent elsewhere is exposed.

Where is my data stored?+

Microsoft Azure, EU regions only. The platform is EU-built and EU-hosted — your evidence does not leave the EU. The sub-processor list is published and updated on every change.

Who owns the evidence I upload?+

You do. Evidence stays under your control — your customer reviews it, but they do not take ownership of it. If you ever stop using the platform, your evidence leaves with you — it is yours, not ours.

How long does responding to a customer request take?+

Depends on what your customer asks for. A typical first request — policies, sub-processor list, incident contacts, a privileged-access summary — is a focused session rather than a project, if your evidence is to hand. Each new request starts from the library you already built — cross-customer reuse is planned for later versions.

What if I disagree with my customer's decision on an evidence item?+

You can respond directly in the platform — every item has a context note field, and your customer's reviewer sees the back-and-forth. The decision and its rationale are timestamped on both sides, so disagreements are surfaced rather than lost in email.

Is this required for me to keep my customer's business?+

Using this platform isn't itself a legal requirement — NIS2 puts the supply-chain obligation on your customer, who then assesses you. Whether you're in scope in your own right is a separate question. Either way, if your customer is regulated, expect the assurance request volume to keep growing — and each new request starts from the evidence library you already built, rather than from scratch.

7.0 / For MSPs and MSSPs

You sit on both sides of NIS2.

Likely regulated yourself under Annex I — ICT service management is listed there, and important-entity status generally starts at 50 staff or €10M turnover, with national variation. You are also supplier-side to every regulated customer you serve, and a co-delivery channel for the Assessment. The full MSP / MSSP picture lives on the partners page, including the channel economics and the honest scope of the supplier surface at pilot stage.

See the MSP / MSSP partner page
8.0 / Are you also a buyer?

Buyers and suppliers are often the same company.

If you also run your own supplier-assurance programme — managing the risk in your own supply chain — the same platform serves the buyer side too.