- Do you need access to our systems?
- No. The assessment is built from the public record and from anything you choose to share with us. We never ask for credentials and we do not probe, scan or hack anyone's infrastructure.
- Will the supplier know they are being assessed?
- No. We only read what is already public, so there is nothing for the supplier to detect. Nothing we do involves intrusion or anything unlawful, and no system is touched or put at risk.
- What do you need from us to start?
- The supplier's name and the requirement you have to satisfy, whether that is a customer's contract clause, an ISO 27001 audit, or a DORA or NIS2 obligation. The scoping call covers the rest.
- Where is our information processed?
- On European infrastructure. Client documents and correspondence are stored encrypted on our provider's own hardware in Switzerland, Germany and Norway, and seen only by the people doing the work. We think about how your data is handled on our side with the same care we apply to your suppliers, because we would otherwise be one more exposure in your chain.
- Can you help us fix what you find?
- Every report comes with a remediation roadmap, and we stay available after delivery to work through it with you. We do our best to guide you, though severe findings such as an active breach may call for a specialised response team.
- Is this everything we need to be compliant?
- No, and we would rather say so plainly. Supplier due diligence is one pillar of ISO 27001, DORA and NIS2. You will still need your own policies, governance and incident response, which an ISMS consultant or your IT partner typically covers. We produce the supplier evidence, and we work alongside those advisers rather than in place of them.
- Is the report a certification of the supplier?
- No, and that is deliberate. A report is documented due diligence: an evidence-based account of what the public record shows about a supplier, which is what auditors and customers ask you to produce. It is not a certificate, an audit opinion or legal advice, and those would come from a certification body, a statutory auditor or a solicitor. What we give you is the groundwork all three would want to see.
- Do you work with MSPs, vCISOs and consultancies?
- Yes. Partners who deliver our assessments under their own brand receive a partner schedule, and the arrangement is simple: you keep the client relationship, we produce the evidence. The method is always disclosed in the report itself, because traceability is the point of the work. Ask about it on the scoping call.