Supplier due diligence · Independent practice · Dublin, Ireland

We do one thing: due diligence on suppliers, for businesses whose customers demand proof.

Every finding in our reports can be traced back to a public source, so nobody has to take the result on faith.

Who this is for

Not every business needs this.

This is for small and mid-sized companies that recognise themselves in one of these situations:

  • A customer's due diligence is holding up a deal or a renewal.
  • An ISO 27001, DORA or NIS2 requirement covers your suppliers, and the evidence is not there yet.
  • Someone expects supplier verification to happen, and nobody in-house has the time or the method.

In each case a questionnaire will not satisfy anyone, and an enterprise platform costs more than the problem justifies.

The stakes are not abstract. NIS2 backs supplier oversight with fines of up to €10 million or 2% of global turnover, and holds management personally accountable for it. Documented due diligence is what stands between an obligation and a finding.

If you manage thousands of suppliers, a platform will serve you better.

If you have a handful of suppliers that matter and a customer or auditor who will look closely, you are in the right place.

The principle

Everything in the report can be traced back to where we found it.

Nothing goes into a report that cannot be walked back to its source. A customer, an auditor, or a supervisor reading an assessment can check any finding themselves, because every one of them comes from records that are publicly available.

Company registriesOwnership filingsCourt and regulatory recordsBreach disclosuresPublic-facing infrastructure

We do not use a proprietary score and there is nothing hidden in the method. The sources are public. What you pay for is knowing where to look, what the findings mean against the framework your customer or regulator requires, whether that is ISO 27001, DORA or NIS2, and which findings need attention first.

The discipline comes from the open-source investigation world, where researchers publish their methods precisely so the work can be checked. We hold ourselves to the same standard, and it is what makes the work hold up under audit.

Why not just a questionnaire?

There are three ways to answer “how do you know your suppliers are safe?”

A questionnaire

You send the supplier a form and they fill it in about themselves. Cheap and fast, but every answer is self-attested. When a customer or auditor asks how you verified the claims, there is no answer.

Self-attested

A ratings platform

An automated score across thousands of suppliers. Useful at portfolio scale, but the method is proprietary, the score cannot be independently checked, and nobody reads your ten suppliers closely.

Unverifiable score

An evidence-based report

A person examines the public record on the suppliers that matter to you and writes down what it shows, with every finding traceable to its source. It is the only one of the three that survives a doubter.

Checkable evidence

All three have their place. We exist for the suppliers where someone is actually going to check.

What you get

One report per supplier, written so it can be checked.

Scope follows what your customers actually require, so you are not paying for work that does not apply to you.

One report per supplier

Every finding traceable to its source and mapped to the specific controls your customer or certifier applies, whether that is ISO 27001 supplier controls, DORA, NIS2 or a combination.

A findings summary

Prioritised by risk, so you can see what needs attention first and what can wait until the next review.

A remediation roadmap

Practical actions in a sensible order, with a realistic view of what can be fixed and by when.

How a finding readsIllustrative example

Finding 3.2

The supplier's primary customer-facing domain permits TLS 1.0 connections, a protocol deprecated since 2021 and disallowed under the supplier's own published security policy.

Source: public TLS configuration of the supplier's production domain, verifiable by anyone, and the supplier's security policy as published on their website.

Maps to

ISO 27001 A.8.21

DORA Art. 28

NIS2 Art. 21(2)(d)

Ongoing monitoring, optional

An assessment describes a supplier on the day it was written. Certificates lapse, ownership changes, breaches surface, and infrastructure decays, which is why DORA and NIS2 both treat supplier oversight as continuous rather than one-off.

If you need the picture kept current, we re-run the same public-record checks monthly. Most months the result is a short note confirming nothing material has changed, which is itself evidence you can show an auditor. When something does change, you hear about it with the same source-traceable write-up as the original report.

How we work

The work is done by hand.

A small senior team does the work, and your information is never handed to a third-party AI service, because that would put one more party inside the very supply chain you are trying to get under control. Our position is not against tooling. It is that every conclusion must rest on evidence a human has verified and can defend, and we hold every supplier we assess, including AI suppliers, to that same standard.

And the point of it all is not the certificate. It is knowing your suppliers well enough to keep working with them safely, which is why we treat the report as the start of a relationship rather than the end of one.

Independent by design. We sell no software, resell no platform, and answer to no vendor, so the assessment has only one customer: you.

Client data on EU infrastructure
Client data is processed on EU infrastructure and seen only by the people doing the work. We also stay available after the report is delivered, to help close the gaps it finds.
Professional grounding
The practice is led by an individual member of ISACA, the professional association for IT audit, risk and governance.

What we examine

Every area we check is in the public record.

Ownership and control
Breach and incident history
Exposed infrastructure and leaked credentials
Email security posture, including SPF, DKIM and DMARC
Published subprocessor lists, including the AI services a supplier discloses
Published GDPR enforcement and regulatory actions
Court, regulatory and insolvency records
Adverse media
Certification claims

How an engagement runs

Three steps, no surprises.

01

Scoping call

You tell us who the supplier is and what your customer or regulator is asking for. We agree what the assessment needs to cover.

02

Assessment

We work through the public record and map what we find to whichever of ISO 27001, DORA and NIS2 apply to your situation.

03

Report and walkthrough

You receive the report and we talk you through it, finding by finding. We stay available afterwards to help close the gaps it raises.

How long it takes depends on the scope, but engagements are measured in days, not months.

Common questions

The things people ask before they email.

Do you need access to our systems?
No. The assessment is built from the public record and from anything you choose to share with us. We never ask for credentials and we do not probe, scan or hack anyone's infrastructure.
Will the supplier know they are being assessed?
No. We only read what is already public, so there is nothing for the supplier to detect. Nothing we do involves intrusion or anything unlawful, so no party is put at risk by the assessment.
What do you need from us to start?
The supplier's name and the requirement you have to satisfy, whether that is a customer's contract clause, an ISO 27001 audit, or a DORA or NIS2 obligation. The scoping call covers the rest.
Where is our information processed?
On EU infrastructure, seen only by the people doing the work. We think about how your data is handled on our side with the same care we apply to your suppliers, because we would otherwise be one more exposure in your chain.
Can you help us fix what you find?
Every report comes with a remediation roadmap, and we stay available after delivery to work through it with you. We do our best to guide you, though severe findings such as an active breach may call for a specialised response team.
Is this everything we need to be compliant?
No, and we would rather say so plainly. Supplier due diligence is one pillar of ISO 27001, DORA and NIS2. You will still need your own policies, governance and incident response, which an ISMS consultant or your IT partner typically covers. We produce the supplier evidence, and we work alongside those advisers rather than in place of them.
Is the report a certification of the supplier?
No, and that is deliberate. A report is documented due diligence: an evidence-based account of what the public record shows about a supplier, which is what auditors and customers ask you to produce. It is not a certificate, an audit opinion or legal advice, and those would come from a certification body, a statutory auditor or a solicitor. What we give you is the groundwork all three would want to see.
Do you work with MSPs, vCISOs and consultancies?
Yes. Partners who deliver our assessments under their own brand receive a partner schedule, and the arrangement is simple: you keep the client relationship, we produce the evidence. The method is always disclosed in the report itself, because traceability is the point of the work. Ask about it on the scoping call.
CS

Contact

Talk to us.

We are here to help you improve your compliance and security. A short, direct conversation is the best place to start, and replies come from the people who do the work, not an intake team.

Get in touch

We reply within two business days. The scoping call is free and carries no obligation: if the work is not a fit, we will say so.