For organizations covered by NIS2 — directly or through their chain

Substantiate your NIS2 supply chain duty of care

The NIS2 directive requires you to take appropriate measures to secure your supply chain. Exposentry delivers continuous, forensically grounded vulnerability monitoring — defensible evidence that you demonstrably manage your digital attack surface.

What is the NIS2 supply chain duty of care?

NIS2 (implemented in the Netherlands through the Cyberbeveiligingswet) requires essential and important entities to manage risks in their supply chain. You are responsible not only for your own security, but also for overseeing the baseline security of your suppliers and service providers.

The obligation affects tens of thousands of organizations — directly as an essential or important entity, and indirectly as a supplier to such an entity. Regulators expect you to demonstrate which measures you take and to provide evidence of them.

How Exposentry substantiates your duty of care

Continuous monitoring

Weekly or monthly scans of your public attack surface, so new vulnerabilities surface quickly instead of once a year.

Forensically grounded evidence

OpenKAT records how and when a finding was detected. Timestamped evidence you can present to auditors, clients and insurers.

NIS2 art. 21 export

From Professional you export your findings in a format aligned with the management measures of article 21 of the NIS2 directive.

Suppliers in view

Alongside your own domains, monitor the public attack surface of critical suppliers — an affordable evidence layer for your chain responsibility.

Honest about what it is and isn't

Exposentry is a necessary building block for your vulnerability management and supply chain duty of care — defensible evidence that you continuously monitor your vulnerabilities. It is not a full compliance guarantee: NIS2 also covers governance, incident reporting and organizational measures. We provide the technical evidence, not a legal seal of approval.

Frequently asked questions about NIS2 and the supply chain duty

Does Exposentry make me NIS2-compliant?

No. Exposentry provides a demonstrable technical building block — continuous vulnerability monitoring with forensically grounded evidence. NIS2 also requires governance, incident reporting and organizational measures that fall outside the scope of a scan.

Am I covered by the NIS2 supply chain duty?

If you are an essential or important entity, the duty applies directly. If you provide services to such an entity, they will likely set requirements for your security — meaning the supply chain duty affects you indirectly.

How do I demonstrate my measures?

With timestamped scan evidence and a NIS2 art. 21 export you show that you continuously monitor your public attack surface and address vulnerabilities — evidence you can present to regulators, clients and insurers.

Can I also monitor my suppliers?

Yes. Alongside your own domains you can monitor the public attack surface of critical suppliers as an affordable evidence layer next to your existing questionnaires.

Start with defensible evidence

Begin with a one-time scan from €149 or continuous monitoring from €79/month. NIS2 art. 21 export included from Professional.

Start now

Prefer to run OpenKAT yourself or need your own implementation? Hasecon provides implementation, management and custom development →