The supplier, and the chain behind it
Suppliers sit as legal entities with their sub-suppliers registered centrally on them, and a Suppliers tab on an asset shows which of them sit behind that system, subcontractors included.
Register the supplier, check it on criteria you set yourself, get the answers and documents out of it, then assess it as a risk in your NIS2 risk area and put a costed plan on what has to come down.
Unlimited users • Free onboarding and support • No commitment
Anders Krogh is CISO at Meridian Nordic, an energy group running around 1,200 active suppliers and processors behind the metering platform, the customer portal and the field work. As an essential entity under NIS2 he is answerable for that chain, and the list he inherited told him who everyone was and nothing about what any of them could do to him. Now a supplier is checked on Meridian's own criteria, asked for the answers and documents Anders actually needs, and then assessed as a risk in its own right, with a plan and a price on the ones that matter.
Your criteria, not ours
Build the check you want, weight it yourself, and read a risk level that came out of your own answers.
No login for suppliers
They answer and upload documents from their own inbox, with no account and nothing to install.
The supplier as a risk
Assess the supplier itself against concrete scenarios in a NIS2 risk area, with a justification on record.
A plan with a cost
Accept it, avoid it or bring it down, and say what bringing it down is expected to cost.
Almost everybody has the list. What NIS2 asks about is what you did with it, and that is where most supply-chain work quietly stops.
Not every supplier needs the same treatment, and you should be the one deciding which is which. The classification is a questionnaire you build and answer yourself about the supplier, and it hands back a risk level.
You design the questionnaire: their security measures, their sub-suppliers, the certificate you want a copy of. Then you send it, to one supplier or to a whole group of them at once.
Every security team has the same three or four of them: too large to care, and too central to drop. There is a route for that, and it does not involve sending anything.
This is where the newer half of the story sits. With the Enterprise Risk Management add-on, released in August 2026, a supplier is an entity you assess, alongside processes and assets.
We would rather tell you this than let you find it in a demo. There are two ways to put a number on a supplier here, and they are separate mechanics.
Suppliers sit as legal entities with their sub-suppliers registered centrally on them, and a Suppliers tab on an asset shows which of them sit behind that system, subcontractors included.
Weight the sections, the questions and each answer option, set the intervals that turn an answer set into a risk level, and use the level to decide who gets looked at hardest.
Send the same questionnaire to a whole group of legal entities at once. Each gets its own instance and its own contact, and you follow who has opened it and who has submitted.
Close the check out with an auditor's report instead. Upload the document or register a link, and the supplier's status shows a report is in place. No email is sent to them at all.
Assess the supplier against concrete scenarios in a risk area with its own matrix and appetite, with a justification required on both consequence and probability. This sits in Enterprise Risk Management, a paid add-on that shipped in August 2026.
Three named treatments for a supplier risk: accept, avoid or mitigate. Mitigation is the one that produces a plan, and that plan carries a cost you can put in front of whoever approves the spend.
One framework, and the part of it this page is about.
NIS2
The supply-chain security an essential entity has to run: which suppliers sit behind your services, what you checked, what they answered, and what you decided about the risk.
Where suppliers live, and the audit engine behind the classification, the questionnaires and the auditor's report route.
Explore Vendor ManagementWhere the NIS2 framework, its controls and your security documentation sit, next to the supplier work on this page. Enterprise Risk Management, which assesses the supplier itself, is a separate paid add-on.
Explore Information Security Managementcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
12 use cases
No use cases match that combination yet. Try removing a filter.
As a sequence rather than a feature. You register the supplier, classify it on criteria you set yourself, send it a questionnaire and collect the documents you asked for, and then, with the Enterprise Risk Management add-on, assess the supplier itself against concrete scenarios in a NIS2 risk area and decide what to do about the result. The platform stands the sequence up and keeps the record of it. It does not tell you which suppliers are in scope, and it does not judge your chain for you.
Getting NIS2-ready without starting from scratchWith a classification you design. You choose the questions that matter to you, weight the sections, the questions and each answer option, and set the percentage intervals that turn a set of answers into a risk level. Nothing is scored for you. One thing worth knowing before a demo: the score runs the opposite way to the level, so a higher score means a lower risk. That is why we talk about the level and not the number, and why you should too.
Running the due diligence check itselfNo, and this is the seam most people find on their first demo, so we would rather say it here. The classification is a questionnaire you designed and answer yourself about the supplier, and it produces a risk level. The risk assessment in Enterprise Risk Management is a different mechanic: the supplier is an entity in a risk area, assessed against concrete scenarios on a matrix you configured. They sit side by side and they do not feed each other. A classification level does not become a risk assessment, and a risk assessment does not update a classification.
No. You register a contact person on the supplier and pick that contact when you send. The link arrives in their own inbox, and they can both answer the questions and upload the documentation without ever creating an account. How they pull the answers together internally is up to them, and whatever comes back is filed against that supplier.
Yes. One questionnaire goes out to a whole group of legal entities in a single send, and each one still gets its own instance with its own contact, so responses stay split per supplier. You see how many have opened it and how many have submitted. Reminders to anyone who has not responded go out automatically after 7, 14 and 21 days, and that cadence is fixed rather than something you configure.
You close the check out with an auditor's report instead of sending anything. Either exclude the supplier from the send with the auditor's report as the reason and upload the document, which then also appears under that supplier's documents, or register it directly from the supplier's audit tab with a responsible person and a document or a link. No email goes to the supplier, and the status shows that a report is in place. We do not tie that route to any named assurance standard, so what the report has to be is your call.
You can assess it. Suppliers are one of the entity types Enterprise Risk Management assesses, alongside processes and assets, so a supplier is assessed directly rather than only inheriting risk from a system it sits behind. You choose which entities a risk area assesses, so nothing is attached by default, and you then add scenarios to the supplier and state consequence and probability with a justification on each. Enterprise Risk Management is a paid add-on that was released on 14 August 2026, and it sits beside the risk assessment you may already be using rather than replacing it.
Yes. Each asset has a Suppliers tab showing the legal entities linked to it, including subcontractors, and sub-suppliers are registered centrally on the supplier itself rather than typed in again everywhere it is used. With the risk add-on there is also a relationship graph, and read from the supplier end it shows the same connections the other way round: which systems and processes a given supplier sits behind, so the reach of one supplier's risk is something you can actually see.
No, and we would rather be plain about it than let you find out later. There is no incident reporting to an authority in the platform, no statutory timers and no submission of any kind. What you get is the record: what you knew about the supplier, when you checked it, what it answered, how you assessed it and what you decided to do. We build the plan, not the filling-in. The platform documents your supply chain, it does not monitor it, so it is not a detection tool of any kind.
One incident log for GDPR and NIS2
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.