EU Vendor Security Due Diligence

Acerta

Vendor trust, verified.
CIA-based risk tiering. OSINT-backed verification.

Built for procurement and security teams operating under GDPR, NIS2 and DORA. Not another Excel spreadsheet.

View Demo Scenarios
GDPR 2016/679NIS2 2022/2555DORA 2022/2554EU AI Act 2024/1689ISO 27001NIST CSF 2.0
Methodology

Four stages. Zero guesswork.

01

IRQ Intake

Six questions determine your CIA exposure vector and assign an inherent risk tier — before the vendor is contacted.

02

CIA Tier Assignment

Confidentiality, Integrity and Availability scores are normalised to a 1–4 tier. Tier drives question depth.

03

Adaptive DDQ

12 EU-aligned domains, 150+ questions. Vendors receive only what is proportionate to their tier.

04

OSINT + Report

Tier 1–2 vendors undergo automated OSINT vetting and analyst sign-off before a scored PDF report is issued.

Differentiator

Vendors can say anything.
OSINT does not lie.

For Tier 1 and Tier 2 vendors, Acerta goes beyond self-attestation. Automated checks across EU registries, sanctions databases, breach records and external security posture — followed by a structured analyst review before approval.

  • OpenCorporates · EU company registry verification
  • EU Financial Sanctions List · OpenSanctions (332 sources)
  • HaveIBeenPwned · data breach history
  • Shodan · external attack surface (passive)
  • Adverse media · regulatory fines · court records
  • Financial health · insolvency register check
Sample OSINT Finding
CLEARCompany Registration
CLEAREU Sanctions Screening
FLAGData Breach History — 1 domain breach (2021)
CLEARExternal Security Posture
CLEARAdverse Media
Try it

Demo Scenarios

Pre-configured vendor scenarios. Loads directly into the assessment flow.