Third-party risk under DORA and NIS2, demonstrated rather than assumed.
A supplier register with tiering, a dependency graph down to subcontractors and a Register of Information export that refuses a half-empty file. Built and hosted in the EU.
From now to next
From supplier list to a demonstrable view of the chain
Every organisation has a list of suppliers. Showing how deeply those suppliers are embedded in your own processes, and substantiating that to the supervisor, is another matter.
Nobody oversees the chain
When a supplier fails, only then does it become clear which business functions and subcontractors depend on it.
Dependency graph
Business functions, suppliers and their subcontractors in one graph, with the critical paths visible.
The register is never finished
The Register of Information is assembled in a spreadsheet at the last minute, with gaps nobody notices.
Export with a validation gate
The export (DORA art. 28(3)) refuses a register with missing mandatory fields, and says which.
Assurance sits in a folder
Supplier ISAE and SOC reports are requested but not assessed in a structured way.
Assurance in the same environment
Reports are requested and assessed per supplier, and a report that no longer covers stands out in the cockpit.
What TPRM offers
One environment for the whole chain
TPRM brings register, graph, contract requirements, assurance and notification duties together, so you answer the supervisor from one place.
Tiering
Every supplier gets a criticality, from critical to supporting, with its assessment date alongside.
Dependency graph
From business function via supplier to subcontractor, so concentration risk becomes visible.
Register of Information
Export in line with DORA art. 28(3), with a gate that stops an incomplete register.
Contract requirements per framework
Requirement lists for DORA, NIS2, CRA and ISO 27001, to check off per supplier.
Notification simulator
Calculates the NIS2, DORA and GDPR reporting deadlines for an incident at a supplier.
A cockpit that counts fairly
One score for the chain; a measure that does not apply to you does not count as zero, and an empty register never shows green.
How it works
From supplier to accountability in five steps
Record the suppliers
Register suppliers with tiering, contract and assessment date.
Map the chain
Link business functions, suppliers and subcontractors in the dependency graph.
Test contract and assurance
Check the contract requirements per framework and assess supplier assurance reports.
Rehearse the notification duty
Use the simulator to see which reporting deadlines start when a supplier fails.
Report to the supervisor
Export the Register of Information once the validation gate is green.
Know who is in your chain, and be able to prove it?
Request a demo or get in touch for more information about TPRM for your organisation.