Request a vendor scan
Would you like your supplier or ICT third-party provider to present CERTavia infrastructure evidence? Fill out the form, and we will contact the provider and coordinate the scan.
Use cases: DORA Art. 28 (third-party risk management), NIS2 supply chain requirements, EU AI Act Annex III systems with external data sources.
Your regulatory evidence about third parties
DORA Art. 28
Financial entities must continuously demonstrate the infrastructure integrity of essential ICT third-party providers. The CERTavia report can be embedded in ICT third-party registers and contract attachments.
NIS2 supply chain
NIS2 Art. 21 obliges essential and important entities to secure their supply chain. The cryptographically signed scan report documents the security status of suppliers at the time of testing.
EU AI Act data sources
AI systems access external data sources. Their infrastructure integrity is part of the Art. 50 requirements for transparency and provenance. A vendor scan proves the quality of the data source infrastructure.
Commission a vendor scan
We contact the provider and coordinate the scan. Delivery time after provider approval: 90-120 seconds. You and the provider receive the result by email.
Request received.
We will get back to you within 24 hours and coordinate the scan with the provider.