DORA & NIS2, continuously monitored
Both regulations rest on the same technical capability: knowing, at any moment, what your ICT supply chain is exposed to. PuReAI monitors that surface continuously — vendor CVEs, exploited vulnerabilities, breach records and threat-actor activity — and reduces it to one Company Risk Score you can put in front of a board.
What the regulations ask for
DORA
Financial sector · in force since January 2025
- ICT third-party risk management across the full provider chain
- A maintained register of ICT providers and the services they support
- Continuous monitoring of ICT risk, not point-in-time assessment
- Evidence trail for incidents and provider-related exposure
NIS2
Cross-sector · critical and important entities
- Supply-chain security as an explicit risk-management measure
- Addressing vulnerabilities in suppliers and service providers
- Risk-management measures proportionate to actual exposure
- Management-level accountability for the security posture
Requirement to capability
Each obligation maps to a module that already runs on every monitored domain — no separate compliance tool, no annual questionnaire cycle.
Evidence, not assertions
The threat graph keeps the chain intact: which vendor, which product and version, which CVE, whether it is on CISA KEV, which actor is known to exploit it, and when it was first observed. That chain is what turns a claim of “we monitor our suppliers” into something an auditor or a regulator can follow.
Which of our ICT providers are affected by actively exploited vulnerabilities right now?
Returns the affected vendors, the CVEs behind them, their CISA KEV status, the threat actors linked to those CVEs and the change in each vendor’s score since the last scan.
PuReAI provides the continuous third-party and ICT supply-chain monitoring capability that DORA and NIS2 require, and the evidence to report on it. It is not a legal certification service and does not by itself make an organisation compliant — compliance also covers governance, contracts, incident reporting processes and internal controls outside the platform.
