PuReAIpureAi

DORA & NIS2, continuously monitored

Both regulations rest on the same technical capability: knowing, at any moment, what your ICT supply chain is exposed to. PuReAI monitors that surface continuously — vendor CVEs, exploited vulnerabilities, breach records and threat-actor activity — and reduces it to one Company Risk Score you can put in front of a board.

What the regulations ask for

/dora

DORA

Financial sector · in force since January 2025

  • ICT third-party risk management across the full provider chain
  • A maintained register of ICT providers and the services they support
  • Continuous monitoring of ICT risk, not point-in-time assessment
  • Evidence trail for incidents and provider-related exposure
/nis2

NIS2

Cross-sector · critical and important entities

  • Supply-chain security as an explicit risk-management measure
  • Addressing vulnerabilities in suppliers and service providers
  • Risk-management measures proportionate to actual exposure
  • Management-level accountability for the security posture

Requirement to capability

Each obligation maps to a module that already runs on every monitored domain — no separate compliance tool, no annual questionnaire cycle.

ICT third-party riskSupply ChainContinuous scoring of vendors, partners and ICT dependencies, with each dependency mapped to its own exposure.
Supplier vulnerabilitiesVulnerabilityDetected products and versions matched against NVD, with CISA KEV marking what is actively exploited in the wild.
Threat monitoringNews / ThreatsRansomware actor activity and MITRE ATT&CK TTPs correlated to your sector and your vendors.
Exposure & data leakageDomain · IP · Certificate · Leaked DataExternal discovery of assets, services, certificates and credentials exposed in third-party breaches.
Management reportingCompany Risk ScoreOne weighted score per company: Compromises 40%, Issues 30%, Supply Chain 20%, Exposure 10%.

Evidence, not assertions

The threat graph keeps the chain intact: which vendor, which product and version, which CVE, whether it is on CISA KEV, which actor is known to exploit it, and when it was first observed. That chain is what turns a claim of “we monitor our suppliers” into something an auditor or a regulator can follow.

pureAi · threat-intel chat
You

Which of our ICT providers are affected by actively exploited vulnerabilities right now?

pureAi

Returns the affected vendors, the CVEs behind them, their CISA KEV status, the threat actors linked to those CVEs and the change in each vendor’s score since the last scan.

/ scope

PuReAI provides the continuous third-party and ICT supply-chain monitoring capability that DORA and NIS2 require, and the evidence to report on it. It is not a legal certification service and does not by itself make an organisation compliant — compliance also covers governance, contracts, incident reporting processes and internal controls outside the platform.

Know your supply chain before the regulator asks.