
GRC Platform
EurisQ answers a key question for management: which ICT suppliers can be trusted with access to your environment — and which to keep out. Instead of sending fragmented questionnaires and reviewing them manually, assess suppliers using one standardized methodology with comparable risk scores and clear decision thresholds.

EurisQ is a Polish SaaS platform
EurisQ standardizes and automates ICT supplier cybersecurity assessments for organizations subject to NIS2, DORA, and the Polish National Cybersecurity System (KSC).
Suppliers complete a single assessment, producing comparable and repeatable risk scores with clear decision thresholds: Accept, Accept Conditionally, Conditional Acceptance, or Reject. EurisQ is developed by Sisoft sp. z o.o. and is available at eurisq.pl.
150+
security controls
7
assessment domains
1900
control-to-requirement mappings
15
standards and regulations
Where EurisQ Comes In
NIS2, DORA, and the updated Polish National Cybersecurity System (KSC) Act share one common principle: your organization — not your ICT suppliers — is responsible for managing supply chain cybersecurity risk.
Management must be able to demonstrate that suppliers have been assessed using a consistent, repeatable methodology and that every decision can be justified during an audit. Traditional questionnaires fall short. Each supplier responds differently, making meaningful comparison and ranking impossible.
Spreadsheets become outdated within weeks and cannot be reused effectively. You may end up with hundreds of completed questionnaires — but still have no clear answer to whether a supplier should be approved.
EurisQ replaces this process with a single standardized methodology based on “assess once, use many times” principle. Suppliers complete one assessment, while you receive a comparable risk score with clear decision thresholds — ready to guide a management decision and to hold up under regulatory scrutiny.
Fragmented Questionnaires vs. Standardized Assessment
It's the difference between a shoebox of receipts and an audited financial statement. The data may be the same, but only a standardized methodology turns it into a reliable basis for decision-making.
Criteria
Fragmented Questionnaires
EurisQ
Comparability
Every supplier responds differently, making ranking impossible.
One scoring model and weighting system produce comparable results and supplier rankings.
Data Freshness
One-time assessments that become outdated within weeks.
Reusable assessments that can be updated over time.
Decision Support
Hundreds of responses without clear decision criteria.
Risk tiering with clear outcomes: Accept, Conditional Acceptance, Reject.
Supplier Data
Entered manually.
Retrieved directly from official registries.
Audit Readiness
Difficult to justify during audits.
Results mapped to standards and regulations, ready for regulatory review.
Platform Access and Sign In
Already have an EurisQ account? Sign in at eurisq.pl and manage all your ICT supplier assessments in one place.
Don't have access yet? Book a demo. We'll walk you through the platform using your own use case, tailor the assessment to your NIS2, DORA, or KSC requirements, and set up your account.
Key Benefits
Comparable Risk Scores
A single assessment model with consistent weighting across security domains. Every supplier is evaluated on the same scale, making results directly comparable and easy to rank.
Assess Once, Use Many Times
Suppliers complete one assessment through a single process. Assessments are reusable and can be updated over time instead of starting from scratch for every customer.
Clear Decision Thresholds
Risk tiering transforms assessment results into clear outcomes: Accept, Accept Conditionally, Conditional Acceptance, or Reject. Management receives a decision-ready risk assessment rather than raw technical responses.
Audit Readiness
Assessments are based on recognized standards, including ISO/IEC 27001:2022 and ISO/IEC 27036, and mapped to the requirements of NIS2, DORA, and the Polish National Cybersecurity System (KSC). Results and supporting evidence are ready for regulatory review.
How EurisQ Works
From defining the assessment scope to continuous monitoring, EurisQ guides the entire ICT supplier risk assessment process in a consistent, repeatable, and compliance-ready way.
Scope and Assessment Criteria
Define the assessment scope using a standardized set of security controls mapped to regulations and industry standards. EurisQ includes more than 150 security controls across 7 assessment domains and approximately 1,900 control-to-requirement mappings across 15 standards and regulations.
Supplier Assessment
Suppliers complete a single assessment through one consistent and predictable process. Supplier information is retrieved directly from official registries instead of being entered manually.
Risk Scoring and Tiering
Assessment responses are converted into a comparable risk score based on predefined decision thresholds. You receive a clear recommendation: Accept, Accept Conditionally, or Reject.
Continuous Monitoring
Assessments are not one-time events. They remain reusable and can be updated over time, ensuring your view of supplier risk evolves with changing circumstances rather than reflecting only the day the contract was signed.
See ICT Supplier Assessments in Action
During a short demo, we'll show you how EurisQ streamlines ICT supplier assessments, automates risk analysis, and supports compliance with NIS2, DORA, and the Polish National Cybersecurity System (KSC).
We'll answer your questions, recommend the right assessment scope, and demonstrate how EurisQ can support your organization.
What Makes EurisQ Different
A common scoring model, weighting system, and decision thresholds turn assessment data into decisions that can be confidently justified during an audit.
Built-in integrations with GUS BIR, KRS, VIES, GLEIF, the Polish VAT White List, and sanctions screening. Supplier profiles are built from authoritative source data, reducing manual effort and minimizing human error.
Powered by Microsoft Azure in Ireland and Sweden, using a multi-tenant architecture with database-level data isolation.
The built-in regulatory assistant provides recommendations, while all final decisions remain under human control. EurisQ is developed by Sisoft sp. z o.o., a cybersecurity company established in 2006.
The EurisQ platform was developed as part of a grant project co-funded by the Digital Europe Programme.
Project and Funding
Project Title
EurisQ – SaaS Platform for ICT Supplier Cyber Risk Assessments
Funding Programme
Funded by the Digital Europe Programme (DEP) under the National Coordination Centre, Poland (NCC-PL) project and the Financial Support to Third Parties (FSTP) programme, pursuant to Grant Agreement DEP.01.01/25/0047-00 of 13 March 2026, concluded with the Centre for Digital Poland Projects (CPPC).
Grant Amount
PLN 238,394.93 (100% funded), including 50% from the European Union budget (PLN 119,197.46) and 50% from the Polish state budget (PLN 119,197.47).
Project Duration
15 September 2025 – 30 June 2026
Co-funded by the European Union. The project was carried out within the National Coordination Centre for Cybersecurity (NCC-PL) in cooperation with the Centre for Digital Poland Projects (CPPC) and the Ministry of Digital Affairs of Poland.

Frequently Asked Questions
Find answers to the most common questions about ICT supplier cybersecurity assessments and the practical use of the EurisQ platform.
EurisQ is a SaaS platform for standardized and automated ICT supplier cybersecurity assessments aligned with NIS2, DORA, and the Polish National Cybersecurity System (KSC). It is based on a single standardized methodology with comparable risk scores and clear decision thresholds.
Sign in at eurisq.pl. If you don't have an account yet, book a demo and we'll set up your access.
NIS2 requires supply chain security to be part of an organization's cybersecurity risk management measures (Article 21(2)(d) of the Directive). Organizations are responsible for assessing and monitoring the cybersecurity of their ICT suppliers.
Articles 28–30 of DORA regulate ICT third-party risk management, including general principles, concentration risk, and mandatory contractual requirements. Financial entities must also maintain a register of information on contracts with ICT service providers.
TPRM is the process of managing risks associated with suppliers, contractors, and business partners. In the ICT context, it includes supplier cybersecurity assessments before onboarding and continuous monitoring throughout the business relationship.
Yes. EurisQ replaces fragmented security questionnaires with one standardized methodology, common scoring, weighting, and decision thresholds, making assessment results both comparable and reusable.
Data is hosted in the European Union on Microsoft Azure in Ireland and Sweden, using a multi-tenant architecture with database-level data isolation.
The EurisQ – SaaS Platform for ICT Supplier Cyber Risk Assessments project is co-funded by the Digital Europe Programme under Grant Agreement DEP.01.01/25/0047-00. The total grant amounts to PLN 238,394.93, covering 100% of eligible project costs.
Let's Stay in Touch
Interested in discussing cybersecurity in your organization or exploring how we can help? Fill out the form below or contact us directly.





