Vendor Assessment

Supply chain security with a Supplier Portal and structured assessment

Vendor management, pre-built CRA frameworks, and a self-service supplier portal. Now live.

Articles 13(5) and 13(12) of the Cyber Resilience Act put supply-chain security on the manufacturer. With the Supplier Portal you send a request by email. The supplier opens a Magic-Link, answers 14 CRA criteria, uploads evidence and submits. No account, no password. You review every answer in the compare view and decide per criterion: Accept or Reject.

Magic-LinkNo login required
14+ criteriaCRA framework
1-ClickImport
Accept/RejectReview
app.kunnus.tech/compliance/requests/jane.doe@smart-systems.com
Supplier request

jane.doe@smart-systems.com

Submitted
13 Accepted1 Rejected0 Pending review
Information Security Policy
Does the vendor have a documented information security policy?
Your current value
Supplier proposed
Yes
Security_Policy_v1.pdf
You'll find the policy in the attachment.
Security Certifications
What security certifications does the vendor hold?
Your current value
Supplier proposed
ISO 27001
You selected ISO 27001, but haven't uploaded any evidence.
Vulnerability Disclosure Policy
Does the vendor have a public vulnerability disclosure policy?
Your current value
Supplier proposed
Yes

Key Benefits

Magic-Link Requests

Send compliance requests by email. Suppliers respond via a secure Magic-Link. No account, no password, no friction.

Compare & Review Workflow

Manufacturers see 'Your current value' next to 'Supplier proposed' and accept or reject individual answers. All in one compare view.

Evidence Upload in the Portal

Suppliers upload policies, certificates (ISO 27001, SOC 2, TISAX) and documents directly in the portal. Required evidence is enforced before submission.

Pre-Built CRA Framework

The CRA Vendor Security Assessment framework covers 14 criteria: from Information Security Policy and Vulnerability Disclosure to Incident Response Plan. Configurable per supplier.

Capabilities

Self-Service Supplier Portal with Magic-Link

Live since June 2026

Suppliers respond to requests via a one-time Magic-Link without creating an account. Sidebar navigation through every criterion, autosave, mandatory evidence, and a submit confirmation with spent token.

Compare view & Accept/Reject per criterion

CRA Art. 13(5)

For each criterion you see 'Your current value' alongside 'Supplier proposed'. Accept individual answers, reject with a comment, or request changes.

CRA Vendor Security Assessment

Art. 13(12)

Pre-built assessment framework with 14 criteria specifically for CRA-compliant vendor evaluation. Ready to use with configurable criteria.

Compliance Module Integration

Annex I Part II

Vendor assessments are fully integrated into the compliance module. Risk levels, evidence upload, and review workflow included.

Central Vendor Management

Full CRUD for vendor data with one-click import of common vendors. Supply chain risk overview with prioritization based on criticality of supplied components.

Use Cases

01

Magic-Link request to a supplier

The compliance manager sends a request with 14 CRA criteria to a supplier. They click the Magic-Link, fill out the portal, upload evidence, and submit. Without creating an account.

02

Review with Accept/Reject per criterion

The manufacturer reviews the supplier's answers in the compare view and accepts 13 criteria. 'Security Certifications' lacks evidence: Reject with comment 'You selected ISO 27001 but haven't uploaded any evidence.' The supplier automatically receives a fresh Magic-Link to correct it.

03

Initial Vendor Onboarding

A manufacturer imports their 50 most important vendors via one-click import and immediately starts with the CRA Vendor Security Assessment framework.

04

Audit Evidence for Supply Chain Security

Auditors receive structured evidence of all vendor evaluations -- including evidence, risk levels, and review history.

Secure your supply chain systematically

See how Kunnus connects vendor assessment and supply chain security. We'll walk you through the workflow in a personalized demo.

View Walkthrough