Supply chain security with a Supplier Portal and structured assessment
Vendor management, pre-built CRA frameworks, and a self-service supplier portal. Now live.
Articles 13(5) and 13(12) of the Cyber Resilience Act put supply-chain security on the manufacturer. With the Supplier Portal you send a request by email. The supplier opens a Magic-Link, answers 14 CRA criteria, uploads evidence and submits. No account, no password. You review every answer in the compare view and decide per criterion: Accept or Reject.
jane.doe@smart-systems.com
Key Benefits
Magic-Link Requests
Send compliance requests by email. Suppliers respond via a secure Magic-Link. No account, no password, no friction.
Compare & Review Workflow
Manufacturers see 'Your current value' next to 'Supplier proposed' and accept or reject individual answers. All in one compare view.
Evidence Upload in the Portal
Suppliers upload policies, certificates (ISO 27001, SOC 2, TISAX) and documents directly in the portal. Required evidence is enforced before submission.
Pre-Built CRA Framework
The CRA Vendor Security Assessment framework covers 14 criteria: from Information Security Policy and Vulnerability Disclosure to Incident Response Plan. Configurable per supplier.
Capabilities
Self-Service Supplier Portal with Magic-Link
Live since June 2026Suppliers respond to requests via a one-time Magic-Link without creating an account. Sidebar navigation through every criterion, autosave, mandatory evidence, and a submit confirmation with spent token.
Compare view & Accept/Reject per criterion
CRA Art. 13(5)For each criterion you see 'Your current value' alongside 'Supplier proposed'. Accept individual answers, reject with a comment, or request changes.
CRA Vendor Security Assessment
Art. 13(12)Pre-built assessment framework with 14 criteria specifically for CRA-compliant vendor evaluation. Ready to use with configurable criteria.
Compliance Module Integration
Annex I Part IIVendor assessments are fully integrated into the compliance module. Risk levels, evidence upload, and review workflow included.
Central Vendor Management
Full CRUD for vendor data with one-click import of common vendors. Supply chain risk overview with prioritization based on criticality of supplied components.
Use Cases
Magic-Link request to a supplier
The compliance manager sends a request with 14 CRA criteria to a supplier. They click the Magic-Link, fill out the portal, upload evidence, and submit. Without creating an account.
Review with Accept/Reject per criterion
The manufacturer reviews the supplier's answers in the compare view and accepts 13 criteria. 'Security Certifications' lacks evidence: Reject with comment 'You selected ISO 27001 but haven't uploaded any evidence.' The supplier automatically receives a fresh Magic-Link to correct it.
Initial Vendor Onboarding
A manufacturer imports their 50 most important vendors via one-click import and immediately starts with the CRA Vendor Security Assessment framework.
Audit Evidence for Supply Chain Security
Auditors receive structured evidence of all vendor evaluations -- including evidence, risk levels, and review history.
Related Features
Secure your supply chain systematically
See how Kunnus connects vendor assessment and supply chain security. We'll walk you through the workflow in a personalized demo.