What a buyer finds out about you before they call.
Procurement, prime contractors and security teams check you before they speak to you. Enter your domain and see what they find.
The first assessment happens without you.
NIST calls basic supplier due diligence “desktop-based research using publicly available information”: research using what is public anyway. It covers company details, provenance, resilience and the security of your publicly reachable IT. You are not in the room, and you never hear the result.
NIST SP 1326, July 2026 ↗A visible version number is a finding, not a blemish.
The same list names “presence of obsolete software versions”, next to open ports and patching cadence. If your CMS writes its version into the page source, the question about your patch level is answered before anyone asks it. A company selling security, defence technology or critical components then contradicts its own claim.
NIST SP 1326, Foundational Cyber Practices ↗Your customer has to justify choosing you.
NIS2 obliges essential and important entities to secure their supply chain as well. Management is explicitly liable, and the maximum fine is at least €10 million or 2% of worldwide annual turnover. Whoever engages you has to defend that to procurement, legal, security and, if it comes to it, a regulator. Anything that makes this easier works for you.
Directive (EU) 2022/2555, Art. 20, 21, 34 ↗You are assessed by the supply chain, not by the ministry.
The UK Ministry of Defence spends around £5bn a year with SMEs: 25% directly, 75% through the supply chain. So you are not assessed once, but by every prime contractor, integrator and consortium lead that passes you on. And competition is growing: EU defence spending reached €418bn in 2025 (+20%), and the European Defence Fund drew 410 proposals (+37%) for 57 selected projects.
MOD SME Action Plan, 21.07.2026 ↗- €418bn
- EU DEFENCE SPENDING 2025
- €454bn
- PROJECTED 2026
- 410
- EDF 2025 PROPOSALS (+37%)
- 57
- PROJECTS SELECTED
Sources
Every figure on this page is in a public document. The links go straight to it.
- NIST SP 1326 · C-SCRM Due Diligence Assessment Quick-Start Guide (July 2026) ↗
- Directive (EU) 2022/2555 (NIS2) · Art. 20, 21, 34 ↗
- European Defence Agency · EU defence spending €418bn (2025), €454bn projected (2026) ↗
- European Commission · EDF 2025: 410 proposals, 57 projects, 634 entities, over 38% SMEs ↗
- UK Ministry of Defence · SME Action Plan: 25% direct, 75% through the supply chain ↗
- Ponemon Institute / NOLA (June 2026, 320 decision-makers) · 45% name website content as an evaluation resource, 52% find messaging lacks technical depth ↗
- RFC 9116 · security.txt ↗
Uncomfortable findings are the good news.
Request an offerRather talk? Twenty minutes is enough.
Some things are easier said than written. A short call is enough for a first assessment – afterwards you get the same offer as through the form.