Most NIS2 obligations have a playbook. Supply chain security doesn't.
Vittnor — Supply Chain Assurance for the mid-market. It turns supplier proof into structured, audit-ready records — without the spreadsheet sprawl. Built for the buyers that bigger players ignored, in central Europe by a cybersecurity practitioner who's been in your shoes.
Walk through the NIS2 obligations as a CISO or Head of IT. Awareness training has a playbook. Incident response has a runbook. Patch management is procedural. Supply chain security isn't. The evidence sits with external parties. It arrives in a dozen formats. It expires unevenly. And someone has to defend the decisions later. That's why Vittnor is its own product — because the obligation deserves its own tool.
Structured supplier evidence — without the spreadsheet sprawl.
Vittnor turns supplier proof — certificates, audit reports, contract clauses, policy documents — into Evidence records with expiry context and a full decision trace. When a supplier has an incident, an auditor asks a hard question, or a regulator sends an inquiry, you have the answer in minutes, not hours.
- Process-driven supplier scoping
- Structured assessment with AI assist
- Evidence records with review history
- NIS2-shaped audit exports — structured, hash-anchored, defensible

Microsoft Azure, EU regions only.
Read the long-formFull list, updated on every change. DPA template available before the deal.
Read the long-formHash-anchored, signed, decision-traced. Stands up six months later, unchanged.
Read the long-formWhen a supplier discloses an incident.
One scenario. Two ways it goes. The difference is what you signed up for the day before it happened.
Open the supplier register spreadsheet. Search SharePoint for their last assessment, your inbox for the contract clauses, a different folder for the evidence files, your calendar for the last review date. Half a day per supplier. Longer if the original reviewer has left. By the time you've reconstructed who reviewed what and when, you're not sure you have the latest version of anything.
One record per supplier. Current evidence, review history, contract clauses, in-scope services — linked, dated, exportable. The CEO gets the answer the same morning. The auditor gets the same answer six months later, unchanged.
The product nouns, plainly.
No 24/7 SOC. No managed endpoint. We build the supplier-assurance tooling that should have existed when the founder was the practitioner filling the spreadsheets — and we're honest about what it's for.
How it fits togetherSub-processor lists, certificates, audit reports — linked, dated, hash-anchored, with reviewer attribution. Always the latest version.
Every approval, rejection, and escalation timestamped and signed. Auditor asks "why was that rejected" — you hand over the trace.
Machine-readable export of every approved evidence record, every reviewer decision, every signed dossier — built to match the structure a NIS2 auditor expects.
Pavel Láska.
Built by the practitioner.
Shards Cybersecurity was founded by Pavel Láska — a CISSP- and CISM-certified cybersecurity practitioner with over a decade across banking, pharma, and education.
Eight years in the banking sector progressing from senior engineer to senior risk manager. Time on critical financial infrastructure. Reporting to board level. Then a global security services team in pharma across three continents. The credibility chain runs practitioner → witness → builder: he was the one filling the spreadsheets, defending the supplier decisions, prepping for the audits. Vittnor is the tooling that should have existed back then.
The product was shaped by quiet conversations with practising CISOs and security leads across regulated industries — people who've sat in the audit chair, defended supplier decisions to boards, and lived with the consequences. They're not named on this page, but they're in the product.
Bratislava · CISSP · CISM · Microsoft Partner
Built on Microsoft Azure, with a Microsoft-first architecture and security model. Microsoft Marketplace listing goes live Q4 2026; V1 commercial launch Q1 2027.
Bratislava-headquartered, EU-hosted. In pilot conversations with regulated buyers across the EU and UK.
Designed for NIS2 supply-chain obligations from day one — not retrofitted from a generic GRC suite.
Two ways to start. Both open today.
Ten minutes. Pavel reads every application himself.
Thirty minutes on your supplier register and what the pilot should prove.
Your first suppliers in the platform within two weeks — free for the first cohort.
Run your supplier register in Vittnor — free for the first cohort of design partners. You shape what ships; V1 lists on the Microsoft Marketplace Q4 2026.
Start with the NIS2 Supplier Exposure Assessment — fixed scope, fixed deliverable, €3,900 one-off. A practitioner-written report on where your supplier risk actually sits, in two to three weeks.
Pilot open today. Free for the first cohort.
The pilot is open now — we are onboarding the first cohort of design partners today. The live production version (V1) is planned for Q4 2026 via the Microsoft Marketplace.
Pilot customers join free or at compute cost. Mutual exchange — we help you, you help us. The first cohort gets the lifetime of input on what we build next.
After the pilot: published prices, no quote calls — free up to five suppliers, paid tiers from €3,500/yr. See pricing →
