Know who you are actually working with
We screen suppliers, service providers and business partners before you sign and continuously afterwards. The focus is on companies and their officers, not on your employees.
A check at contract signature is a snapshot. The risk arrives afterwards.
Shell companies, mailbox addresses and entities set up shortly before a bid cannot be spotted in tender documents.
Insolvency signals, changes of ownership and sanctions hits appear during the relationship, not before it.
Your providers' security maturity becomes part of your own risk the moment they touch your systems or data.
Existence and structure
- Company registry extract, incorporation date, authorised representatives and actual trading activity
- Beneficial owners, ownership chains and interconnections between partners
- Detection of shell companies, mailbox addresses and registered-seat moves shortly before award
Risk and solvency signals
- Screening against the relevant sanctions lists, including hits on officers and shareholders
- Insolvency, payment and credit signals with continuous monitoring instead of a one-off query
- Adverse media and registry events, interpreted rather than merely listed
The partner's security maturity
- A structured supplier questionnaire covering access, data storage, backups and incident reporting
- Reconciliation with certificates and evidence such as ISO 27001, including a check of their scope
- Per-partner documentation you can present in an audit and to your own customers
Monitoring instead of a snapshot: you hear about changes while the contract is running.
A supplier file that stands up to supply chain security requirements.
Screening of companies and their officers, no vetting of individual employees.
Third-party risk
Am I legally required to screen my suppliers?
If you fall under NIS2, yes. Section 30(2)(4) of the German BSIG explicitly requires supply chain security, including security-related aspects of relationships with direct suppliers or service providers. That is a genuine legal obligation, not a recommendation.
How do I know whether NIS2 applies to me?
Important entities are in scope from 50 employees or from 10 million euros in both turnover and balance sheet total, provided they operate in one of the listed sectors. Sector membership is the real hurdle, not size. We work this out with you based on what your company actually does.
What if my own company is out of scope?
Then you are usually regulated indirectly through your customers' supply chains. Regulated customers pass their requirements down contractually, typically as questionnaires, evidence duties and reporting deadlines. Being prepared makes tenders easier to win.
Which other standards can you map to?
ISO 27001:2022 addresses supplier relationships in A.5.19 to A.5.22, from writing requirements into contracts to monitoring service delivery. German anti money laundering law applies only to obliged entities such as goods traders and estate agents and is not relevant for most mid-sized companies.
Do you also screen applicants or employees?
No. Screening natural persons is tightly limited in Germany, particularly in an employment context under Section 26 BDSG. This service addresses companies and their officers, meaning management, shareholders and beneficial owners. We deliberately do not offer employee vetting.
Get your supplier file in order
Write to info@cavrix.de and tell us how many suppliers and service providers you work with. We will tell you what NIS2 actually requires in your case.