← TrendWatcher
Hacker News
6/10

Sovereignty Stack Auditor

A weekly scanner that scores your EU data-sovereignty risk surface — naming exactly which US vendors sit in front of your web stack, what data crosses borders, and what to negotiate next quarter — built for the mid-market companies that have to answer to NIS2 and DORA.

Target user

Heads of IT, CISOs and procurement leads at EU mid-market companies preparing for NIS2 or DORA audits

Features
  • Continuous DNS + ASN scanning of your primary domains with EU-vs-third-country vendor attribution and concentration-risk scores
  • Per-vendor portability checklist showing what data, configs and identity bindings would survive if a US vendor dropped tomorrow
  • EU-sovereignty red-flag map highlighting which subcontractors forward data to non-EU subprocessors and which hold certifiable EU-only data planes
  • Negotiation briefs generated per renewal that surface realistic EU alternatives with switching-cost estimates
Why now

NIS2 and DORA are now enforced and the CipherCue study proved most EU companies don't even know the vendor mix that fronts their public estate — that blind spot will define the next audit-failure cycle.

Signals · overall 6/10
Demand
8/10

Strong regulatory pull: DORA in force since 17 Jan 2025, NIS2 transposition deadline 17 Oct 2024 missed by most Member States (19 reasoned opinions from Commission in May 2025), and CipherCue's fingerprint of 19,450 EU sites confirms the blind spot the idea targets.DORA vs NIS2: How EU Cyber Resilience Regulations Differ and OverlapEurope's company websites are mostly served by US vendors - CipherCue

Whitespace
3/10

Market is already crowded with very close substitutes: meetergo's Sovereignty Scan already tracks 3,040 vendors with jurisdiction/CLOUD Act/DPF and is free, Sovereignly.eu offers a free website sovereignty scanner, kajaril ships sovereignty-scan, and CipherCue commercialises the underlying fingerprint data. GRC incumbents (OneTrust, Vanta, Brandefense) also cover NIS2/DORA TPRM.Vendor Directory - Sovereignty Scan · meetergoWebsite Sovereignty Scanner by Sovereignlysovereignty-scan — kajaril

Monetization
5/10

Free scanners from meetergo and Sovereignly set a $0 anchor for the core scan, so paid monetisation must come from continuous monitoring, NIS2/DORA evidence packs, or procurement workflows. GRC vendors charge mid-market €1–10k/yr for TPRM modules, which is reachable but price-sensitive against free baseline.Vendor Directory - Sovereignty Scan · meetergoNIS2 and DORA Compliance: What They Require for Third-Party Risk

Longevity
9/10

Multi-regulation tailwind (NIS2, DORA, CRA, GDPR/DPF litigation) plus the EU sovereignty policy push (sovereign cloud, Gaia-X successors) means structural demand for at least 5+ years regardless of AI shifts.EU Cyber Resilience Update: NIS2, CRA, and DORA | CSAEU Sovereign Cloud Tender Exposes SEAL Compliance Risk

Feasibility
7/10

Core detection (DNS/MX, CNAME cloaking, CSP, DKIM, TLS SANs, script tags) is proven and open-source-ish; a weekly scheduled re-scan + scoring + negotiation playbook is straightforward to ship. Main cost is curating vendor jurisdiction data, which is the moat but also the bottleneck.Vendor Directory - Sovereignty Scan · meetergo

Europe's company websites are mostly served by US vendors · 218 points · 142 commentsHacker News · 2026-07-07 (17d ago)