One dashboard. Clear actions. No complex software.
Technical Verification & Compliance
Concrete Solutions and Clear Assessments
Developed in Austria · from €1,990 per year
For companies to verify their suppliers, subcontractors or subsidiaries.

🟢 Green?
All good. Audit-ready.
🟡 Yellow?
Room for improvement. To-do list shows what needs to be done.
🔴 Red?
Critical. Concrete fix instructions included.
CheckFix automatically sends a professional invitation with access link to your security partners.
3. Automated security review + compliance questionnaires
|
Technical (Security Check):
|
Organizational (digital questionnaires):
|
Technical score: A-F rating of each supplier
Compliance status: 🟢🟡🔴 traffic light system
Critical findings: Which gaps need to be closed?
Audit status: Which supplier is audit-ready?
Audit-ready reports with before/after comparison for BSI evidence and internal audits.

For Risk Managers
For Security Partners
SPF, DKIM, DMARC configuration → Prevents phishing and email spoofing
TLS versions, cipher strength, certificates → Protects data during transmission
Software versions vs. vulnerability databases → Protects against ransomware
CSP, HSTS, X-Frame-Options → Prevents XSS and clickjacking
Open ports and accessible services → Minimizes attack surface
Here you can find details on the 10 additional test steps: DNS configuration, blacklist status, cookie security, subdomain scanning, SSL/TLS best practices and more.
For security partners (suppliers, service providers, subcontractors): Were you invited by your client? → See CheckFix Premium (€950/year)
Fully Automated
Zero-touch assessment in 24 hours
Technical AND Compliance in 1 Tool
External security check + organizational measures
Central TPRM Overview
Technical score + compliance status in one dashboard
Concrete Action Instructions
Prioritized to-do lists instead of endless reports
Before/After Documentation
Audit-ready evidence for technical AND organizational improvements
Made in Austria
German-speaking support & GDPR compliant
A check cycle consists of two components:
Technical review:
Organizational review (optional):
The result: Audit-ready before/after documentation for technical AND organizational security measures.
CheckFix only scans what an attacker from the internet would also see:
We do not penetrate your systems. No internal scans, no agents, no admin rights required.
CheckFix provides pre-made questionnaires based on established standards:
You can use the pre-made templates or create your own questionnaires.
Yes. NIS2 requires “regular risk assessments” but does not define a minimum frequency.
Two structured check cycles per year with documented improvements are best practice for medium-sized KRITIS operators and meet NIS2 requirements for both technical and organizational risk assessments.
Daily monitoring (like SecurityScorecard) is not required for NIS2.
CheckFix is the technical AND organizational complement to your internal compliance processes.
CheckFix focuses on auditing your supply chain – technically and organizationally. For your own internal processes, you continue to use your GRC software.
CheckFix comprehensively meets NIS2 requirements for external risk assessments:
Technical:
Organizational:
CheckFix covers both pillars of NIS2 requirements for your supply chain: technical security AND organizational measures.
The process is fully automated:
Yes – as long as they have an active CheckFix subscription. Both the technical CheckFix score and the compliance evidence are independent external assessments.
A service provider with green status (technical A-B + organizational 🟢) can use these proofs for any number of KRITIS clients – without having to fill out new questionnaires or perform security assessments each time.
This saves time and costs on both sides.
CheckFix makes the process transparent and actionable:
This way, a red status becomes step by step a green one – measurably and audit-ready documented.
Book a personal demo and see how CheckFix automates your third-party risk management.