Skip to content
Nenkin

Use case: GRC and supplier risk

Evidence of supplier certification, exported on demand.

Pull the full certification timeline for any product in your supplier register. Documents archived with hashes, CVEs linked from NVD, structured CSV and JSON export for the audit trail. Replaces the stale vendor PDF in the supplier binder with continuously refreshed source data.

Three jobs NenkinTracker does for GRC teams

Audit-ready evidence on demand

Every Security Target, Certification Report, and Maintenance Report archived with its source URL, fetch timestamp, and content hash. When the auditor asks why you trust the certificate, the evidence file is one click away, not a vendor email chain from six months ago.

CVE-to-certificate linkage for vuln post-mortems

When a vulnerability lands against a certified product, you need the certified scope, the affected versions, and the remediation status in one view. NenkinTracker links NVD CVE entries to the certificates impacted, so the post-mortem starts with the timeline already assembled.

Continuous timeline, not a quarterly rebuild

The certification timeline updates daily as schemes publish. No more spreadsheet re-population at audit time. CSV and JSON export when you need to drop the data into your GRC system or attach to a control evidence record.

What you can export

  • Per-product certification timeline - every certificate ever issued, with scheme, certificate ID, security level, issue date, expiry, and current status.
  • Document version history with hashes - every Security Target, Certification Report, and Maintenance Report archived with source URL, fetch timestamp, and SHA-256 content hash.
  • Linked CVE list: NVD entries attached to the certified product, with CVSS severity, affected versions, and references.
  • Vendor-level rollups: aggregate the certification posture across every product from a given supplier, useful for vendor onboarding scorecards.
  • Structured CSV and JSON: every export is a flat structured file ready to drop into Archer, ServiceNow GRC, OneTrust, AuditBoard, or any GRC platform with a CSV import.

Verify vendor roadmap claims against the public pipeline

A vendor that tells an auditor "our next-generation product is currently in evaluation" is making a checkable claim. Every major certification body publishes a "Products in Evaluation" list (BSI, NIAP, CCCS, JISEC, CSEC Sweden, TrustCB, Brightsight, and the equivalents). NenkinTracker ingests all of them daily, so an analyst chasing a supplier's certification roadmap can confirm whether the claim is in the public list, against which lab, and against which assurance package, or surface that it is not.

The same view supports compliance-roadmap planning. A control pinned to a deprecated certified product can be mapped against what is actually in evaluation today, so the documentation team is not promising customers a certified migration path that does not exist in any scheme's queue. Background on the pattern is in Procurement Planning Before the Certificate Exists.

Sized for an analyst or a team.

The Professional plan at €99/month includes 10 lists and up to 100 followed products, with CVE visibility across the catalogue. Team at €299/month includes unlimited lists and products, evaluation tracking, and following up to 3 developers. Add teammates for €149.50 per user per month (half the plan price). Enterprise at €499/month adds unlimited developer following, certification-source feeds, and custom notifications. All prices exclude VAT.

The 30-day free trial includes Enterprise features, no credit card required.

Frequently asked questions

How do I pull certification evidence for a product in our supplier register?
Sign in to NenkinTracker, search for the product by name or vendor, and follow it. Review the certification history, retained document versions, and linked CVEs. The Professional plan at €99/month excluding VAT covers up to 100 followed products across 10 lists.
What evidence does NenkinTracker preserve for an audit trail?
Each Security Target, Certification Report, and Maintenance Report we ingest is archived with the source URL, the fetch timestamp, the issuing scheme, and a SHA-256 content hash. When a scheme silently republishes a document, the new version is captured alongside the prior one, so you can reconstruct exactly what the certificate said on any given day. The hash chain is the audit-relevant artifact.
Can NenkinTracker email us when a CVE is published against a certified product we depend on?
Yes. Follow the products that matter to your vendor risk register to receive email and in-app notifications about linked CVEs. Professional costs €99/month excluding VAT and covers up to 100 followed products across 10 lists. Team costs €299/month excluding VAT and includes unlimited lists and followed products.
Does NenkinTracker integrate with our GRC platform?
Today the integration surface is the public read-only API and structured CSV / JSON exports, both available on every paid tier. That covers ingestion into the major GRC platforms (Archer, ServiceNow GRC, OneTrust, AuditBoard) via their import paths. Direct connectors are not yet shipped; talk to us if a particular GRC platform is high-priority for your team.
How can we verify that a vendor's claim of 'currently in evaluation' is real?
Every major certification body publishes a public 'Products in Evaluation' list, and NenkinTracker ingests them daily (BSI, NIAP, CCCS, JISEC, CSEC Sweden, TrustCB, Brightsight, and the equivalents). Search returns under-evaluation products with an 'Under Eval' badge and links to the scheme's published entry, including the sponsor, developer, registered title, and (where the scheme publishes it) the targeted assurance package. If a vendor's claim does not appear in any scheme's pipeline list, the product is not in evaluation at that scheme.

Replace the supplier binder with evidence on demand.

Start the 30-day free trial and add the products in your supplier register. The first export is one click away.