Sovereignty Is a Procurement Requirement, Not a Preference
Public bodies buy software under rules about where it runs and who can reach it. Whitespots is self-hosted by design: the platform, the findings and the audit trail sit on infrastructure the authority controls, including in environments with no route to the internet.
Runs inside sovereign infrastructure
On the authority's own hardware, in the authority's own network zone — including zones with no outbound route.
Contractor code in your database
Delivered software is assessed against your standard and recorded in your system, not in the supplier's dashboard.
Evidence for the audit that follows
Public bodies are audited on process. A dated per-finding record is the cheapest possible answer to how vulnerabilities are managed.
Inventory of what you actually run
Dependency scanning and asset discovery for every system, which is usually the missing half of a public-sector security baseline.
What Public Sector Security Teams Run Into
Government software is mostly built by other people, on schedules set by procurement, and inherited by a team that must defend it for a decade.
Cloud tooling that procurement cannot buy
A SaaS scanner raises questions about where code and findings are stored and whose law applies to them. Public cloud tenders now score providers on exactly that.
Contractor practice varies by contract
Each supplier brings its own toolchain and its own definition of done. Comparing their output requires one model, not five reports.
Systems outlive the teams that built them
A citizen-facing service commissioned years ago is still running, still in scope, and the original developers are long gone.
Baselines that require evidence, not intent
National security baselines expect documented, repeatable vulnerability management. Screenshots of a scanner do not satisfy that.
What the Frameworks Actually Require
The obligations most often cited at public bodies and the suppliers who sell to them.
public administration · risk-management measures
Public administration entities in scope must implement measures including vulnerability handling and disclosure, security in acquisition, development and maintenance, and supply-chain security.
How Whitespots helps
Every change scanned, with automatic validation, notifications and per-severity SLAs — applied to contractor-delivered code in the same database as your own.
reporting obligations
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents. The remaining obligations and the penalty regime apply from 11 December 2027.
How Whitespots helps
Every change is scanned, and each finding records when it first appeared and when it was fixed, so a report to a coordinator can go out inside the window.
IT-Grundschutz · building blocks
Documented protection requirements per system, with modules covering software development, patch and change management and vulnerability handling.
How Whitespots helps
Per-system scoping and a persistent finding history, which is the evidence layer the building blocks assume exists.
SP 800-53
Vulnerability monitoring and scanning, flaw remediation with defined timelines, and developer security testing and evaluation.
How Whitespots helps
Scanning on a defined cadence, remediation timelines tracked per severity, and developer-side testing enforced through quality gates.
Annex A, as listed in BSI's mapping table
Management of technical vulnerabilities, secure development lifecycle, secure coding, and security testing in development and acceptance.
How Whitespots helps
Each of those controls has an artefact in the platform, which is what turns a control statement into audit evidence.
security of processing
Regular testing, assessing and evaluating the effectiveness of technical measures protecting citizen data.
How Whitespots helps
Continuous testing on infrastructure the authority controls, with no processor in the chain.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. CRA dates are as published: reporting obligations from 11 September 2026, the remaining obligations and penalties from 11 December 2027. National baselines differ — confirm applicable requirements with your competent authority.
What Whitespots Gives a Public Sector Security Team
Built for systems you commissioned rather than wrote, and a network that may have no way out.
No vendor cloud to assess, because there isn't one
-
Runs on your own infrastructure Including restricted and air-gapped zones.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Leave whenever you want Exit is a database export, not a vendor negotiation.
Every contractor judged by your standard, not theirs
-
Weak deliveries stopped at handover Acceptance criteria enforced as quality gates.
-
Suppliers compared like for like Any scanner normalised, assets split by contract or supplier.
-
The record outlives the contract History retained after the supplier leaves.
Find what the documentation forgot before planning the programme
-
Forgotten and legacy hosts surface Continuous external asset and subdomain discovery.
-
Vulnerable dependencies caught early Scanned on every commit, outside CI/CD.
-
Containers covered too Base-image findings in the same model.
The audit deliverable is already written
-
Every decision traceable Per-finding trail: scanner, first seen, severity, decision, owner.
-
Remediation timelines you can show Tracked per severity.
-
Accepted risk that expires Temporary risk acceptance with an end date.
Where It Lands
What a public sector security function is usually asked to produce.
- Scenario
Procurement asks where the tool processes data
With Whitespots platformOn the authority's own infrastructure, with no external transfer.
- Scenario
A contractor hands over a finished system
With Whitespots platformAssessed against your acceptance criteria and recorded in your database.
- Scenario
An audit asks how vulnerabilities are managed
With Whitespots platformA dated record per system rather than a policy document.
- Scenario
A legacy citizen-facing service is still running
With Whitespots platformDiscovered, scanned and tracked even though nobody owns its codebase.
What Public Sector Teams Ask First
Can it run with no internet access at all?
Yes. The platform is self-hosted, sends nothing outward and needs no vulnerability feed from outside. Updates are Docker images, so they reach a closed network the same way as any other approved software. Licence activation is the only step that normally needs a connection, and for disconnected deployments we agree an offline way to do it.
Does this make us NIS2 compliant?
No product does. NIS2 obligations are organisational. What the platform covers is the technical evidence behind several of the Article 21 measures — vulnerability handling, security in development and maintenance, and supply-chain visibility — in a form an authority can read.
Most of our software is delivered by contractors. How does that work?
Their code is scanned into your findings database, split by contract or supplier and checked against your quality gates. The important consequence is that the history stays with you when the contract ends.
What about the Cyber Resilience Act?
If your organisation places products with digital elements on the EU market, the reporting obligations apply from 11 September 2026 and the remaining obligations and penalties from 11 December 2027. Continuous scanning, with a record of when each finding appeared and when it was fixed, is the practical prerequisite for reporting inside the window; the legal analysis is your regulatory function's.
Can several agencies share one instance?
Scoping, roles and reporting are per-entity in a single instance, so a shared-services arrangement is workable. Whether that fits your governance is a decision about data ownership rather than a technical limit.
Run the Security Platform on Your Own Infrastructure
Start with a free external scan of your public-facing systems, or talk to us about a deployment inside a restricted or disconnected zone.