Skip to content

Ceeyu

A Belgian attack surface management and third-party risk platform combining continuous external scanning with compliance questionnaires, built around EU NIS2 and DORA requirements.

Visit Website ↗ + Add to Compare
53/100Incremental Innovator

Overview

Ceeyu is a Belgian attack surface management and third-party cyber risk platform that combines continuous, automated external scanning with digital security questionnaires into a single third-party risk management (TPRM) workflow. The platform runs nine categories of external attack-surface analysis against an organization’s own digital footprint and against its suppliers’ footprints, then layers in questionnaire-based assessments so risk teams get both an outside-in technical view and a compliance-style self-attestation view of vendor risk in one place.

Founded in 2020 by cybersecurity specialist Jimmy Pommerenke and based in Bonheiden, Belgium, Ceeyu built its go-to-market around the EU regulatory wave — NIS2 and DORA both require organizations to actively manage supply-chain and third-party cyber risk, and Ceeyu positions its platform explicitly as a NIS2/DORA risk-identification tool. Named customers include the Port of Antwerp-Bruges and Belgium’s Ministry of Foreign Affairs, alongside logistics and food-industry accounts, giving it credible public-sector and critical-infrastructure reference customers for a company of its size.

Ceeyu is a regional player competing in a category with much larger, better-funded global vendors (SecurityScorecard, BitSight, UpGuard), and its roughly $1.9 million in total funding is modest by that standard. Its differentiation is regulatory specificity — being purpose-built around NIS2 and DORA compliance workflows for European organizations — rather than broader platform scale, which makes it most relevant to EU-based risk and compliance teams navigating those specific mandates.

Innovation Matrix Assessment

Innovation Velocity 5/10

The platform already runs nine distinct external attack-surface analysis categories alongside a questionnaire engine, a reasonably broad feature set for a five-year-old, ~13-person company.

Operational Value 6/10

Named reference customers including the Port of Antwerp-Bruges and Belgium's Ministry of Foreign Affairs indicate real production deployment at critical-infrastructure and government scale, not just pilot usage.

Market Momentum 5/10

Ceeyu closed a EUR/USD ~$1.1M growth round in September 2024 (total funding ~$1.9M) and continues to add public-sector and logistics customers, modest but real traction for its size and market.

Category Disruption 5/10

Combining automated outside-in scanning with questionnaire-based TPRM in one workflow, purpose-built around NIS2/DORA obligations, is a meaningful but incremental combination rather than a wholly new approach to third-party risk management.

Real-World Efficacy 5/10

Public-sector and critical-infrastructure reference customers are a credible signal of real-world usage, though no independent third-party benchmark of Ceeyu's scanning accuracy or coverage was found.

Enduring Relevance 6/10

NIS2 and DORA both impose binding third-party and supply-chain risk management obligations on a large population of EU organizations starting in the mid-2020s, making a compliance-purpose-built TPRM tool directly relevant to that buyer base.

Why CISOs Should Care

EU-regulated organizations facing NIS2 or DORA supply-chain risk requirements get a tool built specifically around those obligations rather than a generic global TPRM platform retrofitted with EU compliance mapping.

What Makes It Different

Ceeyu pairs automated external attack-surface scanning across nine categories with built-in questionnaire workflows and explicit NIS2/DORA framing, rather than treating EU regulatory mapping as an add-on to a US-built platform.

The Matrix Verdict

53/100 — INCREMENTAL INNOVATOR

A small but credible European TPRM/ASM vendor with genuine public-sector customers and clear regulatory timing; it competes against much larger global players on feature depth, but wins on EU compliance specificity.

Editorial Note: Claims vs. Verified Findings

Customer names (Port of Antwerp-Bruges, Belgian Ministry of Foreign Affairs) and funding figures are drawn from Ceeyu's own press materials and corroborated by third-party funding trackers (Crunchbase, PitchBook, CB Insights); no independent audit of the platform's scanning accuracy or the completeness of its nine attack-surface checks was found.

Sources