LAUNCHING SOON · NIS2 · DORA · ISO 27001

EU compliance tools,
handcrafted for your business

Domain & brand monitoring and Entra ID access reviews — built for EU SMBs who need NIS2, DORA, and ISO 27001 compliance without the enterprise price tag.

30-day free trial · No charge during trial · EU data residency

Two shields, one mission

Each shield protects a different angle of your compliance posture

🌐
DomainShieldCOMING SOON
Domain & brand monitoring

Know when someone impersonates your brand online

DomainShield continuously scans for typosquats, homoglyphs, and lookalike domains that could be used for phishing attacks against your organization. Daily automated monitoring with instant email alerts and one-click compliance reports mapped to ISO 27001 and NIS2.

Daily automated brand & domain scans
Typosquat, homoglyph & keyword detection
Threat risk scoring (DNS, SSL, content)
Instant email alerts
One-click PDF compliance reports
Change tracking & audit trail
€49/month
Flat monthly price, all features included
ISO 27001 A.5.7NIS2 Art.21DORA Art.9
🔐
AccessShieldCOMING SOON
Entra ID access reviews & group audit

Know who has access, who approved it, and when it changed

AccessShield connects to your Microsoft 365 tenant and takes daily snapshots of all Entra ID group memberships. Historical audit trail for 12 months, automated access review campaigns, and compliance reports — at a fraction of the cost of Entra ID Governance P2.

Daily Entra ID group snapshots (all types)
12-month historical audit trail
Point-in-time membership queries
Automated access review campaigns
Group metadata & hygiene dashboard
Auto-remediation via Graph API (optional)
€3/user/monthmin. €99/month
All features included · 80% cheaper than Entra P2 + Governance
ISO 27001 A.5.18ISO 27001 A.8.2NIS2 Art.21(2)(i)DORA Art.9(4)(c)
🔒
✉️
🔑
🏢
🚨
More shields are in the workshop
CertShield · MailShield · LeakShield · VendorShield · IncidentShield
Get notified →

Built for EU compliance frameworks

Every report maps directly to the controls your auditor needs to see

ISO 27001:2022
A.5.7 — Threat intelligence
A.5.18 — Access rights
A.8.2 — Privileged access rights
A.5.17 — Authentication information
NIS2 Directive
Art.21 — Cybersecurity risk management
Art.21(2)(d) — Supply chain security
Art.21(2)(e) — Network security
Art.21(2)(i) — Access control policies
DORA
Art.9 — ICT risk management
Art.9(4)(c) — Access management
Art.19 — Incident reporting
Art.28-30 — Third party risk

Transparent pricing, no surprises

Every shield includes all features. No tiers, no feature gating.

🌐 DomainShield
€49/mo
Flat price, all features
🔐 AccessShield
€3/user/mo
minimum €99/month
80% cheaper than Entra P2

Get notified at launch

Be the first to know when ShieldShed launches. Early subscribers get priority access and a free 30-day trial.

Book a demo call

Want to see ShieldShed in action before launch? Book a 15-minute call and we'll walk you through both products with your compliance requirements in mind.

📅
15-minute product walkthrough
We'll cover your compliance needs, show both shields, and answer any questions about NIS2, ISO 27001, or DORA requirements.
Pick a time slot →
Powered by Calendly · Free, no commitment
🇪🇺
EU data residency
Azure West Europe
🔒
GDPR compliant
By design, not afterthought
5-minute setup
No implementation needed
💳
30-day free trial
Cancel anytime during trial

Frequently asked questions

NIS2 (Network and Information Systems Directive 2) is an EU cybersecurity regulation that came into effect in October 2024. It applies to essential and important entities across sectors including IT, finance, healthcare, energy, and digital infrastructure. Companies with 50+ employees or €10M+ annual turnover in these sectors are generally covered. NIS2 requires organizations to implement cybersecurity risk management measures, including access control policies and threat intelligence monitoring — exactly what ShieldShed helps you achieve.

ISO 27001 Annex A.5.7 requires organizations to collect and analyze threat intelligence relevant to their information security. Monitoring for lookalike domains and brand impersonation attempts directly addresses this control. DomainShield provides automated daily scans with audit-ready PDF reports that map findings to ISO 27001, NIS2 Article 21, and DORA Article 9 — giving your auditor exactly the evidence they need.

Access reviews are periodic evaluations of who has access to what in your organization's Microsoft 365 environment. ISO 27001 A.5.18 and NIS2 Art.21(2)(i) require documented, periodic review of access rights. Without a tool, most companies rely on manual Excel exports — which lack historical audit trails. AccessShield automates this process by taking daily snapshots of all Entra ID groups, tracking changes, and enabling group owners to review and approve memberships through a simple email-based workflow.

Microsoft Entra ID P2 costs approximately €8.40 per user per month and includes access reviews as part of a broader identity suite (PIM, Identity Protection, etc.). For a 200-user company, that's €1,680/month. AccessShield focuses specifically on the group audit trail and access review functionality at €3/user/month (€600/month for 200 users) — an 80% cost saving. DomainShield addresses a completely different need (external threat monitoring) that Entra doesn't cover at all.

All ShieldShed data is stored exclusively in the European Union, in Microsoft Azure's West Europe region (Netherlands). No data is transferred outside the EU. We are GDPR-compliant by design, and our infrastructure meets the data residency requirements of NIS2, DORA, and ISO 27001.

Yes. We offer a 30-day free trial for all shields. During the trial you get full access to all features, including compliance reports. You can cancel anytime from your account dashboard at no cost. If you don't cancel before the trial ends, your subscription will automatically convert to a paid plan.

Absolutely. ShieldShed is built specifically for organizations preparing for or maintaining ISO 27001 certification. DomainShield covers A.5.7 (Threat intelligence) and AccessShield covers A.5.18 (Access rights) and A.8.2 (Privileged access rights). Both products generate one-click PDF reports that map directly to these controls — ready to hand to your auditor.

DORA (Digital Operational Resilience Act) is an EU regulation for the financial sector that took effect in January 2025. Article 9 requires ICT risk management measures including access control and threat monitoring. DomainShield addresses Article 9's threat intelligence requirements, while AccessShield addresses the access management and audit trail requirements. Both generate reports with explicit DORA control mapping.

Ready to simplify your EU compliance?

Start with a 30-day free trial · No commitment required