LiveAI-powered GRC platform · free to start

Enterprise-grade compliance, built by a CISO for teams that don't have one.

Audit-ready across 17 frameworks including NIS2, GDPR, ISO 27001 and DORA, with the assessments, controls, policies and reporting your auditor expects, all in one platform. Free baseline in 15 minutes.

No credit card15-minute setup17 frameworksEU-hosted data

Built for SMEs. Scales to multinationals across the EU, UK and worldwide.

Meet the founder
Dr Matt Lemon presenting Defending Against AI-Powered Attacks on stage at Black HatOn stage at Black Hat

Dr Matt Lemon

Founder & CISO

Connect on LinkedIn

I didn't design ShieldIQ from a feature list. I built it from 25 years in the CISO chair, steering organisations through live ransomware attacks, EU data-sovereignty fights, and regulators at the door.

But the idea came from the ground up. Working hands-on with SMEs, I kept seeing the same thing: the tooling built for big enterprises didn't fit them, and the gaps left them exposed. ShieldIQ grew directly out of that, shaped by the real problems those teams face, not built in a lab.

Everything else I've learned is in it too. I hold a PhD in Digital Security & Forensics, wrote the cybersecurity books others now train from (Applied Cybersecurity and Applied AI Security), founded the Global CISO Council in Ireland, and speak regularly at industry conferences. Today I also teach the next generation as an Associate Professor of Cybersecurity.

ShieldIQ is all of it: every framework, every hard lesson, every 3am incident, turned into software a smaller team can actually run. Enterprise-grade security leadership, without the enterprise price tag.

PhD, Digital Security & Forensics25+ years as a CISOAuthor, Applied Cybersecurity & Applied AI SecurityFounding President, Global CISO Council IrelandAssociate Professor of CybersecurityInternational speaker
Compliance dashboard
ShieldIQ compliance dashboard: live posture across every frameworkShieldIQ risk register: likelihood by impact heat mapShieldIQ control library: cross-framework controls with status and evidenceShieldIQ workspace admin: team, security policy and audit trail

Trusted by teams at

Permanent TSB
Huawei
Gas Networks Ireland
CCT College Dublin
Client logo
Client logo

Consulting Services

Prefer hands-on support?

The platform does the heavy lifting, but sometimes you want an expert alongside you. ShieldIQ's Dublin-based consultants work as an extension of your team, from a one-off assessment to an ongoing programme, led by a CISO who has been in your seat.

Virtual CISO
Fractional security leadership, board reporting and strategy.
GRC programmes
Stand up NIS2, ISO 27001, GDPR and DORA from scratch.
Strategic planning
Roadmaps, risk appetite and budgets you can defend.
Incident response
Preparation, tabletop exercises and support when it counts.
17
Compliance frameworks
21
Integrated modules
15 min
To your first baseline
72·24·4h
GDPR · NIS2 · DORA, automated
The problem

Regulations keep multiplying. Your headcount doesn't.

Each new regulation brings its own deadlines, evidence requirements and penalties. But you don't have a security team, and consultants charge a fortune for a report that's out of date the day they walk out the door.

Where the deadlines stand

In force now

GDPR · DORA · PCI DSS 4.0

Already applies. Penalties are live.

Arriving

NIS2 · EU AI Act (high-risk)

Landing now, hard deadlines through 2026.

On the horizon

EU AI Act (2027) · more to come

Plan ahead so it isn't a scramble.

ISO 27001, NIST CSF, SOC 2 and Cyber Essentials are voluntary standards, adopt them when you're ready.

ShieldIQ gives you a way to get compliant, and stay compliant, without either.

How it works

Audit-ready in three steps

No setup calls, no professional services. Start in minutes.

01

Sign up & pick a framework

Create a free account and choose from your supported frameworks. No credit card required.

02

Run your first assessment

Guided questions, AI scores every category, identifies gaps and produces a prioritised remediation plan in around 15 minutes.

03

Manage & stay compliant

Track controls, manage risks, store policies, handle incidents and produce board-ready reports from one dashboard.

Trusted by working teams

Real users, real results.

Having a CISO with 25 years of experience available without the full-time cost is exactly what we needed. ShieldIQ gave us a clear picture of our compliance posture within the first week.
Operations Director
Irish Technology SME
NIS2 compliance felt impossible until we started using ShieldIQ. The gap analysis and AI policy drafting saved us weeks of work.
IT Manager
Dublin Financial Services Firm

21 Modules · 4 outcomes

Everything you need. Nothing you don't.

Twenty-one integrated modules grouped into the four outcomes that matter: assess, govern, manage risk, respond.

01

Assess & Benchmark

2 modules
AssessmentsDashboard
02

Govern & Prove

5 modules
ControlsPoliciesActivity FeedTeam ManagementBulk Import
03

Manage Risk

6 modules
Risk RegisterVendor ManagementAsset InventoryAI Systems RegisterActions BoardCompliance Calendar
04

Respond & Improve

8 modules
Incident ManagementCRA Vuln & Incident ReportingFRIA / Human-ImpactNetwork ScannerPen TestsROPA (Art. 30)DPIA (Art. 35)Security Controls

AI-Powered

Your AI compliance analyst, built in.

ShieldIQ's AI reads your assessment in your business context, drafts policies you can edit, judges whether your evidence actually proves a control, finds the gaps, and drafts your incident notifications. It's the expertise of a GRC consultant, without the day rate. All on one shared credit pool, no surprise bills.

AI Assessment Analysis

Each category individually analysed with full business context: 2 to 3 paragraphs per category, bundled into every assessment.

AI Policy Drafter

Pick a policy type, scope, and framework. AI drafts a tailored policy you can review, edit and save as a versioned draft.

AI Evidence Judge

Upload a file and get a verdict (satisfies, partial, or does not satisfy) with reasoning and improvement suggestions.

AI Incident Notifications

Automatically drafts regulator-ready notifications with correct deadlines for GDPR, NIS2, and DORA incidents.

AI Gap Analysis

Finds gaps across your controls and frameworks, prioritises remediation, and keeps you continuously audit-ready.

Pricing

Start for free. Scale when ready.

No credit card required to get started. Your first assessment takes around 15 minutes.

The NIST Cybersecurity Framework (CSF 2.0) is free to assess. All other frameworks are available on a paid plan.

Starter

Free

Everything you need to run your first assessment and understand your posture.

  • NIST CSF 2.0 assessment (free)
  • Controls & risk register
  • Basic policy library
  • 1 user
  • AI assessment analysis included
Start free
Most popular

Professional

See plans

Unlocks all 17 frameworks (NIST CSF plus the other 16), unlimited users, full AI credit pool, and priority support.

  • All 17 frameworks (NIST CSF free tier plus 16 more)
  • All 21 modules
  • 5 AI features (shared credit pool)
  • Unlimited users
  • Auditor access (time-boxed)
  • Priority support
View all plans & pricing

FAQ

Frequently asked questions

What is a GRC platform?

GRC stands for governance, risk and compliance. A GRC platform brings those three together in one place, so instead of juggling spreadsheets for assessments, controls, policies, risks, vendors and incidents, you run them from a single system that stays audit-ready. ShieldIQ is a GRC platform built specifically for smaller teams.

Do I need to comply with NIS2?

If you operate in the EU in a sector NIS2 covers, such as energy, health, digital infrastructure, transport, manufacturing and many others, and you are a medium or large entity, you very likely fall in scope. Even where you are not directly regulated, your customers and supply chain increasingly expect NIS2-level security. ShieldIQ helps you assess your obligations and close the gaps.

How long does a compliance assessment take?

Your first baseline takes about 15 minutes. You work through a guided assessment, and ShieldIQ scores you against the framework, shows your gaps and prioritises what to fix first. A full programme takes longer, but you get a clear picture of where you stand on day one.

What frameworks does ShieldIQ support?

Seventeen, including NIS2, GDPR, ISO 27001, DORA, the EU AI Act, NIST CSF 2.0, SOC 2, PCI DSS and Cyber Essentials. NIST CSF 2.0 is free to assess and the rest are on a paid plan. Every framework has scoring, gap analysis and prioritised remediation built in.

Is ShieldIQ suitable for SMEs without a dedicated security team?

Yes, that is exactly who it is built for. Most small and mid-sized businesses cannot justify a full-time compliance team, so ShieldIQ gives you the assessments, controls, policies and reporting a security lead would produce, guided by AI and structured so a non-specialist can run it. If you want an expert alongside you, our consultants can step in too.

How much does ShieldIQ cost?

You can start for free, with no card required. The free tier includes a full NIST CSF 2.0 assessment, controls and a risk register. Unlocking all 17 frameworks, all 21 modules and unlimited users is a paid plan. See the pricing page for current plans.

Where is my data stored?

Your data is hosted in the EU. Security and privacy are the whole point of the product, so strong access controls, encryption and audit logging are applied by default.

Can I get hands-on help, not just the software?

Yes. Alongside the platform, our Dublin-based consultants work as an extension of your team, from a one-off assessment to an ongoing programme, covering virtual CISO, GRC programmes, strategic planning and incident response. The software and the human expertise are designed to work together.

See your compliance posture in 15 minutes, and leave with a prioritised plan.

Free to start. No credit card. No setup calls. Run your first assessment across any supported framework.