For years, cybersecurity and privacy regulation was seen as a problem for large organisations. GDPR, in 2018, was the first sign that this was changing: all organisations that process personal data of European citizens were covered, regardless of size. But it was between 2022 and 2025 that regulatory pressure became truly democratised.
NIS2 extended cybersecurity obligations to many more sectors. DORA imposed stringent requirements on the financial sector, including IT suppliers. The EU AI Act introduced obligations for organisations using high-risk AI systems. CSRD made sustainability reporting mandatory for a growing number of companies. In Portugal, Decree-Law 125/2025 transposed NIS2 with ANACOM as the competent authority.
| Regulation | Maximum Fine | Application Condition |
|---|---|---|
| GDPR | €20M or 4% global turnover | Personal data breach, lack of legal basis |
| NIS2 | €10M or 2% global turnover | Inadequate measures, notification failure |
| DORA | Per national authority | Insufficient operational resilience |
| EU AI Act | €35M or 7% global turnover | High-risk AI systems without compliance |
Many organisations respond to regulatory pressure in the most obvious way: they hire a consultant, conduct an assessment, produce documentation, and pass an audit. A year later, the consultant is gone, the person who coordinated the process has moved to another company, and the organisation starts from scratch.
This is the problem EterShield was designed to solve. It is not a problem of lacking tools — it is a problem of knowledge that disappears. Every decision taken, every risk assessed, every policy approved should be a growing asset of the organisation.
The market has responded with solutions at the extremes: Enterprise GRC (OneTrust, IBM OpenPages) with prices of €50,000–€500,000 annually and implementations taking months; or isolated tools (Eramba, spreadsheets) with no integration or AI. The gap is clear: no affordable solution preserves organisational knowledge, integrates multiple European frameworks in Portuguese, and uses contextual AI — all in a single product for SMEs.
A vCISO (Virtual Chief Information Security Officer) externalises the function of strategic security leadership. A vCISO platform is the technological evolution: software that structures, automates, and systematises the functions of a CISO in an interface that any IT or compliance manager can operate — without being a security specialist.
EterShield is a vCISO platform, but goes further: it is an organisational security knowledge management system that collects and structures everything the organisation knows about its own security, uses AI to transform that knowledge into actionable assessments and policies, and accumulates value over time.
| Model | Description | Suitable for |
|---|---|---|
| Self-managed | Organisation uses the platform directly | SME with a dedicated IT manager |
| Assisted | Eter Growth operates the platform with the organisation | SME without internal technical capacity |
| Full vCISO | Eter Growth assumes the vCISO role | Organisations with no security resources whatsoever |
| MSP / partner | Consultancy uses EterShield for multiple clients | MSSPs, compliance consultancies |
| Framework | Scope | Controls |
|---|---|---|
| RJC (DL 125/2025) | Cybersecurity — Portuguese legal framework | 126 |
| ISO 27001:2022 | Information Security (Annex A + clauses 4–10) | 120 |
| QNRCS | National Cybersecurity (Portugal — CNCS) | 107 |
| NIST CSF 2.0 | Cybersecurity (US framework) | 106 |
| IFS Food v8 | Food Safety — retail | 96 |
| FSSC 22000 v7 | Food Safety | 74 |
| CIS Controls v8 (IG1) | Essential Security Controls | 72 |
| HIPAA Security Rule | Health Data | 65 |
| HACCP (Codex CXC 1-1969) | Food Safety | 60 |
| ISO 42001:2023 | AI Management | 57 |
| TISAX® (VDA ISA 6.0) | Information Security — automotive industry | 55 |
| Modern ITSM Practices | IT Service Management — maturity | 54 |
| FSSC 22000 v6 | Food Safety (with transition to v7) | 49 |
| ISO 26000:2010 | Social Responsibility | 40 |
| NP 4469:2019 | Social Responsibility (Portugal — IPQ) | 39 |
| SOC 2 (AICPA) | Security and Availability | 38 |
| MITRE ATT&CK | Attack Tactics and Techniques | 38 |
| EU AI Act (2024/1689) | High-Risk AI Systems | 38 |
| ISO/IEC 20000-1:2018 | IT Service Management | 37 |
| GDPR (2016/679) | Data Protection | 36 |
| ISO 22301:2019 | Business Continuity | 31 |
| ISO 9001:2015 | Quality | 30 |
| PCI DSS v4.0 | Payments | 29 |
| Cyber Resilience Act (2024/2847) | Products with Digital Elements | 29 |
| ISO 31000:2018 | Risk Management | 28 |
| ISO 56001 | Innovation Management | 28 |
| DORA (2022/2554) | Digital Resilience — financial sector | 24 |
| ISO 55001 | Asset Management | 24 |
| NIS2 (2022/2555) | Cybersecurity — EU directive | 23 |
| AMLD6 / Law 83/2017 | Anti-Money Laundering | 23 |
| FEDIAF | Nutrition and Labelling — pet food | 22 |
| ISO 23894:2023 | AI Risk Management | 22 |
| IT 01/2026 (CNCS) | Coordinated Vulnerability Disclosure | 21 |
| MITRE CTID Fraud | Fraud and Abuse | 16 |
| ISO 45001:2018 | Occupational Health and Safety | 13 |
| MyCiber | CNCS Registration and Qualification (Portugal) | 13 |
| ISO 14001:2026 | Environmental Management | 12 |
| OWASP Top 10 | Application Security | 10 |
Instead of going through 93 ISO 27001 controls manually, the user activates the AI Gap Analysis. Based on the organisation's profile and accumulated Knowledge Base, the AI automatically identifies the most likely gaps, suggests remediation priority, and proposes response texts for each control. The compliance score (0–100%) updates in real time by category and by framework.
Control exceptions with expiry: when a gap cannot be closed immediately, the organisation can record a control exception — a temporary risk acceptance with justification and an expiry date. When an approved exception expires without renewal, the platform automatically reopens the underlying gap and notifies the requester, so a stale risk acceptance never becomes permanent by omission. The expiry sweep runs daily inside the platform's in-process scheduler.
An ISO 27001 control can simultaneously satisfy NIS2 and DORA requirements. An organisation working ISO 27001 in parallel with NIS2 and DORA can have 60–70% of DORA controls already answered by the work done on ISO 27001. No duplicate questions, no redundant effort.
The policy repository generates contextualised drafts — not generic templates. Based on the organisation's profile, sector of activity, and active frameworks, the AI creates a policy that references the specific reality of the company. Full versioning with revision history, approvals, and next scheduled review.
Most risk tools stop at coloured matrices. EterShield quantifies risks financially using the FAIR model (Factor Analysis of Information Risk) with Monte Carlo simulation: 10,000 simulations produce an annual expected loss (ALE) distribution with P10, P50, and P90 percentiles in euros.
| Risk (example) | Median ALE (P50) | ALE P90 |
|---|---|---|
| Ransomware on a Windows endpoint | €78,000 | €310,000 |
| Unauthorised access to customer database | €45,000 | €180,000 |
| Critical cloud vendor failure | €25,000 | €95,000 |
FAIR quantification requires parameters that few IT managers know how to estimate. The AI proposes frequency and magnitude parameters with justification based on benchmarks from DBIR (Verizon), ENISA, and CNCS, presenting a TransparencyBadge with the complete reasoning and sources used.
For each implemented security control, EterShield automatically calculates the risk reduction in euros — allowing investments to be prioritised by financial return, not intuition. Each risk enters a formal treatment plan with milestones, owners, approval, and linkage to the compliance calendar.
A dedicated KRIs (Key Risk Indicators) page complements the risk register: each indicator carries a warning threshold, a critical threshold, a configurable direction (higher-is-worse or lower-is-worse), and either a manual or an automatic source. The automatic source L3_CONTROL_TESTS feeds directly off continuous control monitoring: the indicator is the failure rate of automated control tests (FAIL=1, PARTIAL=0.5), recalculated at the end of every hourly monitoring cycle. State transitions — into warning, into critical, or back to normal — trigger deduplicated notifications, with no noise while an indicator sits steady.
A loss events register grounds risk management in actual financial outcomes rather than opinion: events categorised as cyber, operational, fraud, legal/compliance, or reputational, with direct, indirect, and recovered loss values, root cause, and lessons learned. Optional links to an existing risk, incident, or CAPA avoid duplicate data entry; a running summary of total and per-category net loss gives management a factual baseline to calibrate FAIR parameters.
EterShield uses an adaptive TPRM questionnaire with 33 questions distributed across 5 modules, activated automatically based on the vendor's profile. An office supplies vendor answers 8 questions. A personal data processor with direct CRM access answers all 33.
| Module | Activated when | Questions |
|---|---|---|
| Information Security | Always | 8 |
| Data Protection | Vendor processes personal data | 7 |
| Business Continuity | Vendor critical to operations | 6 |
| Technical Security | Vendor with access to systems | 7 |
| Compliance | Vendor in a regulated sector | 5 |
The vendor does not need to create an account. They receive an email with a unique token link, access a secure public page, respond, and submit. The token expires after submission or deadline. All interaction is tracked and audited.
After submission, the AI analyses each response: score 0–100, red flags identified with reasoning, and overall recommendation (Approve / Conditional / Reject / Defer). The responsible party records the formal decision with a justification note — direct evidence for ISO 27001 and NIS2 auditors.
The access lifecycle tracks Joiners (new employees with a provisioning checklist), Movers (role changes with access review), and Leavers (departures with a revocation checklist). Each event generates an assigned task with a deadline and completion confirmation.
Automated periodic access reviews: a cron job schedules the review, the responsible party receives the access list, approves or revokes each entry, all recorded with a timestamp. Background checks with status and validity. Disciplinary process with PII fields encrypted in AES-256-GCM (GDPR Art. 9).
GDPR Art. 15–20 requests with entry date registration, 30-day legal countdown, status tracking (Received → Under review → Responded), and complete history for compliance demonstration.
| Module | Description |
|---|---|
| Document Control | QMS with version, revision date, approval owner, and automatic alert |
| Customer Complaints | Full cycle: reception, root cause analysis, action plan, effectiveness verification |
| Equipment Calibration | Records with calibration dates and automatic alert before recalibration deadline |
| Supplier Audits | ISO 9001 checklists by category, non-conformance records |
| SPC Control Charts | X-bar, R and p charts for statistical process monitoring |
| CAPA 8D | Structured resolution following 8 Disciplines (D1–D8) with evidence chain |
Accident records with root cause analysis and automatic ACT report; hazard register with risk assessment and controls; PPE management per employee; documented worker consultation (clause 5.4 ISO 45001 requirement).
Critical physical systems (HVAC, CCTV, alarms, sprinklers, UPS) registered as assets with preventive maintenance plans, inspection history, and imminent maintenance alerts. Direct linkage to ISO 27001 physical and environmental security controls.
Vehicle and driver records, fuel tracking, maintenance history, and document expiry calendar (inspection, insurance, service). Fuel data feeds directly into the GHG Scope 1 emissions module.
| Pillar | Standard | Content |
|---|---|---|
| GHG Emissions | ESRS E1 | Scope 1/2/3 with IPCC factors; sync from fleet records; tCO₂e dashboard |
| Social Indicators | ESRS S1 | Workforce, gender, accidents, training, absenteeism, pay gap |
| Governance | ESRS G1 | Anti-corruption policy, whistleblower (AES-256), vendor assessment, fines |
The CSRD report editorial cycle follows a Draft → Under Review → Approved → Published flow. The report is generated from records already existing on the platform — no manual re-entry of data.
All AI in EterShield is auditable. Every generated result includes a TransparencyBadge visible to the user — relevant for organisations subject to the EU AI Act.
| Field | Content |
|---|---|
| Model | Language model (version and provider identified) |
| Tokens consumed | Input + Output |
| Estimated cost | In euros (cost control) |
| Latency | Response time in ms |
| Operation | E.g.: "Gap Analysis ISO 27001 Annex A.8" |
| Reasoning | Exposed model reasoning |
| Sources | Benchmarks or frameworks referenced |
| Component | Usage |
|---|---|
| Internal AI Gateway | Security and authentication layer that intermediates all requests to the language API — ensures isolation and cost control |
| State-of-the-art language model | Gap Analysis, TPRM, Monte Carlo, EtherFlow, Cook, Sparks, response suggestions, profile prefill |
| Proprietary semantic search engine | Knowledge Base — context retrieval by entity optimised for European Portuguese |
| GRC knowledge graph | Vera's structured context injected into prompts — at no additional cost per call |
EterShield's deepest differentiator: a per-entity Knowledge Base system with contextual semantic search in four phases.
6-step wizard (identification, business, systems, regulation, team, maturity). Completeness score 0–100%. AI suggests frameworks and identifies the competent NIS2 authority (ANACOM, BdP, CNCS) based on the sector.
Any free text (meeting minutes, email, report) is processed by the AI, which extracts structured knowledge in 7 categories. The CISO approves, edits, or rejects each item before it enters the database.
Approved items are indexed and made available for semantic search optimised for European Portuguese. At each AI call, the most relevant Knowledge Base items are retrieved and injected into the prompt. The AI responds with the organisation's real context.
PDFs, DOCX, and TXT files up to 20MB are processed, fragmented into chunks, and integrated into the Knowledge Base. Existing policies, audit reports, contracts — all enrich the AI context.
The meeting ingestion pipeline: the transcript is sent via API or uploaded manually; the AI extracts risks, gaps, tasks, and decisions; items appear in an approval inbox; approved items go directly into the corresponding modules and the Knowledge Base. A 2-hour meeting produces 15 structured entries in 10 minutes.
With the proliferation of AI systems in business processes, AI risk management has become a formal requirement (EU AI Act, ISO 42001). EterShield includes a set of specialised modules for organisations that develop or use AI systems.
The ARIA Framework (Agentic Risk Intelligence Assessment) is a proprietary agentic AI risk assessment methodology structured in 7 phases, aligned with NIST AI RMF, MITRE ATLAS, MAESTRO, OWASP AIUC-1, and AIVSS. It covers 15 risk vectors: A1–A8 (agentic system risks: objective manipulation, planning hallucination, privilege escalation, context exfiltration, reasoning loop, tool abuse, irreversible impact, malicious coordination) and D Series D1–D7 (development phase threats, OWASP AI Exchange: data poisoning, backdoors, model attacks, inversion, extraction, adversarial evasion, dependency injection).
| Module | Description |
|---|---|
| ARIA Assessment | Complete 7-phase assessment — score per phase, A1–A8 risks + D Series, assessment history, and mitigation plan |
| AI Incidents | AI behavioural incidents — 7 types (hallucination, bias, prompt injection, data leak, jailbreak, misuse, unexpected behaviour); EU AI Act Art. 72 flag |
| Model Cards | EU AI Act Art. 13 technical fact sheet — intended use, training data, limitations, bias, ethics, human oversight; formal approval with record |
| Red Team Scheduler | Red teaming campaigns on AI systems — pre-defined OWASP AIUC-1 tests by category (prompt injection, jailbreak, data exfiltration) |
| EU AI Act Assessment | Compliance assessment with 33 EU AI Act obligations per AI system; risk classification (UNACCEPTABLE / HIGH / LIMITED / MINIMAL); automatic seed of applicable obligations |
| Obligation | Deadline | Trigger |
|---|---|---|
| CNCS notification (NIS2) | 24 hours | Incident with significant impact |
| DPA notification (GDPR) | 72 hours | Personal data breach |
| BdP/ANACOM notification (DORA) | 4 hours | Major ICT incident |
ANACOM routing automatically identifies the competent authority based on the sector and Decree-Law 125/2025 — eliminating manual research during a crisis.
Formal internal audit planning with audit team, agenda, findings, and non-conformance classification (Major / Minor / Observation). CAPAs with structured root cause, owner, deadline, status, and effectiveness verification. Evidence with automatic OCR — text extracted from any PDF or image, searchable and linked to the control it supports.
Automated evidence (e.g. a connector-collected screenshot or an OCR-extracted document) carries a freshness / TTL flag: once validity expires, the evidence is marked stale and the control it supports drops out of the "fresh" bucket until re-collected. A continuous coverage view shows, per framework, the split between fresh, stale, and manual evidence — giving the CISO a single screen to answer "what still needs a human this week." Google Drive Livesync links a Drive folder directly to a control: files added to that folder are picked up automatically and attached as evidence, with no manual upload step.
Dedicated portal for external auditors with controlled access to assessments, evidence, and reports — without access to platform configuration or data from other modules. Revocable access, with all queries recorded in the audit trail.
A weekly job polls RSS feeds from EU regulatory sources — the European Data Protection Board (EDPB) and the European Commission's Digital Strategy publications — and runs each new item through AI classification: which framework it affects, likely impact, and any inferable compliance deadline. Classified items land in a human review queue, where a CISO or compliance officer publishes or rejects each one before it reaches end users. Published items are pushed straight into the tenant's regulatory calendar, alongside internal read-time deadlines, so a new EDPB guideline or Commission proposal shows up next to the organisation's own compliance milestones — no manual trawling of regulatory websites.
Per-tenant regulatory impact: each update in the regulatory calendar now shows its concrete impact on the tenant — a badge with the number of active frameworks affected and the total control count, plus an expandable panel listing them (code, name, control count, active or not). Matching between an update's free-text framework name and the catalogue code is fuzzy — alphanumeric normalisation, cross-matching by code and by name, and known aliases — and codes with no match are declared as such rather than silently dropped.
The /dashboard/issues page pulls everything in the organisation that needs attention into a single per-tenant feed: open gaps, integration findings (Wazuh, EterScan, Prowler), audit findings, CAPAs, failed control tests — both manual and from continuous L3 monitoring — and unresolved incidents. Exact count cards per source, filters by source and normalised severity, drill-down into the originating module. Read-only in v1, with a 100-item-per-source cap and a clear truncation indicator. The GET /api/v1/issues route returns an {data, meta:{total, counts}} envelope.
The TIA module addresses the GDPR obligation to assess the impact of international personal-data transfers, as established in GDPR Art. 44–49, grounded in the Schrems II judgment (CJEU C-311/18) and EDPB Recommendations 01/2020 on supplementary measures.
Regulatory trigger: Following the collapse of the EU–US Data Privacy Framework (DPF) on 29 June 2026 (Trump v. Slaughter), transfers based on that adequacy decision lost their legal basis. Organisations relying on the DPF must now use an alternative mechanism — Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or Art. 49 derogations — and, in any case, conduct a formal Transfer Impact Assessment whenever there is a risk of access by authorities in third countries.
| Field / Feature | Detail |
|---|---|
| Transfer mechanism | Adequacy Decision | SCCs | BCRs | DPF | Art. 49 Derogations |
| Lifecycle | DRAFT → UNDER_REVIEW → APPROVED / REJECTED / NEEDS_REVISION; mandatory periodic review date |
| Surveillance risk | Assessment of the legal and surveillance environment of the destination country |
| Supplementary measures | Encryption, pseudonymisation, contractual clauses, technical restrictions |
| Residual risk | LOW / MEDIUM / HIGH / CRITICAL with decision and rationale |
| Optional links | Data Flow, RoPA entry, Vendor, or DPA — no data duplication |
| Access control | ADMIN / MANAGER / AUDITOR / SUPER_ADMIN; fully multi-tenant |
| Route | /dashboard/transfer-impact-assessments |
DPF Watch is a dashboard card that auto-derives — with no manual data entry — all Data Flows and DPAs in the tenant that involve a DPF-based or adequacy-based transfer to the US and have no associated approved TIA. When uncovered flows exist, the card displays a red alert listing the affected transfers, ensuring that no high-risk transfer goes undetected after a legal-framework change such as the collapse of the DPF in June 2026.
In Portugal, the obligation does not arise directly from NIS2. It arises from the Cybersecurity Legal Framework (RJC) — Decree-Law 125/2025 of 4 December, which transposes Directive (EU) 2022/2555 into Portuguese law. This is the instrument the competent authority enforces, and the one against which an organisation is assessed. Anyone who has already worked through NIS2 has part of the road behind them, not all of it: the RJC adds obligations of its own, deadlines of its own, and a registration cycle the directive never describes.
EterShield treats the RJC as a first-class framework, not as an alias for NIS2. It carries 126 control objectives derived from the statute — governance duties (art. 25), cybersecurity risk management (arts. 26 to 29) and the minimum measures of art. 27 read together with Annex III of Regulation 756/2026 — applicable to the essential and important entities in the critical and highly critical sectors listed in Annexes I and II to the decree-law.
Meeting the technical measures is not enough: the entity must exist in the regulator's eyes. MyCiber is the electronic platform of the Portuguese National Cybersecurity Centre (CNCS) where that cycle takes place, and EterShield tracks it with 13 control objectives under Chapter II (arts. 6 to 19) of Regulation 756/2026 and arts. 8 and 35 of the RJC: initial self-identification, follow-up of the qualification, definitive registration, permanent updating of the data, and notification of the security officer.
| Framework | Legal basis | Control objectives |
|---|---|---|
| RJC | Decree-Law 125/2025 of 4 December (transposes Directive (EU) 2022/2555) | 126 |
| MyCiber | Regulation 756/2026, Ch. II (arts. 6–19); RJC arts. 8 and 35 | 13 |
| NIS2 | Directive (EU) 2022/2555 | 23 |
| QNRCS | National Cybersecurity Reference Framework (CNCS) | 107 |
The four coexist for a practical reason: cross-mapping between frameworks means a piece of evidence uploaded once answers the RJC control, the NIS2 control and the QNRCS control at the same time. The work is done once; the demonstration is made three times.
Technical Instruction 01/2026 of the Portuguese National Cybersecurity Centre, approved on 24 June 2026 under art. 20(1)(h) and art. 38 of the RJC, sets the requirements for identifying vulnerabilities and disclosing them in a coordinated manner. It defines what is expected of each of the three parties: whoever identifies the vulnerability, the manufacturer or supplier of the vulnerable technology, and the CNCS as coordinator.
EterShield has a dedicated module with 21 control objectives covering the full cycle: publication of the disclosure policy and point of contact, intake and triage of reports, response and remediation deadlines, communication with the reporter, and an auditable record of every step — which is, in practice, what you present if compliance is ever questioned.
A compliance platform holds what an organisation keeps most closely about its own security posture: what remains undone, where the gaps are, which incidents occurred. The client's legitimate question is not whether the platform is secure — it is how they verify that it is. What follows is the answer in verifiable terms.
Isolation by organisation is enforced on every data operation, not as a coding convention but as a condition of each query — there is no path by which one organisation's data surfaces in another. On top of that, granular access profiles (RBAC) per entity and per module let an organisation with several companies or business units give each team exactly what belongs to it.
Since 26 August 2026, accounts with administrative privileges require a second factor — an authenticator application (TOTP) or an email code as the alternative method. It is neither optional nor deferrable by client configuration: an administrative account without a second factor can no longer complete sign-in.
There are moments when the Eter Growth team needs to enter a client's organisation to diagnose a problem. That access is not a standing administrator privilege: it is a temporary grant, with a recorded reason, a defined term and an automatic end. While it lasts, the client sees that we are there — a persistent notice in the interface states that the session is running under a grant and how much time remains. Every visit is recorded to the second in the organisation's own audit log, which they can consult without asking us for anything.
| Guarantee | How it is delivered |
|---|---|
| Audit log | Sensitive actions recorded with integrity chaining — an entry cannot be altered or removed without breaking the chain |
| Authentication | Credentials with second factor, Google, or the organisation's federated identity (OIDC / SAML 2.0) |
| Encryption | In transit and at rest; encrypted daily backups |
| Data location | Own dedicated server in the European Union — no sub-processor outside the EEA handles compliance data |
| Artificial intelligence | Requests pass through our own intermediary service, with usage logging; content is not used to train models |
| Exit | Full data export at any time, in JSON, CSV and PDF — no request, no waiting period, no retention used as commercial leverage |
That last line deserves emphasis. The ability to leave is part of the offer: a compliance platform that holds a client's data hostage becomes, itself, a continuity risk to record in that client's risk register.
| Criterion | Eramba | EterShield |
|---|---|---|
| Model | Self-hosted (free) or SaaS (€800+/month) | Managed SaaS — immediate access |
| Installation | 4–8 hours for self-hosted | Zero — trial in 5 minutes |
| Native AI | None | Contextual AI with RAG per entity |
| NIS2 / DORA | Manual (customisation) | Native PT-PT frameworks |
| TPRM | Basic module | Adaptive questionnaire + AI + public portal |
| HR Security | None | JML, Access Reviews, Disciplinary (AES-256) |
| ISO 9001 / ISO 45001 | None | Complete modules |
| ESG / CSRD | None | Native ESRS E1/S1/G1 |
| Monte Carlo / FAIR | None | 10,000 simulations, ALE in euros |
| Language | English | Native PT-PT + EN |
| Data | Depends on client's deployment | EU always — own dedicated server |
| Criterion | OneTrust | EterShield |
|---|---|---|
| Target audience | Large companies (500+ employees) with a dedicated DPO | SMEs and mid-sized companies (10–500 employees) |
| Price | €50,000 – €200,000+/year | From €209/month (PT) |
| Implementation | 3–6 months with consultants | Days (trial → production) |
| GDPR / RoPA | Market reference | Complete module |
| NIS2 / DORA | Configurable with effort | Native, PT-PT |
| Generative AI | Limited to some modules | Integrated across the whole platform |
| Data in the EU | Configurable | Always |
| ISO 9001 / OH&S | None | Native modules |
| ESG / CSRD | Enterprise only | Included in Starter |
OneTrust is irreplaceable for multinationals operating across multiple jurisdictions. For the Portuguese SME market, the cost is prohibitive and the complexity excessive.
| Criterion | Drata / Vanta | EterShield |
|---|---|---|
| Target market | USA / UK, SaaS startups | Europe (PT, ES, EU), traditional SMEs |
| Frameworks | SOC 2, ISO 27001, HIPAA, PCI DSS | 38 frameworks incl. NIS2, DORA, GDPR, ISO 9001, ISO 45001, CSRD, NIST CSF 2.0, CIS Controls v8, HIPAA Security Rule, Cyber Resilience Act, QNRCS, HACCP, NP 4469, ISO 55001, ISO 56001 |
| GDPR / NIS2 / DORA | No real support | Native |
| NIDS / Network Alerts | None | Suricata NIDS; CRITICAL → automatic Incident |
| Integrations | 100+ (GitHub, AWS, GCP, Slack) | Wazuh, GLPI, EterScan, Gophish, webhooks |
| AI | Basic automation | Contextual AI with RAG per entity |
| Price | $1,000 – $5,000+/month | From €209/month (PT) |
| Data | USA | EU |
| Language | English | PT-PT + EN |
Drata/Vanta are excellent for English-speaking startups focused on SOC 2. For a European SME that needs NIS2, DORA, ISO 27001, and ISO 9001 in Portuguese with data in the EU — EterShield is the natural choice.
| Criterion | Cynomi | EterShield |
|---|---|---|
| Sales model | Exclusively MSPs (B2B2B) | Direct to SME + MSP/vCISO channel |
| Price | Custom, ~$500–$2,000+/month | From €209/month (PT) |
| AI | AI CISO (automatic reports) | Generative AI + RAG per entity |
| Frameworks | ~8 (ISO 27001, SOC 2, NIS2, HIPAA) | 38 frameworks |
| OH&S / Fleet / Facilities | None | Integrated modules |
| NIDS / Network Alerts | None | Suricata NIDS; CRITICAL → automatic Incident |
| HR Security | None | JML, disciplinary, Access Reviews, DSR |
| Audit Trail → SIEM | None | Automatic Wazuh forward |
| Whistleblower | None | Native (AES-256-GCM) |
| Knowledge Base / FTS | None | Complete system per entity |
| PT market | None | Native PT-PT + CNCS + ANACOM routing |
| Eramba SaaS | OneTrust | Drata/Vanta | Cynomi | EterShield | |
|---|---|---|---|---|---|
| Annual SME cost | €9,600+ | €50,000+ | €12,000–60,000 | €6,000–24,000 | €2,508–8,388 ¹ |
| Integrated IMS | ✗ | ✗ | ✗ | ✗ | ✓ |
| Native NIS2/DORA PT | ✗ | ✗ | ✗ | Partial | ✓ |
| Contextual AI (RAG) | ✗ | Partial | Partial | Partial | ✓ |
| HR Security | ✗ | Partial | ✗ | ✗ | ✓ ² |
| ISO 9001 / Quality | ✗ | ✗ | ✗ | ✗ | ✓ ² |
| ESG / CSRD | ✗ | Enterprise | ✗ | ✗ | ✓ ² |
| NetworkAlerts (NIDS) | ✗ | ✗ | ✗ | ✗ | ✓ ² |
| Monte Carlo / FAIR | ✗ | ✗ | ✗ | ✗ | ✓ |
| Whistleblower | ✗ | Enterprise | ✗ | ✗ | ✓ |
| Portuguese language | ✗ | ✗ | ✗ | ✗ | ✓ |
| Guaranteed EU data | Depends | Configurable | ✗ | Partial | ✓ |
| Solution | Year 1 | Years 2–5 (average) | 5-year Total |
|---|---|---|---|
| OneTrust | €60,000 | €55,000/year | €280,000+ |
| Drata (Professional) | €20,000 | €18,000/year | €92,000 |
| Cynomi (MSP) | €15,000 | €12,000/year | €63,000 |
| Eramba SaaS | €10,000 | €9,600/year | €48,400 |
| EterShield (Starter + Operations Pack) | €7,400 | €6,800/year | €34,600 |
| EterShield (Starter, GRC core) | €5,500 | €5,000/year | €25,500 |
Starter + Operations Pack = €419 + €149/month PT — all operational modules without upgrading to Professional.
EterShield is SaaS — no software installation, no servers to configure. A modern browser (Chrome 120+, Firefox 120+, Safari 17+), an internet connection, and an email address.
| Feature | Prerequisite |
|---|---|
| SSO SAML 2.0 | Configuration on the IdP (Okta, Entra ID, Google Workspace) |
| Wazuh SIEM Integration | Network connectivity between the Wazuh Manager and EterShield infrastructure |
| GLPI Integration | GLPI API active with access token |
| API EtherFlow | API key generated on the platform; accessible endpoint |
| Plan | PT Price | Users | Entities | AI / month |
|---|---|---|---|---|
| Trial | Free (14 days) | 5 | 1 | 20 |
| Lite | €209/month · €2,090/year | 3 | 1 | — |
| Starter | €419/month · €4,190/year | 20 | 1 | 200 |
| Professional | €699/month · €6,990/year | 50 | 3 | 500 |
| Enterprise | Negotiated | Unlimited | Unlimited | Unlimited |
PT prices with a 30% discount for organisations headquartered in Portugal (valid NIF).
| Priority | Feature | Impact |
|---|---|---|
| High | Maturity Benchmarks by sector | Anonymous comparison with organisations in the same sector |
| High | DORA RTS for financial entities | DORA report templates for BdP |
| Medium | OpenCTI Integration | Sector-contextualised threat intelligence |
| Medium | Multi-language (ES, FR) | Expansion to Iberian and Francophone markets |
| Future | Native Mobile App (iOS / Android) | Push notifications, full mobile access |
| Future | Autonomous AI Agent | Agent that proposes and executes remediations with human approval |
Situation: a logistics company with 120 employees needs ISO 27001 certification as a requirement from a customer in the automotive sector. No CISO. The IT Manager has other responsibilities.
Situation: a health clinic (NIS2 PT) detects ransomware on 3 servers. It is 14:30 on a Friday.
Situation: a cybersecurity consultancy manages 8 SME clients with different maturity levels and frameworks.
Situation: an asset management company with 200 employees, subject to DORA, in a remediation process.
Security compliance has moved from a peripheral concern to a strategic factor in competitiveness. Organisations that build real security management capability — not just pass audits — gain access to larger clients, public contracts, cyber insurance with lower premiums, and partnerships that require certifications.
EterShield was built for a specific reality: the European SME facing growing regulation without resources for an internal CISO, without budget for enterprise platforms, and without patience for tools that don't speak their language.
| Term | Definition |
|---|---|
| vCISO | Virtual Chief Information Security Officer — the CISO function outsourced to a partner or platform |
| GRC | Governance, Risk and Compliance — set of processes for managing governance, risk, and compliance |
| IMS | Integrated Management System — a management system that combines multiple standards (ISO 27001, ISO 9001, ISO 45001…) |
| RAG | Retrieval-Augmented Generation — AI technique that injects relevant context into prompts for precise and contextualised responses |
| FAIR | Factor Analysis of Information Risk — financial quantification methodology for cyber risk |
| ALE | Annualised Loss Expectancy — expected annual financial loss, the output of the FAIR/Monte Carlo model |
| TPRM | Third-Party Risk Management — management of risks associated with vendors and third parties |
| JML | Joiners, Movers, Leavers — the access lifecycle of employees |
| DSR | Data Subject Request — a request by a data subject under GDPR (access, rectification, erasure…) |
| CAPA | Corrective and Preventive Action — plan of corrective and preventive actions for non-conformances |
| NIS2 | Network and Information Security Directive 2 — European cybersecurity directive (2022/2555) |
| DORA | Digital Operational Resilience Act — European digital resilience regulation for the financial sector (2022/2554) |
| CSRD | Corporate Sustainability Reporting Directive — European sustainability reporting directive (2022/2464) |
| ESRS | European Sustainability Reporting Standards — CSRD sustainability reporting standards |
| CNCS | Centro Nacional de Cibersegurança (Portuguese National Cybersecurity Centre) — national cybersecurity authority in Portugal |
| CNPD | Comissão Nacional de Protecção de Dados (Portuguese Data Protection Authority, DPA) — data protection authority in Portugal |
| ANACOM | Autoridade Nacional de Comunicações (Portuguese National Communications Authority) — NIS2 competent authority for specific sectors in Portugal |
| MONARC | Method for an Optimised aNAlysis of Risks — ISO 27005 threat catalogue under CC0 licence |
| AI Sparks | Intelligent form prefill — automatic AI content suggestion based on gap or entity context |
| SPC | Statistical Process Control — statistical process control (ISO 9001) |
| RBAC | Role-Based Access Control — access control by user role |
| RoPA | Record of Processing Activities — Register of Processing Activities (GDPR Article 30) |
| BIA | Business Impact Analysis — business impact analysis (ISO 22301) |
| ARIA | Agentic Risk Intelligence Assessment — proprietary agentic AI risk assessment methodology in 7 phases |
| AIVSS | AI Vulnerability Scoring System — vulnerability scoring system for AI systems, analogous to CVSS |
| TIA | Transfer Impact Assessment — formal assessment of the impact of international personal-data transfers required by GDPR Art. 44–49 and Schrems II |
| DPF | Data Privacy Framework — EU–US adequacy decision (invalidated 29 June 2026, Trump v. Slaughter); replaced by SCCs, BCRs, or Art. 49 derogations |
| DPA | Data Processing Agreement — contract required under GDPR for sub-processors handling personal data on behalf of a controller |
| SCCs | Standard Contractual Clauses — pre-approved GDPR transfer mechanism for transfers to countries without an adequacy decision |