71%
Overall EU Compliance Score
Your site passes most automated checks. Two items need attention — see findings below.
✅ Pass — minor issues found
📊 Score Summary
71%
Overall score
5/7
Checks passed
2
Issues found
30
Days of history
🔍 Detailed Check Results
-
✓
HTTPS
TLS 1.3 active, valid certificate (Let's Encrypt), expires Mar 12, 2026
-
⚠
HSTS header
HTTPS works but Strict-Transport-Security header is missing
→ Add:
Strict-Transport-Security: max-age=31536000; includeSubDomains (improves security score for GDPR Art. 32)
-
✓
Cookie consent
Cookie consent banner detected (Shopify's default consent banner — verifies consent logic independently)
-
✓
Forms & privacy link
5 forms detected, privacy policy linked in footer
-
✓
Legal pages
Privacy policy and terms of service found via common paths
-
⚠
CSP header
Content-Security-Policy header not set — risk of XSS and data exfiltration
→ Implement CSP with
default-src 'self' as baseline (NIS2 Art. 21 — basic security measures)
-
✓
DORA resilience
HTTPS + valid certificate — meets basic DORA ICT security requirements
📋 Recommended Fixes (priority order)
- Add HSTS header — protects against SSL stripping. Add
Strict-Transport-Security to your server config or Shopify theme.liquid header.
- Add Content-Security-Policy header — limits which scripts can run on your site. Start with a restrictive policy and relax as needed.
- Review cookie categories — ensure analytics/tracking cookies are correctly categorized as "optional" in your consent manager.
📈 30-Day Compliance History
Score trend over the last 30 days:
Dec 18 Jan 15
📝 Dec 20–22: Score dropped due to expired SSL cert (renewed Dec 23). Daily monitoring caught it the same day — no auditor ever saw the gap.
📎 Attachments
This report includes the following documents (available for download with Pro):
- ✅ Compliance Score Badge — embeddable badge showing your 71% score, click-through to verified record
- ✅ GDPR Data Processing Agreement (Art. 28) — controller → processor DPA with EU hosting clauses
- ✅ NIS2 Vendor Compliance Clause Set — audit-trail, incident-reporting and subcontractor clauses
- ✅ EAA Accessibility Statement — compliant with European Accessibility Act requirements
Get your own automated compliance reports
Daily scans, PDF reports, email alerts, and legal templates — $79/year per site.
See Pro features →