Performance 1 (Perf1)
France · www.perf1.com · 16 vendors
Nameshield SAS is a French company specializing in domain name management, cybersecurity, and online brand protection. It provides solutions to help organizations protect their digital identity and strategic online services, including brand protection, managed DNS infrastructure, and DMARC compliance.
Resilience scores
- Digital Sovereignty: 6
- Digital Resilience: 6
Technology vendors
- Demandware — Technology — United States
- HubSpot, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 13 more
Services catalogue
2 services in catalogue across 2 categories; runs on 16 sub-vendors.
- DNS Hosting
- Perf1 DNS
Insights
Last updated 2026-07-30 · revision 11
16 direct vendors, 236 subvendors
Direct vendors by controlling owner country (sample)
- United States: 15
- France: 1
Subvendors by controlling owner country (sample)
- United Kingdom: 3
- Sweden: 8
- Ireland: 2
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Performance 1 exhibits low to medium migration readiness. The primary challenge is the 'Proprietary Domain Management Platform', which is likely not cloud-native and could be complex to re-platform or refactor for a modern cloud environment. Strict data residency requirements, including 'French sovereign data hosting infrastructure' and GDPR compliance, along with ANSSI compliance, will severely constrain the choice of cloud providers and architecture, potentially limiting options to specific regions or certified providers. The significant uncertainties regarding their own regulatory compliance (GDPR, NIS2, SOC2, ISO 27001) introduce substantial risk and complexity to any migration project, requiring thorough pre-migration assessments. Financial stability data is missing, making it impossible to assess their capacity to fund a potentially costly migration. Vendor lock-in risk is unknown, but the existence of 27 services and a proprietary platform suggests potential dependencies that could complicate disentanglement. There is no explicit mention of cloud-native architectural patterns like containerization or microservices, suggesting a more traditional, potentially monolithic architecture. An opportunity exists with the WordPress website, which is relatively straightforward to migrate. While their expertise in cybersecurity protocols is a strength, it does not directly translate to cloud-native architectural readiness.
Compliance
7 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
Cybersecurity companies in the EU are directly implicated by NIS2 in multiple ways. First, as a cybersecurity service provider, Perf1 may qualify as a 'Managed Security Service Provider' (MSSP) or 'ICT service management' provider — both of which are explicitly listed under NIS2 Annex I (Essential Entities) or Annex II (Important Entities). Second, NIS2 Article 2 covers entities providing services in the EU that meet the medium enterprise threshold (50+ employees OR €10M+ turnover). Third, France has transposed NIS2 into national law (Loi n° 2023-703 and ANSSI regulations). Non-compliance can result in fines up to €10 million or 2% of global turnover for Essential Entities, and €7 million or 1.4% for Important Entities. The risk is HIGH because cybersecurity firms are both subject to NIS2 and are expected to be exemplars of compliance.
Evidence: https://www.anssi.fr/en/, https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000047860386, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (CRA), adopted in October 2024 and entering into force progressively through 2027, applies to manufacturers and suppliers of products with digital elements (hardware and software) sold in the EU. If Perf1 develops or sells cybersecurity software products, tools, or hardware, CRA compliance will be mandatory. The risk is Medium-to-High for cybersecurity software vendors, as the CRA imposes strict security-by-design requirements, vulnerability disclosure obligations, and CE marking requirements for digital products.
Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847, https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
eIDAS 2.0 — Assessment Required
eIDAS 2.0 (Regulation EU 2024/1183) is relevant to cybersecurity companies that provide trust services such as electronic signatures, certificates, timestamping, or authentication services. If Perf1 provides any PKI, certificate management, or digital identity services as part of their cybersecurity offering, eIDAS 2.0 compliance would be mandatory. The risk is Medium because applicability depends on specific service offerings that could not be confirmed due to the parked domain.
Evidence: https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation, https://eidas.ec.europa.eu/efts/
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.