PSD3 and PSR compliance is an offset from an unset anchor, not a calendar date. The 21 and 27 month tiers, sourced from the Council's April 2026 compromise texts, and what a build has to have ready before either clock starts.
Engineering
-
PSD3 Compliance Requirements -
RAG Data PipelineA RAG corpus is a live system with state, not a build artifact. This piece traces one document through arrival, change, duplication, deletion and embedding model migration, and shows where five major vector stores document contradictory answers to the same event.
-
European Accessibility Act ComplianceThe European Accessibility Act never names WCAG or EN 301 549. This piece sorts a software company into the role that actually carries liability, and states plainly why the standard everyone cites carries no legal presumption here.
-
NIS2 Compliance Software RequirementsNIS2 never names a software company as a regulated type. This piece sorts a software vendor into the route that actually applies, then lists the artifacts each route asks it to keep on a shelf.
-
CRA Vulnerability Handling RequirementsAnnex I Part II of the Cyber Resilience Act sets eight standing vulnerability handling duties, and Article 13 layers two further clocks on top: a support period of at least five years, unless the product's expected use is genuinely shorter, and a ten year availability window on every security update issued during it. Which conformity route a product takes then depends on its Annex III or Annex IV class.
-
CRA Single Reporting Platform IntegrationThe CRA's Single Reporting Platform is a web form and case management system that ENISA runs, not an API, with no published roadmap for one. Registration runs through named individual Assigned Representatives, and one notification record moves through three stages that lock for good once the final report is submitted.
-
CRA NIS2 and DORA Reporting OverlapA company that is at once a CRA manufacturer, a NIS2 essential or important entity and a DORA financial entity keeps three separate reporting duties on three separate filings, even where two of them reach the same national CSIRT. The CRA's Single Reporting Platform consolidates filings within the CRA itself and does not fold NIS2 or DORA into that filing.
-
CRA Severe Incident ClassificationThe Cyber Resilience Act never defines severe as a standalone term. The threshold sits in Article 14(5), narrowing the general incident definition to sensitive or important data or functions, or to malicious code, while Article 3(42) sets a separate evidentiary bar for actively exploited that a high severity score alone does not meet.
-
CRA Incident Reporting DeadlinesThe EU Cyber Resilience Act's Article 14 sets up two separate reporting duties, not one sequence: an actively exploited vulnerability and a severe incident share the same 24-hour and 72-hour stages but diverge at the final report deadline. Filing there does not satisfy the separate duty to inform affected users.
-
LLM Observability CostA real LLM observability cost model built from verified vendor pricing retrieved 2026-08-08, showing why Langfuse, LangSmith, Braintrust and Arize cannot be compared on list price alone and how the OpenTelemetry GenAI conventions' Development status quietly breaks naive cost attribution.
-
MCP Server DevelopmentA spec-current guide to MCP server development after the 2026-07-28 revision, covering the stateless protocol change, the modern-vs-legacy split, server primitives, transports, authorization and the named security failure modes, plus what a server actually costs to build and maintain.
-
Electronic Money Token IssuanceMiCA describes an accounting outcome for an e-money token and almost never a mechanism. This follows one euro through the licence gate, the mint, placement, circulation, the redemption request, burn and attestation, states which of those steps the Regulation actually specifies and names the two places where it specifies nothing at all.
-
E-Money Safeguarding ReconciliationAn EMI or PI CTO has to prove on any business day that customer balances in the ledger equal the safeguarding accounts. No EU instrument in force names how often that comparison runs. This walks the invariants that do exist, the way each one breaks and the control that catches the break, ordered by how fast the control fires.
-
Instant Payments Sanctions ScreeningArticle 5d did not ban sanctions screening on the instant rail. It moved the object of the screening from the transaction to the customer base, prohibited one specific check in one specific window between two specific parties and carved out three categories expressly. This walks the pre-2025 screening stack component by component and states, for each one, what replaces it and which control it was carrying.
-
Verification of Payee ImplementationVerification of Payee is two jobs in one build, and the scheme treats them very differently. The requesting side is a specified round trip with a five second envelope and a discard rule. The responding side is a specified message shape wrapped around a decision the scheme declines to make, in a guidance document that says it is not part of the Rulebook and that the responder is free to ignore. This walks the message lifecycle position by position, states each one twice and closes each one on the contract both sides owe.
-
ISO 20022 Structured Address Migration: What Breaks on 15 November 2026The EPC's 15 November 2026 inter-PSP settlement date and Swift's 14 November 2026 SR 2026 go-live are two different events on one cutover weekend. This walks an address population through seven gates, from scope to the inter-PSP double rejection duty, and states at each gate which records die and what the remedy is.
-
CASP Wind Down PlanA CASP wind down plan is required by MiCA Article 74 and defined by almost nothing else in the act: no paragraph numbering, no recital, no technical standard, no filing duty and no deadline. What MiCA does supply is two conflicting destinations for client assets, a transfer to a successor provider under Article 64(8) and a return to the client under Article 75(6), and it never says which one runs. This article walks the wind-down in execution order, from the duties that have to be standing before any exit decision through trigger, freeze, client instruction, execution, sub-custody unwind and register closeout, and it is honest about the three different timing formulas MiCA writes for cessation, none of which is a number.
-
Omnibus vs Segregated Crypto WalletsOmnibus vs segregated crypto wallets is an architecture decision with a statutory edge: MiCA Article 75(7) limb one requires that on the distributed ledger, clients' crypto-assets are held separately from the CASP's own. This article reads that sentence closely, shows where per-client granularity actually lives, walks the cost of each branch on UTXO and account-model chains and treats reconciliation between the on-ledger position and the Article 75(2) register as the evidence artefact a supervisor will ask for.
-
Smart Contract Risk in Crypto CustodySmart contract risk in crypto custody is the one ESMA Common Supervisory Action scope item with no settled evidence practice behind it. This article treats each claim a CASP makes about its contracts as a claim under test, and names the artefact that proves or falsifies it: how upgrade privilege is proven on chain and revoked, what a proxy admin key does to an Article 75(7) segregation argument, what a staking contract does to the register of positions and what 130 audits say about where the critical findings actually cluster.
-
GPAI Model ObligationsWhat a general-purpose AI model provider owes regulators under Annex XI versus downstream integrators under Annex XII, where the open-source carve-out stops and why GPAI penalties sit in Article 101, not Article 99.
-
AI Act Technical DocumentationAnnex IV of the EU AI Act translated point by point into engineering deliverables, plus the logging and retention duties in Article 12, Article 19 and Article 26 and the unconfirmed SME simplified-documentation route.
-
AI Act High Risk ClassificationHow to classify an AI system as high-risk under Article 6 and Annex III of the EU AI Act after the Digital Omnibus, with the new 1a to 1c carve-outs, a decision tree and worked examples.
-
AI Act Article 50What Article 50 of the EU AI Act actually requires for marking AI-generated content, the two mandatory layers, the transitional date hidden in Article 111(4) and the failure modes the Code of Practice admits marking cannot survive.
-
EU AI Act ComplianceA dated EU AI Act compliance timeline and applicability map after Regulation (EU) 2026/1744, covering what changed in Article 113, Article 6 and Article 50 and why EUR-Lex, the Commission's AI Act tool and the most-cited third-party tracker still show the pre-amendment rules.
-
Crypto AML Rule TuningCrypto AML rule tuning covering the ATL/BTL threshold-testing lifecycle, a hedged sub-1 percent SAR-conversion retirement signal, the back-test gate before a threshold ships and what MiCA vs the incoming AMLR actually require of CASP transaction monitoring.
-
CASP License Cost by CountryCASP license cost broken down per EU country: national regulator fees from Latvia's EUR 2,500 to Malta's EUR 25,000, MiCA's EU-wide capital floors, market total-setup estimates, the Poland no-license-window trap and passporting under Article 65.
-
Threat-Led Penetration Testing for Crypto FirmsDORA Threat-Led Penetration Testing (TLPT) for crypto firms mapped provision by provision: the Article 26(8) designation gate that decides which CASPs owe TLPT at all, how it differs from ordinary Article 25 testing, the ECB TIBER-EU phases behind it, tester requirements under Article 27 and the evidence a regulator expects afterward.
-
DORA Register of InformationHow a MiCA-authorized CASP builds and maintains the DORA Register of Information under Article 28: the 15-template data model from Commission Implementing Regulation (EU) 2024/2956, mandatory LEI/EUID identifiers, the criticality classification that drives subcontractor depth and risk assessment, common register-build mistakes and the xBRL-CSV submission pipeline.
-
MPC vs Multisig vs HSMThe engineering decision underneath MiCA custody: MPC threshold signatures, HSM tamper-response hardware and on-chain multi-sig compared on single-point-of-failure resistance, auditability, recovery, cost and chain-agnosticism, with a cold/warm/hot tiering pattern and key ceremony, rotation and disaster-recovery design notes.
-
MiCA Custody RequirementsMiCA custody requirements mapped provision by provision: Article 70's safekeeping baseline for every CASP, Article 75's nine-paragraph custody rulebook, the three-limb segregation test, the liability cap at market value at time of loss and the evidence a CASP should have ready for each obligation.